Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-46604 KEVEPSS 100% The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to… Activemq 5.15.16 / 5.16.7+ Fix from $2,3002023-10-27 CRITICAL 9.8 CVE-2023-43668 Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se… Inlong after 1.8.0 Fix from $2,3002023-10-16 CRITICAL 9.1 CVE-2023-44981 Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru… Zookeeper 3.7.2 / 3.8.3+ Fix from $2,3002023-10-11 CRITICAL 9.8 CVE-2023-40743 ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S… Axis 2023-08-01+ Fix from $2,3002023-09-05 CRITICAL 9.1 CVE-2023-33934 Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. Traffic Server after 9.2.1 Fix from $2,3002023-08-09 CRITICAL 9.8 CVE-2023-38647 An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S… Helix 1.3.0+ Fix from $2,3002023-07-26 CRITICAL 9.8 CVE-2023-37895 Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in… Jackrabbit 2.20.11 / 2.21.18+ Fix from $2,3002023-07-25 CRITICAL 9.8 CVE-2023-35088 Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i… Inlong after 1.7.0 Fix from $2,3002023-07-25 CRITICAL 9.8 CVE-2023-34478 Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth… Shiro 1.12.0+ Fix from $2,3002023-07-24 CRITICAL 9.8 CVE-2023-26512 CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac… Eventmesh Connector Rabbitmq after 1.8.0 Fix from $2,3002023-07-17 CRITICAL 9.8 CVE-2023-37582EPSS 90% The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version … Rocketmq after 5.1.1 Fix from $2,3002023-07-12 CRITICAL 9.8 CVE-2023-35797 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Pro… Apache Airflow Providers Apache Hive 6.1.1+ Fix from $2,3002023-07-03 CRITICAL 9.8 CVE-2023-34340 Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta… Accumulo Mitigation only Fix from $2,3002023-06-21 CRITICAL 9.8 CVE-2023-33246 KEVEPSS 97% For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu… Rocketmq 4.9.6 / 5.1.1+ Fix from $2,3002023-05-24 CRITICAL 9.8 CVE-2023-31098 Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  Wh… Inlong after 1.6.0 Fix from $2,3002023-05-22 CRITICAL 9.1 CVE-2023-31065 Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.… Inlong after 1.6.0 Fix from $2,3002023-05-22 CRITICAL 9.1 CVE-2023-31066 Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from … Inlong after 1.6.0 Fix from $2,3002023-05-22 CRITICAL 9.8 CVE-2023-31062 Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.… Inlong after 1.6.0 Fix from $2,3002023-05-22 CRITICAL 9.8 CVE-2022-47937 Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted inpu… Sling Commons Json after 2.0.20 Fix from $2,3002023-05-15 CRITICAL 9.8 CVE-2023-25754 Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0. Airflow 2.6.0+ Fix from $2,3002023-05-08 CRITICAL 9.8 CVE-2023-31039 Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker tha… Brpc 1.5.0+ Fix from $2,3002023-05-08 CRITICAL 9.1 CVE-2022-46365 Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a … Streampark 2.0.0+ Fix from $2,3002023-05-01 CRITICAL 9.8 CVE-2022-45802 Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload… Streampark 2.0.0+ Fix from $2,3002023-05-01 CRITICAL 9.8 CVE-2023-27524 KEVEPSS 97% Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K… Superset after 2.0.1 Fix from $2,3002023-04-24 CRITICAL 9.9 CVE-2023-22946 In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c… Spark 3.4.0+ Fix from $2,3002023-04-17 CRITICAL 9.8 CVE-2023-30771 Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd… Iotdb Web Workbench Mitigation only Fix from $2,3002023-04-17 CRITICAL 9.8 CVE-2023-24831 Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu… Iotdb after 0.13.3 Fix from $2,3002023-04-17 CRITICAL 9.0 CVE-2022-45064 The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting is… Apache Sling Engine 2.14.0+ Fix from $2,3002023-04-13 CRITICAL 9.8 CVE-2023-27603 In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-29215 In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi… Linkis after 1.3.1 Fix from $2,3002023-04-10