Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2024-39676 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. U… Pinot 1.0.0+ Fix from $1,9502024-07-24 HIGH 8.8 CVE-2024-23321 For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i… Rocketmq 5.3.0+ Fix from $1,9502024-07-22 HIGH 7.5 CVE-2024-36471 Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp… Allura 1.17.0+ Fix from $1,9502024-06-10 CRITICAL 9.1 CVE-2024-27905 ** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte… Aurora Mitigation only Fix from $2,3002024-02-27 HIGH 7.5 CVE-2023-50298 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, fr… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2023-44312 Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Cente… Servicecomb 2.2.0+ Fix from $1,9502024-01-31 MEDIUM 6.5 CVE-2023-50290EPSS 68% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment v… Solr 9.3.0+ Fix from $1,6002024-01-15 HIGH 7.5 CVE-2023-50968EPSS 63% Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th… Ofbiz 18.12.11+ Fix from $1,9502023-12-26 MEDIUM 5.7 CVE-2023-45725 Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the do… Couchdb after 3.3.2 Fix from $1,6002023-12-13 HIGH 7.5 CVE-2023-49068 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: befor… Dolphinscheduler 3.2.1+ Fix from $1,9502023-11-27 HIGH 7.5 CVE-2023-48796 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors … Dolphinscheduler 3.0.2+ Fix from $1,9502023-11-24 MEDIUM 5.5 CVE-2023-43123 On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set th… Storm 2.6.0+ Fix from $1,6002023-11-23 MEDIUM 6.5 CVE-2023-42781 Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat… Airflow 2.7.3+ Fix from $1,6002023-11-12 HIGH 7.5 CVE-2023-41752 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.… Traffic Server 8.1.9 / 9.2.3+ Fix from $1,9502023-10-17 MEDIUM 6.5 CVE-2023-42780 Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, … Airflow 2.7.2+ Fix from $1,6002023-10-14 MEDIUM 6.5 CVE-2023-42663 Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat… Airflow 2.7.2+ Fix from $1,6002023-10-14 MEDIUM 6.5 CVE-2023-40712 Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, … Airflow 2.7.1+ Fix from $1,6002023-09-12 HIGH 8.1 CVE-2023-37379 Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed… Airflow 2.7.0+ Fix from $1,9502023-08-23 HIGH 8.8 CVE-2023-39508 Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apach… Airflow 2.6.0+ Fix from $1,9502023-08-05 MEDIUM 6.5 CVE-2022-46651 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Co… Airflow 2.6.3+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-35005 In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact… Airflow 2.6.2+ Fix from $1,6002023-06-19 HIGH 7.5 CVE-2023-33933 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach… Traffic Server 8.1.7 / 9.2.1+ Fix from $1,9502023-06-14 HIGH 7.5 CVE-2022-47184 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach… Traffic Server 8.1.7 / 9.2.1+ Fix from $1,9502023-06-14 MEDIUM 5.3 CVE-2023-26268 Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design d… Couchdb 3.2.3 / 3.3.2+ Fix from $1,6002023-05-02 HIGH 7.5 CVE-2022-26885 When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher. Dolphinscheduler 2.0.6+ Fix from $1,9502022-11-24 HIGH 7.5 CVE-2022-27949 A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (fo… Airflow 2.3.1+ Fix from $1,9502022-11-14 HIGH 7.5 CVE-2022-30556 Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the … HTTP Server 2.4.54+ Fix from $1,9502022-06-09 MEDIUM 5.3 CVE-2022-28614 The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very larg… HTTP Server after 2.4.53 Fix from $1,6002022-06-09 MEDIUM 5.5 CVE-2021-36151 In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.… Gobblin after 0.15.0 Fix from $1,6002022-02-04 MEDIUM 6.5 CVE-2022-22733EPSS 38% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco… Shardingsphere Elasticjob Ui Mitigation only Fix from $1,6002022-01-20