Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Kvrocks HIGH 7.5
CVE-2025-26413

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it …

Fix: 2.12.0+
Fix from $1,950 2025-04-22
Poi MEDIUM 5.3
CVE-2025-31672

Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file forma…

Fix: 5.4.0+
Fix from $1,600 2025-04-09
Traffic Server MEDIUM 6.3
CVE-2024-38311

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…

Fix: 9.2.9 / 10.0.4+
Fix from $1,600 2025-03-06
Traffic Server HIGH 7.5
CVE-2024-50305

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2…

Fix: 9.2.6+
Fix from $1,950 2024-11-14
Traffic Server HIGH 7.5
CVE-2024-38479

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…

Fix: 9.2.6+
Fix from $1,950 2024-11-14
Cloudstack CRITICAL 9.9
CVE-2024-50386

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan…

Fix: 4.18.2.5 / 4.19.1.3+
Fix from $2,300 2024-11-12
Cloudstack HIGH 8.5
CVE-2024-45219

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as …

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,950 2024-10-16
Druid MEDIUM 6.5
CVE-2024-45537

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se…

Fix: 30.0.1+
Fix from $1,600 2024-09-17
Dolphinscheduler HIGH 8.1
CVE-2024-30188EPSS 6%

File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affect…

Fix: 3.2.2+
Fix from $1,950 2024-08-12
Dolphinscheduler HIGH 8.8
CVE-2024-29831

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.2.2+
Fix from $1,950 2024-08-12
Traffic Server HIGH 8.2
CVE-2024-35296

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic…

Fix: 8.1.11 / 9.2.5+
Fix from $1,950 2024-07-26
Roller MEDIUM 5.4
CVE-2024-25090

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …

Fix: 6.1.3+
Fix from $1,600 2024-07-26
Cxf HIGH 7.5
CVE-2024-32007

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of…

Fix: 3.5.9 / 3.6.4+
Fix from $1,950 2024-07-19
HTTP Server HIGH 7.5
CVE-2024-39573EPSS 35%

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to…

Fix: 2.4.60+
Fix from $1,950 2024-07-01
Superset MEDIUM 5.3
CVE-2024-34693

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile ena…

Fix: 3.1.3 / 4.0.1+
Fix from $1,600 2024-06-20
Allura HIGH 7.5
CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp…

Fix: 1.17.0+
Fix from $1,950 2024-06-10
Karaf Cave CRITICAL 9.1
CVE-2024-34365

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A…

Mitigation only
Fix from $2,300 2024-05-14
Traffic Server HIGH 7.5
CVE-2024-31309EPSS 95%

HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0…

Fix: 8.1.10 / 9.2.4+
Fix from $1,950 2024-04-10
Zeppelin MEDIUM 6.5
CVE-2024-31867

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 6.5
CVE-2024-31865

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.3
CVE-2022-47894

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is …

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.3
CVE-2024-31862

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.…

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Cloudstack MEDIUM 6.4
CVE-2024-29008

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to…

Fix: 4.18.1.1+
Fix from $1,600 2024-04-04
Hop Engine MEDIUM 6.5
CVE-2024-24683

Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to…

Fix: 2.8.0+
Fix from $1,600 2024-03-19
Tomcat HIGH 7.5
CVE-2024-24549EPSS 23%

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the requ…

Fix: 8.5.99 / 9.0.86+
Fix from $1,950 2024-03-13
Pulsar CRITICAL 9.9
CVE-2024-27135EPSS 6%

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function w…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Pulsar HIGH 8.8
CVE-2024-27894

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referen…

Fix: 2.10.6 / 2.11.4+
Fix from $1,950 2024-03-12
James HIGH 7.1
CVE-2023-51747

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ…

Mitigation only
Fix from $1,950 2024-02-27
Dolphinscheduler HIGH 8.8
CVE-2024-23320

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.2.1+
Fix from $1,950 2024-02-23
Dolphinscheduler HIGH 8.8
CVE-2023-49299

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.1.9+
Fix from $1,950 2023-12-30