Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2025-26413 Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it … Kvrocks 2.12.0+ Fix from $1,9502025-04-22 MEDIUM 5.3 CVE-2025-31672 Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file forma… Poi 5.4.0+ Fix from $1,6002025-04-09 MEDIUM 6.3 CVE-2024-38311 Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th… Traffic Server 9.2.9 / 10.0.4+ Fix from $1,6002025-03-06 HIGH 7.5 CVE-2024-50305 Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2… Traffic Server 9.2.6+ Fix from $1,9502024-11-14 HIGH 7.5 CVE-2024-38479 Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th… Traffic Server 9.2.6+ Fix from $1,9502024-11-14 CRITICAL 9.9 CVE-2024-50386 Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan… Cloudstack 4.18.2.5 / 4.19.1.3+ Fix from $2,3002024-11-12 HIGH 8.5 CVE-2024-45219 Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as … Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,9502024-10-16 MEDIUM 6.5 CVE-2024-45537 Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se… Druid 30.0.1+ Fix from $1,6002024-09-17 HIGH 8.1 CVE-2024-30188EPSS 6% File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affect… Dolphinscheduler 3.2.2+ Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-29831 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed … Dolphinscheduler 3.2.2+ Fix from $1,9502024-08-12 HIGH 8.2 CVE-2024-35296 Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic… Traffic Server 8.1.11 / 9.2.5+ Fix from $1,9502024-07-26 MEDIUM 5.4 CVE-2024-25090 Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of … Roller 6.1.3+ Fix from $1,6002024-07-26 HIGH 7.5 CVE-2024-32007 An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of… Cxf 3.5.9 / 3.6.4+ Fix from $1,9502024-07-19 HIGH 7.5 CVE-2024-39573EPSS 35% Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to… HTTP Server 2.4.60+ Fix from $1,9502024-07-01 MEDIUM 5.3 CVE-2024-34693 Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile ena… Superset 3.1.3 / 4.0.1+ Fix from $1,6002024-06-20 HIGH 7.5 CVE-2024-36471 Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp… Allura 1.17.0+ Fix from $1,9502024-06-10 CRITICAL 9.1 CVE-2024-34365 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A… Karaf Cave Mitigation only Fix from $2,3002024-05-14 HIGH 7.5 CVE-2024-31309EPSS 95% HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0… Traffic Server 8.1.10 / 9.2.4+ Fix from $1,9502024-04-10 MEDIUM 6.5 CVE-2024-31867 Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties… Zeppelin 0.11.1+ Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-31865 Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the… Zeppelin 0.11.1+ Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2022-47894 Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is … Zeppelin 0.11.0+ Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2024-31862 Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.… Zeppelin 0.11.0+ Fix from $1,6002024-04-09 MEDIUM 6.4 CVE-2024-29008 A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to… Cloudstack 4.18.1.1+ Fix from $1,6002024-04-04 MEDIUM 6.5 CVE-2024-24683 Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to… Hop Engine 2.8.0+ Fix from $1,6002024-03-19 HIGH 7.5 CVE-2024-24549EPSS 23% Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the requ… Tomcat 8.5.99 / 9.0.86+ Fix from $1,9502024-03-13 CRITICAL 9.9 CVE-2024-27135EPSS 6% Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function w… Pulsar 2.10.6 / 2.11.4+ Fix from $2,3002024-03-12 HIGH 8.8 CVE-2024-27894 The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referen… Pulsar 2.10.6 / 2.11.4+ Fix from $1,9502024-03-12 HIGH 7.1 CVE-2023-51747 Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ… James Mitigation only Fix from $1,9502024-02-27 HIGH 8.8 CVE-2024-23320 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed … Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-23 HIGH 8.8 CVE-2023-49299 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed … Dolphinscheduler 3.1.9+ Fix from $1,9502023-12-30