Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-62183 Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 HIGH 8.1 CVE-2026-59245 In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour… Apache Airflow Providers Fab 3.7.2+ Fix from $1,9502026-07-13 MEDIUM 5.5 CVE-2026-44119 Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges… HTTP Server 2.4.68+ Fix from $1,6002026-06-08 HIGH 8.8 CVE-2026-24072 An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges … HTTP Server 2.4.67+ Fix from $1,9502026-05-04 HIGH 8.1 CVE-2025-47411EPSS 15% A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th… Streampipes 0.98.0+ Fix from $1,9502026-01-01 MEDIUM 5.4 CVE-2025-59790 Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommende… Kvrocks 2.14.0+ Fix from $1,6002025-11-28 HIGH 8.8 CVE-2025-47713 A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-47849 A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 MEDIUM 6.5 CVE-2024-24778 Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This i… Streampipes 0.97.0+ Fix from $1,6002025-03-03 MEDIUM 6.5 CVE-2024-31141 Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accep… Kafka after 3.6.2 Fix from $1,6002024-11-19 HIGH 8.8 CVE-2024-27181 In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Link… Linkis 1.6.0+ Fix from $1,9502024-08-02 HIGH 8.8 CVE-2024-23537 Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to versi… Fineract 1.9.0+ Fix from $1,9502024-03-29 HIGH 8.8 CVE-2023-31469 A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi… Streampipes after 0.91.0 Fix from $1,9502023-06-23 HIGH 7.8 CVE-2023-30601 Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This iss… Cassandra 4.0.10 / 4.1.2+ Fix from $1,9502023-05-30 CRITICAL 9.8 CVE-2023-31062 Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.… Inlong after 1.6.0 Fix from $2,3002023-05-22 CRITICAL 9.9 CVE-2023-22946 In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c… Spark 3.4.0+ Fix from $2,3002023-04-17 HIGH 8.8 CVE-2022-42735 Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators… Shenyu Mitigation only Fix from $1,9502023-02-15 CRITICAL 9.8 CVE-2021-38540EPSS 81% The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint … Airflow 2.1.3+ Fix from $2,3002021-09-09 MEDIUM 5.3 CVE-2021-26697 The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h… Airflow Mitigation only Fix from $1,6002021-02-17 HIGH 7.4 CVE-2018-11767 In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-d… Hadoop after 2.9.1 Fix from $1,9502019-03-21 HIGH 8.8 CVE-2018-11786 In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri… Karaf 4.2.0+ Fix from $1,9502018-09-18 CRITICAL 9.8 CVE-2017-12635EPSS 100% Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1… Couchdb 1.7.0+ Fix from $2,3002017-11-14