Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Camel MEDIUM 6.5
CVE-2026-49097

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-49098

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-49099

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key …

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Wicket CRITICAL 9.8
CVE-2024-36522

The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…

Fix: 8.16.0 / 9.18.0+
Fix from $2,300 2024-07-12
James Mime4j MEDIUM 5.3
CVE-2024-21742

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an atta…

Fix: after 0.8.9
Fix from $1,600 2024-02-27
Hertzbeat CRITICAL 9.8
CVE-2023-51388

Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no …

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Hertzbeat CRITICAL 9.8
CVE-2023-51653

Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec…

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Derby CRITICAL 9.8
CVE-2022-46337

A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up …

Fix: 10.14.3.0 / 10.15.2.1+
Fix from $2,300 2023-11-20
Inlong HIGH 7.5
CVE-2023-43667

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects …

Fix: after 1.8.0
Fix from $1,950 2023-10-16
Flink Stateful Functions MEDIUM 6.1
CVE-2023-41834

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject…

Fix: after 3.2.0
Fix from $1,600 2023-09-19
Apache Airflow Providers Cncf Kubernetes HIGH 7.2
CVE-2023-33234

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow …

Fix: 7.0.0+
Fix from $1,950 2023-05-30
Ranger HIGH 8.8
CVE-2022-45048

Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe…

Mitigation only
Fix from $1,950 2023-05-05
Streampark MEDIUM 5.4
CVE-2022-45801

Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that constru…

Fix: 2.0.0+
Fix from $1,600 2023-05-01
Kerby Ldap Backend CRITICAL 9.8
CVE-2023-25613

An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. 

Fix: 2.0.3+
Fix from $2,300 2023-02-20
Sling Jcr Base HIGH 7.5
CVE-2023-25141

Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct…

Fix: 3.1.12+
Fix from $1,950 2023-02-14
Superset MEDIUM 5.4
CVE-2022-43720

An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the t…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Karaf CRITICAL 9.8
CVE-2022-40145

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function …

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-12-21
Manifoldcf MEDIUM 5.3
CVE-2022-45910

Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory …

Fix: after 2.23
Fix from $1,600 2022-12-07
Spark MEDIUM 5.4
CVE-2022-31777

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScri…

Fix: 3.2.2+
Fix from $1,600 2022-11-01
Flume CRITICAL 9.8
CVE-2022-42468

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…

Fix: after 1.10.1
Fix from $2,300 2022-10-26
Flume CRITICAL 9.8
CVE-2022-25167

Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…

Fix: 1.10.0+
Fix from $2,300 2022-06-14
Log4j MEDIUM 6.6
CVE-2021-44832EPSS 98%

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…

Fix: 2.3.2 / 2.12.4+
Fix from $1,600 2021-12-28
Traffic Control CRITICAL 9.8
CVE-2021-43350

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…

Fix: 5.1.4 / 6.0.1+
Fix from $2,300 2021-11-11
Storm CRITICAL 9.8
CVE-2021-38294EPSS 84%

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Unomi HIGH 7.5
CVE-2021-31164

Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

Fix: 1.5.5+
Fix from $1,950 2021-05-04
Unomi CRITICAL 9.8
CVE-2020-13942EPSS 68%

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…

Fix: 1.5.2+
Fix from $2,300 2020-11-24
Camel HIGH 7.5
CVE-2020-11994

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

Fix: after 8.5.0
Fix from $1,950 2020-07-08
Archiva MEDIUM 5.3
CVE-2020-9495EPSS 8%

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP…

Fix: 2.2.5+
Fix from $1,600 2020-06-19
Syncope CRITICAL 9.8
CVE-2020-1961

Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e…

Fix: 2.0.15 / 2.1.6+
Fix from $2,300 2020-05-04