Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Openoffice HIGH 8.8
CVE-2023-47804

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. …

Fix: 4.1.15+
Fix from $1,950 2023-12-29
Uimaj HIGH 8.8
CVE-2023-39913

Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apach…

Fix: 3.5.0+
Fix from $1,950 2023-11-08
Traffic Server HIGH 7.5
CVE-2023-39456EPSS 53%

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th…

Fix: 9.2.3+
Fix from $1,950 2023-10-17
Tomcat MEDIUM 5.3
CVE-2023-45648EPSS 6%

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro…

Fix: 8.5.94 / 9.0.81+
Fix from $1,600 2023-10-10
Commons Compress MEDIUM 5.5
CVE-2023-42503

Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common…

Fix: 1.24.0+
Fix from $1,600 2023-09-14
Superset MEDIUM 6.5
CVE-2023-39265EPSS 84%

Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+p…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Axis CRITICAL 9.8
CVE-2023-40743

** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S…

Fix: 2023-08-01+
Fix from $2,300 2023-09-05
Airflow Sqoop Provider HIGH 8.8
CVE-2023-27604

Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, wh…

Fix: 4.0.0+
Fix from $1,950 2023-08-28
Apache Airflow Providers Apache Spark HIGH 7.5
CVE-2023-40272

Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when est…

Fix: 4.1.3+
Fix from $1,950 2023-08-17
Apache Airflow Providers Apache Drill HIGH 7.5
CVE-2023-39553

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a …

Fix: 2.4.3+
Fix from $1,950 2023-08-11
Traffic Server HIGH 7.5
CVE-2022-47185

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Ser…

Fix: after 9.2.1
Fix from $1,950 2023-08-09
Apache Airflow Providers Apache Hive HIGH 8.8
CVE-2023-37415

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before …

Fix: 6.1.2+
Fix from $1,950 2023-07-13
Airflow MEDIUM 6.5
CVE-2023-22888

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_i…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Any23 MEDIUM 5.3
CVE-2023-34150

** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.

Fix: after 2.7
Fix from $1,600 2023-07-05
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2023-35797

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Pro…

Fix: 6.1.1+
Fix from $2,300 2023-07-03
Apache Airflow Providers Jdbc HIGH 8.8
CVE-2023-22886

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection UR…

Fix: 4.0.0+
Fix from $1,950 2023-06-29
Traffic Server HIGH 7.5
CVE-2023-30631

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Sling Commons Json CRITICAL 9.8
CVE-2022-47937

Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted inpu…

Fix: after 2.0.20
Fix from $2,300 2023-05-15
Openmeetings HIGH 7.2
CVE-2023-29246

An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affec…

Fix: 7.1.0+
Fix from $1,950 2023-05-12
Brpc CRITICAL 9.8
CVE-2023-31039

Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker tha…

Fix: 1.5.0+
Fix from $2,300 2023-05-08
Streampark CRITICAL 9.1
CVE-2022-46365

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Apache Airflow Providers Apache Drill HIGH 7.5
CVE-2023-28707

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider:…

Fix: 2.3.2+
Fix from $1,950 2023-04-07
Apache Airflow Providers Apache Spark HIGH 7.5
CVE-2023-28710

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider:…

Fix: 4.0.1+
Fix from $1,950 2023-04-07
Openoffice HIGH 7.8
CVE-2022-47502

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. …

Fix: after 4.1.13
Fix from $1,950 2023-03-24
Apache Airflow Providers Google CRITICAL 9.8
CVE-2023-25691

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1…

Fix: 8.10.0+
Fix from $2,300 2023-02-24
Apache Airflow Providers Apache Sqoop CRITICAL 9.8
CVE-2023-25693

Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

Fix: 3.1.1+
Fix from $2,300 2023-02-24
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2023-25696

Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

Fix: 5.1.3+
Fix from $2,300 2023-02-24
Apache Airflow Providers Google HIGH 7.5
CVE-2023-25692

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1…

Fix: 8.10.0+
Fix from $1,950 2023-02-24
Linkis MEDIUM 6.5
CVE-2022-44644

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files b…

Fix: after 1.3.0
Fix from $1,600 2023-01-31
Dolphinscheduler CRITICAL 9.8
CVE-2022-45875

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects…

Fix: 3.0.2+
Fix from $2,300 2023-01-04