Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Apache Airflow Providers Ftp HIGH 7.5
CVE-2026-49486

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control c…

Fix: 3.15.1+
Fix from $1,950 2026-06-26
Apisix HIGH 7.5
CVE-2026-31923

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configur…

Fix: 3.16.0+
Fix from $1,950 2026-04-14
Apisix MEDIUM 5.3
CVE-2026-31924

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects …

Fix: 3.16.0+
Fix from $1,600 2026-04-14
Directory Studio HIGH 7.5
CVE-2021-33900

While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-…

Fix: after 1.5.3
Fix from $1,950 2021-07-26
Kafka HIGH 7.5
CVE-2019-12399

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a conne…

Fix: after 14.4.0
Fix from $1,950 2020-01-14
Mina HIGH 7.5
CVE-2019-0231

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the cl…

Mitigation only
Fix from $1,950 2019-10-01
Nifi HIGH 7.5
CVE-2018-17195

The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack…

Fix: after 1.7.1
Fix from $1,950 2018-12-19
Jmeter CRITICAL 9.8
CVE-2018-1297EPSS 10%

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …

Mitigation only
Fix from $2,300 2018-02-13
Impala HIGH 7.5
CVE-2017-5652

During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when …

Mitigation only
Fix from $1,950 2017-07-10