Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-35003 Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut… Nuttx 12.9.0+ Fix from $2,3002025-05-26 CRITICAL 9.8 CVE-2025-47436 Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially … Orc 1.8.9 / 1.9.6+ Fix from $2,3002025-05-14 CRITICAL 9.8 CVE-2024-24780 Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu… Iotdb 1.3.4+ Fix from $2,3002025-05-14 CRITICAL 9.8 CVE-2025-31651 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, i… Tomcat 9.0.104 / 10.1.40+ Fix from $2,3002025-04-28 CRITICAL 9.8 CVE-2025-29953 Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client befor… Activemq Nms Openwire 2.1.1+ Fix from $2,3002025-04-18 CRITICAL 9.8 CVE-2024-56325EPSS 79% Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Examp… Pinot 1.3.0+ Fix from $2,3002025-04-01 CRITICAL 9.8 CVE-2025-30065EPSS 41% Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are reco… Parquet Java 1.15.1+ Fix from $2,3002025-04-01 CRITICAL 9.8 CVE-2024-47552 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.… Seata 2.2.0+ Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2025-24813 KEVEPSS 100% Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade… Tomcat 9.0.99 / 10.1.35+ Fix from $2,3002025-03-10 CRITICAL 9.8 CVE-2024-55532 Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade… Ranger 2.6.0+ Fix from $2,3002025-03-03 CRITICAL 9.8 CVE-2024-56180 CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo… Eventmesh 1.11.0+ Fix from $2,3002025-02-14 CRITICAL 9.0 CVE-2024-52577 In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili… Ignite 2.17.0+ Fix from $2,3002025-02-14 CRITICAL 9.1 CVE-2024-45479 SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger… Ranger 2.5.0+ Fix from $2,3002025-01-21 CRITICAL 9.8 CVE-2024-54676EPSS 65% Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions … Openmeetings 8.0.0+ Fix from $2,3002025-01-08 CRITICAL 9.8 CVE-2024-52046EPSS 24% The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary… Mina 2.0.27 / 2.1.10+ Fix from $2,3002024-12-25 CRITICAL 9.8 CVE-2024-43441EPSS 69% Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 bef… Hugegraph 1.5.0+ Fix from $2,3002024-12-24 CRITICAL 9.8 CVE-2024-56337EPSS 9% Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, f… Tomcat 9.0.98 / 10.1.34+ Fix from $2,3002024-12-20 CRITICAL 9.8 CVE-2024-50379EPSS 44% Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file syste… Tomcat 9.0.98 / 10.1.34+ Fix from $2,3002024-12-17 CRITICAL 9.8 CVE-2024-53677EPSS 78% File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th… Struts 6.4.0+ Fix from $2,3002024-12-11 CRITICAL 9.8 CVE-2024-53947 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s… Superset 4.1.0+ Fix from $2,3002024-12-09 CRITICAL 9.8 CVE-2024-52338 Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut… Arrow 17.0.0+ Fix from $2,3002024-11-28 CRITICAL 9.8 CVE-2024-52316EPSS 6% Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuth… Tomcat 9.0.96 / 10.1.31+ Fix from $2,3002024-11-18 CRITICAL 9.8 CVE-2024-47208 Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.17+ Fix from $2,3002024-11-18 CRITICAL 9.1 CVE-2024-50306 Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through… Traffic Server 9.2.6 / 10.0.2+ Fix from $2,3002024-11-14 CRITICAL 9.9 CVE-2024-50386 Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan… Cloudstack 4.18.2.5 / 4.19.1.3+ Fix from $2,3002024-11-12 CRITICAL 9.1 CVE-2024-51504 When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP bas… Zookeeper 3.9.3+ Fix from $2,3002024-11-07 CRITICAL 9.1 CVE-2024-23590 Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to versio… Kylin 5.0.0+ Fix from $2,3002024-11-04 CRITICAL 9.8 CVE-2024-45216EPSS 92% Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen… Solr 8.11.4 / 9.7.0+ Fix from $2,3002024-10-16 CRITICAL 9.8 CVE-2024-22399 Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seat… Seata 1.8.1+ Fix from $2,3002024-09-16 CRITICAL 9.8 CVE-2024-45507EPSS 93% Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.16+ Fix from $2,3002024-09-04