Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Fineract CRITICAL 9.1
CVE-2025-58130

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver…

Fix: 1.12.1+
Fix from $2,300 2025-12-12
Solr HIGH 7.5
CVE-2023-50291

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.…

Fix: 8.11.3 / 9.3.0+
Fix from $1,950 2024-02-09
Kylin HIGH 7.5
CVE-2023-29055

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain…

Fix: 4.0.4+
Fix from $1,950 2024-01-29
Superset MEDIUM 6.5
CVE-2023-30776

An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue…

Fix: after 2.0.1
Fix from $1,600 2023-04-24
Superset MEDIUM 6.5
CVE-2021-44451EPSS 8%

Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could b…

Fix: after 1.3.2
Fix from $1,600 2022-02-01
Shenyu HIGH 7.5
CVE-2022-23223

On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to versio…

Patch available
Fix from $1,950 2022-01-25
Superset MEDIUM 6.5
CVE-2021-41972

Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed …

Fix: after 1.3.1
Fix from $1,600 2021-11-12
Solr HIGH 7.5
CVE-2021-29262EPSS 8%

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing…

Fix: 8.8.2+
Fix from $1,950 2021-04-13
Fineract HIGH 7.5
CVE-2018-20243

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract ji…

Fix: after 1.3.0
Fix from $1,950 2020-10-13
Artemis MEDIUM 5.5
CVE-2020-10727

A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in t…

Fix: after 2.12.0
Fix from $1,600 2020-06-26
Cxf HIGH 7.5
CVE-2019-12423EPSS 6%

Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to ver…

Fix: 3.2.12 / 3.3.5+
Fix from $1,950 2020-01-16