Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Airflow MEDIUM 6.5
CVE-2026-68971

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Nifi CRITICAL 9.8
CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Atlas HIGH 8.8
CVE-2026-50622

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated …

Fix: 2.6.0+
Fix from $1,950 2026-07-29
Hbase MEDIUM 6.5
CVE-2026-49326

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, f…

Fix: 2.5.15 / 2.6.6+
Fix from $1,600 2026-07-24
Activemq HIGH 7.5
CVE-2026-54475

Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations …

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Nifi HIGH 7.2
CVE-2026-44914

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Per…

Fix: 2.10.0+
Fix from $1,950 2026-06-22
Nifi HIGH 8.8
CVE-2026-39816

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi…

Fix: 2.9.0+
Fix from $1,950 2026-05-08
Polaris CRITICAL 9.9
CVE-2026-42809

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Airflow HIGH 8.1
CVE-2026-30911

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows…

Fix: 3.1.8+
Fix from $1,950 2026-03-17
Nifi MEDIUM 6.6
CVE-2026-25903

Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required …

Fix: 2.8.0+
Fix from $1,600 2026-02-17
Openoffice MEDIUM 5.3
CVE-2025-64407

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Openoffice HIGH 8.1
CVE-2025-64403

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64404

Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64405

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice MEDIUM 6.5
CVE-2025-64402

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64401

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Nifi MEDIUM 5.4
CVE-2024-56512

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenc…

Fix: 2.1.0+
Fix from $1,600 2024-12-28
Cloudstack MEDIUM 6.3
CVE-2024-45461

The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. …

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,600 2024-10-16
Zookeeper MEDIUM 5.3
CVE-2024-23944

Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by…

Fix: 3.8.4 / 3.9.2+
Fix from $1,600 2024-03-15
Airflow MEDIUM 5.9
CVE-2024-27906

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not hav…

Fix: 2.8.2+
Fix from $1,600 2024-02-29
Airflow MEDIUM 6.5
CVE-2023-50944

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …

Fix: 2.8.1+
Fix from $1,600 2024-01-24
Hertzbeat HIGH 7.5
CVE-2023-51650

Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized acc…

Fix: 1.4.1+
Fix from $1,950 2023-12-22
Dolphinscheduler MEDIUM 6.5
CVE-2023-49620

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), …

Fix: 3.1.0+
Fix from $1,600 2023-11-30
James HIGH 7.8
CVE-2023-26269

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation b…

Fix: 3.7.4+
Fix from $1,950 2023-04-03
Iotdb HIGH 7.5
CVE-2022-38370

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…

Mitigation only
Fix from $1,950 2022-09-05
Shenyu CRITICAL 9.1
CVE-2022-23944EPSS 79%

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $2,300 2022-01-25
Shenyu HIGH 7.5
CVE-2022-23945

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $1,950 2022-01-25
Ozone CRITICAL 9.1
CVE-2021-39231

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Ozone HIGH 8.8
CVE-2021-39232

In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

Fix: 1.2.0+
Fix from $1,950 2021-11-19
Ozone HIGH 8.8
CVE-2021-39236

In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

Fix: 1.2.0+
Fix from $1,950 2021-11-19