Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Ranger CRITICAL 9.8
CVE-2026-32227

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the…

No fix yet
Fix from $5,750 2026-08-10
Apr Util CRITICAL 9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…

Fix: after 1.6.3
Fix from $2,300 2026-08-06
Syncope CRITICAL 9.8
CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Fineract HIGH 8.1
CVE-2026-56287

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Fineract HIGH 8.1
CVE-2026-57821

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Fineract HIGH 8.8
CVE-2026-35152

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report p…

Fix: 1.15.0+
Fix from $1,950 2026-07-15
Kylin CRITICAL 9.8
CVE-2026-62390

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Gravitino MEDIUM 5.4
CVE-2025-53648

SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to…

Fix: 1.0.0+
Fix from $1,600 2026-06-30
Doris Mcp Server HIGH 8.1
CVE-2025-66336

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated int…

Fix: 0.6.1+
Fix from $1,950 2026-06-22
Doris Mcp Server MEDIUM 5.3
CVE-2025-66335

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow executio…

Fix: 0.6.1+
Fix from $1,600 2026-04-20
Superset MEDIUM 6.5
CVE-2026-23969

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within…

Fix: 4.1.2+
Fix from $1,600 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23980

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user wit…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Camel MEDIUM 5.3
CVE-2025-66169

Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before…

Fix: 4.10.8 / 4.14.3+
Fix from $1,600 2026-01-14
Hive MEDIUM 5.4
CVE-2025-62728

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i…

Mitigation only
Fix from $1,600 2025-11-26
Flink Cdc HIGH 8.8
CVE-2025-62228

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.…

Mitigation only
Fix from $1,950 2025-10-09
Streampark HIGH 7.6
CVE-2024-48988

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade t…

Fix: 2.1.6+
Fix from $1,950 2025-08-22
Superset MEDIUM 6.5
CVE-2025-55674

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a…

Fix: 5.0.0+
Fix from $1,600 2025-08-14
Superset MEDIUM 6.5
CVE-2025-48912

An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression'…

Fix: 4.1.2+
Fix from $1,600 2025-05-30
Airflow Common Sql Provider HIGH 8.8
CVE-2025-30473

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using…

Fix: 1.24.1+
Fix from $1,950 2025-04-07
Vcl HIGH 8.8
CVE-2024-53678

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitte…

Fix: 2.5.2+
Fix from $1,950 2025-03-25
Apache Airflow Providers Mysql MEDIUM 6.3
CVE-2025-27018

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user trigg…

Fix: 6.2.0+
Fix from $1,600 2025-03-19
Fineract HIGH 8.8
CVE-2024-32838

SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that al…

Fix: 1.10.1+
Fix from $1,950 2025-02-12
Traffic Control HIGH 8.8
CVE-2024-45387EPSS 42%

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …

Fix: 8.0.2+
Fix from $1,950 2024-12-23
Superset CRITICAL 9.8
CVE-2024-53947

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s…

Fix: 4.1.0+
Fix from $2,300 2024-12-09
Hertzbeat CRITICAL 9.8
CVE-2024-42361

Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin…

Fix: 1.6.0+
Fix from $2,300 2024-08-20
Superset CRITICAL 9.8
CVE-2024-39887

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…

Fix: 4.0.2+
Fix from $2,300 2024-07-16
Streampark HIGH 8.1
CVE-2023-52290

In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…

Fix: 2.1.4+
Fix from $1,950 2024-07-16
Submarine HIGH 8.1
CVE-2024-36263

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarin…

Patch available
Fix from $1,950 2024-06-12
Fineract CRITICAL 9.8
CVE-2024-23538

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…

Fix: 1.9.0+
Fix from $2,300 2024-03-29
Fineract CRITICAL 9.8
CVE-2024-23539

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…

Fix: 1.9.0+
Fix from $2,300 2024-03-29