Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Ranger HIGH 7.5
CVE-2026-55814

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $4,900 2026-08-10
Answer HIGH 7.5
CVE-2026-48911

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authoriza…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Jspwiki HIGH 7.5
CVE-2026-28814

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Doris CRITICAL 9.1
CVE-2026-58319

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …

Fix: 3.1.0+
Fix from $2,300 2026-07-14
Camel CRITICAL 9.8
CVE-2026-53913

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Thrift HIGH 7.4
CVE-2026-41603

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Artemis CRITICAL 9.8
CVE-2026-27446EPSS 10%

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…

Fix: after 2.44.0
Fix from $2,300 2026-03-04
Seatunnel MEDIUM 6.5
CVE-2025-32896

# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized …

Fix: 2.3.11+
Fix from $1,600 2025-06-19
Pulsar HIGH 8.2
CVE-2022-34321

Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The v…

Fix: 2.10.6 / 2.11.3+
Fix from $1,950 2024-03-12
Ofbiz MEDIUM 5.3
CVE-2023-46819

Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.  Use…

Fix: 18.12.09+
Fix from $1,600 2023-11-07
Openmeetings CRITICAL 9.8
CVE-2023-28326

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privi…

Fix: 7.0.0+
Fix from $2,300 2023-03-28
Soap CRITICAL 9.8
CVE-2022-45378

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invok…

Fix: after 2.3
Fix from $2,300 2022-11-14
Hive HIGH 7.5
CVE-2021-34538

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was…

Fix: 3.1.3+
Fix from $1,950 2022-07-16
Shenyu CRITICAL 9.1
CVE-2022-23944EPSS 79%

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $2,300 2022-01-25
Shenyu HIGH 7.5
CVE-2022-23945

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $1,950 2022-01-25
Apisix Dashboard CRITICAL 9.8
CVE-2021-45232EPSS 86%

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all…

Fix: 2.10.1+
Fix from $2,300 2021-12-27
Ozone CRITICAL 9.1
CVE-2021-39233

In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any …

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Airflow CRITICAL 9.8
CVE-2021-38540EPSS 81%

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …

Fix: 2.1.3+
Fix from $2,300 2021-09-09
Airflow MEDIUM 5.3
CVE-2021-35936

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…

Fix: 2.1.2+
Fix from $1,600 2021-08-16
Ozone HIGH 7.5
CVE-2020-17517

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allo…

Fix: 1.1.0+
Fix from $1,950 2021-04-27
Airflow MEDIUM 5.3
CVE-2021-26697

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…

Mitigation only
Fix from $1,600 2021-02-17
Airflow CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…

Fix: 1.10.11+
Fix from $2,300 2020-11-10
Hadoop HIGH 8.8
CVE-2018-11764

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even …

Mitigation only
Fix from $1,950 2020-10-21
Nifi HIGH 7.5
CVE-2020-9487

In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to c…

Fix: after 1.11.4
Fix from $1,950 2020-10-01
Activemq MEDIUM 5.9
CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to con…

Fix: 5.15.12+
Fix from $1,600 2020-09-10
Spark CRITICAL 9.8
CVE-2020-9480EPSS 29%

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…

Fix: after 2.4.5
Fix from $2,300 2020-06-23
Tomee CRITICAL 9.8
CVE-2020-11969

If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP…

Fix: after 8.0.1
Fix from $2,300 2020-06-15
Couchdb CRITICAL 9.8
CVE-2020-1955

CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…

Mitigation only
Fix from $2,300 2020-05-20
Cassandra CRITICAL 9.8
CVE-2018-8016

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows r…

Fix: after 3.11.1
Fix from $2,300 2018-06-28
Zookeeper HIGH 7.5
CVE-2017-5637EPSS 73%

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead…

Mitigation only
Fix from $1,950 2017-10-10