Vulnerability index

Browse CVEs

58 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Polaris MEDIUM 6.5
CVE-2026-64640

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permissi…

Fix: after 1.6.0
Fix from $1,600 2026-08-06
Answer MEDIUM 6.5
CVE-2026-50749

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary…

Fix: 2.0.2+
Fix from $1,600 2026-08-05
Nifi CRITICAL 9.1
CVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Traffic Server HIGH 8.2
CVE-2026-58159

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Nifi MEDIUM 6.3
CVE-2026-44911

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submi…

Fix: 2.10.0+
Fix from $1,600 2026-06-22
Apisix HIGH 8.1
CVE-2026-47339

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authentica…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Dolphinscheduler MEDIUM 6.5
CVE-2026-42357

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to acces…

Fix: 3.4.2+
Fix from $1,600 2026-06-17
Dolphinscheduler CRITICAL 9.8
CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache …

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Dolphinscheduler CRITICAL 9.1
CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before…

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Apache Airflow Providers Amazon MEDIUM 5.3
CVE-2026-42526

In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic coul…

Fix: 9.28.0+
Fix from $1,600 2026-05-19
Cloudstack MEDIUM 6.5
CVE-2025-66170

The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in …

Fix: 4.22.0.1+
Fix from $1,600 2026-05-08
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Dolphinscheduler HIGH 8.1
CVE-2026-23902

Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not…

Fix: 3.4.1+
Fix from $1,950 2026-04-24
Airflow HIGH 7.5
CVE-2026-32228

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that …

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Superset MEDIUM 6.5
CVE-2026-23984

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only ver…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23982

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a d…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Superset HIGH 8.8
CVE-2025-27696

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read…

Fix: 4.1.2+
Fix from $1,950 2025-05-13
Cassandra MEDIUM 5.4
CVE-2025-24860

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi…

Fix: 4.0.16 / 4.1.8+
Fix from $1,600 2025-02-04
Superset MEDIUM 6.5
CVE-2024-55633

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed…

Fix: 4.1.0+
Fix from $1,600 2024-12-12
Superset MEDIUM 6.5
CVE-2024-53949

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users …

Fix: 4.1.0+
Fix from $1,600 2024-12-09
Ozone HIGH 8.1
CVE-2024-45106

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…

Mitigation only
Fix from $1,950 2024-12-03
Solr CRITICAL 9.8
CVE-2024-45216EPSS 91%

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…

Fix: 8.11.4 / 9.7.0+
Fix from $2,300 2024-10-16
Cloudstack HIGH 7.2
CVE-2024-42062

CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran…

Fix: 4.18.2.3 / 4.19.1.1+
Fix from $1,950 2024-08-07
Ofbiz CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi…

Fix: 18.12.15+
Fix from $2,300 2024-08-05
Submarine CRITICAL 9.8
CVE-2024-36265

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co…

Mitigation only
Fix from $2,300 2024-06-12
Kafka HIGH 7.4
CVE-2024-27309

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditi…

Fix: after 3.6.1
Fix from $1,950 2024-04-12
Pulsar MEDIUM 6.4
CVE-2024-29834

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u…

Fix: 3.0.4 / 3.2.2+
Fix from $1,600 2024-04-02
Pulsar MEDIUM 5.4
CVE-2024-28098

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off…

Fix: 2.10.6 / 2.11.4+
Fix from $1,600 2024-03-12
Archiva HIGH 7.5
CVE-2024-27139

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated…

Mitigation only
Fix from $1,950 2024-03-01
Archiva HIGH 7.5
CVE-2024-27138

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, …

Mitigation only
Fix from $1,950 2024-03-01