Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Traffic Server CRITICAL 9.3
CVE-2026-41920

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Camel CRITICAL 9.8
CVE-2026-48204

Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Iotdb CRITICAL 9.8
CVE-2026-24014

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Ofbiz MEDIUM 5.3
CVE-2026-31388

Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are reco…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Doris Mcp Server MEDIUM 5.4
CVE-2025-58337

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that s…

Fix: 0.6.0+
Fix from $1,600 2025-11-05
HTTP Server CRITICAL 9.1
CVE-2025-23048

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 …

Fix: 2.4.64+
Fix from $2,300 2025-07-10
Traffic Server HIGH 7.5
CVE-2025-31698

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.…

Fix: 9.2.11 / 10.0.6+
Fix from $1,950 2025-06-19
Commons Beanutils HIGH 8.8
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop att…

Fix: 1.11.0+
Fix from $1,950 2025-05-28
Traffic Server MEDIUM 6.3
CVE-2024-56195

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 thro…

Fix: 9.2.9 / 10.0.4+
Fix from $1,600 2025-03-06
Traffic Server MEDIUM 6.3
CVE-2024-56196

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are rec…

Fix: 10.0.4+
Fix from $1,600 2025-03-06
Hugegraph CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Hertzbeat HIGH 7.5
CVE-2022-39337

Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v…

Fix: 1.2.1+
Fix from $1,950 2023-12-22
Airflow MEDIUM 6.5
CVE-2023-50783

Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to upda…

Fix: 2.8.0+
Fix from $1,600 2023-12-21
Openoffice HIGH 7.8
CVE-2021-28129

While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi…

Mitigation only
Fix from $1,950 2021-10-07
Airflow MEDIUM 6.5
CVE-2021-26559

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur…

Mitigation only
Fix from $1,600 2021-02-17
Artemis HIGH 7.5
CVE-2021-26118

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 …

Mitigation only
Fix from $1,950 2021-01-27
Traffic Server CRITICAL 9.8
CVE-2014-3624

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request…

Patch available
Fix from $2,300 2017-10-30
Subversion HIGH 8.8
CVE-2013-4246

libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a…

Patch available
Fix from $1,950 2017-10-30
Derby HIGH 7.5
CVE-2010-2232

In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.

Patch available
Fix from $1,950 2017-10-23
Atlas HIGH 7.5
CVE-2016-8752

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI…

Mitigation only
Fix from $1,950 2017-08-29
Ambari CRITICAL 9.8
CVE-2016-6807

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that …

Mitigation only
Fix from $2,300 2017-03-28
Hadoop HIGH 8.8
CVE-2016-5393

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary comm…

Mitigation only
Fix from $1,950 2016-11-29
Commons Fileupload CRITICAL 9.8
CVE-2016-1000031EPSS 34%

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Fix: after 1.3.2
Fix from $2,300 2016-10-25
Cxf Fediz CRITICAL 9.8
CVE-2016-4464

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured…

Mitigation only
Fix from $2,300 2016-09-21
Shiro HIGH 7.5
CVE-2016-6802EPSS 10%

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

No fix yet
Fix from $1,950 2016-09-20
Sentry HIGH 8.8
CVE-2016-0760

Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re…

Mitigation only
Fix from $1,950 2016-08-19
HTTP Server HIGH 7.5
CVE-2016-4979EPSS 19%

The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" direc…

Patch available
Fix from $1,950 2016-07-06
Cordova MEDIUM 5.3
CVE-2015-5207

Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by levera…

Fix: after 3.9.1
Fix from $1,600 2016-05-09
Subversion MEDIUM 6.8
CVE-2016-2167EPSS 7%

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication…

Fix: after 1.8.15
Fix from $1,600 2016-05-05