Vulnerability index

Browse CVEs

58 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2026-64640 Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permissi… Polaris after 1.6.0 Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-50749 Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary… Answer 2.0.2+ Fix from $1,6002026-08-05 CRITICAL 9.1 CVE-2026-68980 Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor… Nifi 2.11.0+ Fix from $2,3002026-08-03 HIGH 8.2 CVE-2026-58159 Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 MEDIUM 6.3 CVE-2026-44911 Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submi… Nifi 2.10.0+ Fix from $1,6002026-06-22 HIGH 8.1 CVE-2026-47339 Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authentica… Apisix 3.17.0+ Fix from $1,9502026-06-19 MEDIUM 6.5 CVE-2026-42357 Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to acces… Dolphinscheduler 3.4.2+ Fix from $1,6002026-06-17 CRITICAL 9.8 CVE-2026-32966 DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache … Dolphinscheduler 3.4.2+ Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-32967 Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before… Dolphinscheduler 3.4.2+ Fix from $2,3002026-06-17 MEDIUM 5.3 CVE-2026-42526 In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic coul… Apache Airflow Providers Amazon 9.28.0+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2025-66170 The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in … Cloudstack 4.22.0.1+ Fix from $1,6002026-05-08 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 HIGH 8.1 CVE-2026-23902 Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not… Dolphinscheduler 3.4.1+ Fix from $1,9502026-04-24 HIGH 7.5 CVE-2026-32228 UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that … Airflow 3.2.0+ Fix from $1,9502026-04-18 MEDIUM 6.5 CVE-2026-23984 An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only ver… Superset 6.0.0+ Fix from $1,6002026-02-24 MEDIUM 6.5 CVE-2026-23982 An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a d… Superset 6.0.0+ Fix from $1,6002026-02-24 HIGH 8.8 CVE-2025-27696 Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read… Superset 4.1.2+ Fix from $1,9502025-05-13 MEDIUM 5.4 CVE-2025-24860 Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi… Cassandra 4.0.16 / 4.1.8+ Fix from $1,6002025-02-04 MEDIUM 6.5 CVE-2024-55633 Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed… Superset 4.1.0+ Fix from $1,6002024-12-12 MEDIUM 6.5 CVE-2024-53949 Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users … Superset 4.1.0+ Fix from $1,6002024-12-09 HIGH 8.1 CVE-2024-45106 Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t… Ozone Mitigation only Fix from $1,9502024-12-03 CRITICAL 9.8 CVE-2024-45216EPSS 91% Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen… Solr 8.11.4 / 9.7.0+ Fix from $2,3002024-10-16 HIGH 7.2 CVE-2024-42062 CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran… Cloudstack 4.18.2.3 / 4.19.1.1+ Fix from $1,9502024-08-07 CRITICAL 9.8 CVE-2024-38856 KEVEPSS 99% Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi… Ofbiz 18.12.15+ Fix from $2,3002024-08-05 CRITICAL 9.8 CVE-2024-36265 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co… Submarine Mitigation only Fix from $2,3002024-06-12 HIGH 7.4 CVE-2024-27309 While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditi… Kafka after 3.6.1 Fix from $1,9502024-04-12 MEDIUM 6.4 CVE-2024-29834 This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u… Pulsar 3.0.4 / 3.2.2+ Fix from $1,6002024-04-02 MEDIUM 5.4 CVE-2024-28098 The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off… Pulsar 2.10.6 / 2.11.4+ Fix from $1,6002024-03-12 HIGH 7.5 CVE-2024-27139 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated… Archiva Mitigation only Fix from $1,9502024-03-01 HIGH 7.5 CVE-2024-27138 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, … Archiva Mitigation only Fix from $1,9502024-03-01