Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.3 CVE-2026-41920 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-48204 Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici… Iotdb 2.0.8+ Fix from $2,3002026-07-06 MEDIUM 5.3 CVE-2026-31388 Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are reco… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 MEDIUM 5.4 CVE-2025-58337 An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that s… Doris Mcp Server 0.6.0+ Fix from $1,6002025-11-05 CRITICAL 9.1 CVE-2025-23048 In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 … HTTP Server 2.4.64+ Fix from $2,3002025-07-10 HIGH 7.5 CVE-2025-31698 ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.… Traffic Server 9.2.11 / 10.0.6+ Fix from $1,9502025-06-19 HIGH 8.8 CVE-2025-48734 Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop att… Commons Beanutils 1.11.0+ Fix from $1,9502025-05-28 MEDIUM 6.3 CVE-2024-56195 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 thro… Traffic Server 9.2.9 / 10.0.4+ Fix from $1,6002025-03-06 MEDIUM 6.3 CVE-2024-56196 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are rec… Traffic Server 10.0.4+ Fix from $1,6002025-03-06 CRITICAL 9.8 CVE-2024-27348 KEVEPSS 99% RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & … Hugegraph 1.3.0+ Fix from $2,3002024-04-22 HIGH 7.5 CVE-2022-39337 Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v… Hertzbeat 1.2.1+ Fix from $1,9502023-12-22 MEDIUM 6.5 CVE-2023-50783 Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to upda… Airflow 2.8.0+ Fix from $1,6002023-12-21 HIGH 7.8 CVE-2021-28129 While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi… Openoffice Mitigation only Fix from $1,9502021-10-07 MEDIUM 6.5 CVE-2021-26559 Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur… Airflow Mitigation only Fix from $1,6002021-02-17 HIGH 7.5 CVE-2021-26118 While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 … Artemis Mitigation only Fix from $1,9502021-01-27 CRITICAL 9.8 CVE-2014-3624 Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request… Traffic Server Patch available Fix from $2,3002017-10-30 HIGH 8.8 CVE-2013-4246 libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a… Subversion Patch available Fix from $1,9502017-10-30 HIGH 7.5 CVE-2010-2232 In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file. Derby Patch available Fix from $1,9502017-10-23 HIGH 7.5 CVE-2016-8752 Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI… Atlas Mitigation only Fix from $1,9502017-08-29 CRITICAL 9.8 CVE-2016-6807 Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that … Ambari Mitigation only Fix from $2,3002017-03-28 HIGH 8.8 CVE-2016-5393 In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary comm… Hadoop Mitigation only Fix from $1,9502016-11-29 CRITICAL 9.8 CVE-2016-1000031EPSS 34% Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution Commons Fileupload after 1.3.2 Fix from $2,3002016-10-25 CRITICAL 9.8 CVE-2016-4464 The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured… Cxf Fediz Mitigation only Fix from $2,3002016-09-21 HIGH 7.5 CVE-2016-6802EPSS 10% Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path. Shiro No fix yet Fix from $1,9502016-09-20 HIGH 8.8 CVE-2016-0760 Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re… Sentry Mitigation only Fix from $1,9502016-08-19 HIGH 7.5 CVE-2016-4979EPSS 19% The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" direc… HTTP Server Patch available Fix from $1,9502016-07-06 MEDIUM 5.3 CVE-2015-5207 Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by levera… Cordova after 3.9.1 Fix from $1,6002016-05-09 MEDIUM 6.8 CVE-2016-2167EPSS 7% The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication… Subversion after 1.8.15 Fix from $1,6002016-05-05