Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2026-32227 SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.1 CVE-2026-34191 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora… Apr Util after 1.6.3 Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-57308 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 HIGH 8.1 CVE-2026-56287 A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.… Fineract 1.15.0+ Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-57821 A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy… Fineract 1.15.0+ Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-35152 A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report p… Fineract 1.15.0+ Fix from $1,9502026-07-15 CRITICAL 9.8 CVE-2026-62390 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca… Kylin 5.0.4+ Fix from $2,3002026-07-14 MEDIUM 5.4 CVE-2025-53648 SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to… Gravitino 1.0.0+ Fix from $1,6002026-06-30 HIGH 8.1 CVE-2025-66336 Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated int… Doris Mcp Server 0.6.1+ Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2025-66335 Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow executio… Doris Mcp Server 0.6.1+ Fix from $1,6002026-04-20 MEDIUM 6.5 CVE-2026-23969 Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within… Superset 4.1.2+ Fix from $1,6002026-02-24 MEDIUM 6.5 CVE-2026-23980 Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user wit… Superset 6.0.0+ Fix from $1,6002026-02-24 MEDIUM 5.3 CVE-2025-66169 Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before… Camel 4.10.8 / 4.14.3+ Fix from $1,6002026-01-14 MEDIUM 5.4 CVE-2025-62728 SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i… Hive Mitigation only Fix from $1,6002025-11-26 HIGH 8.8 CVE-2025-62228 Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.… Flink Cdc Mitigation only Fix from $1,9502025-10-09 HIGH 7.6 CVE-2024-48988 SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade t… Streampark 2.1.6+ Fix from $1,9502025-08-22 MEDIUM 6.5 CVE-2025-55674 A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a… Superset 5.0.0+ Fix from $1,6002025-08-14 MEDIUM 6.5 CVE-2025-48912 An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression'… Superset 4.1.2+ Fix from $1,6002025-05-30 HIGH 8.8 CVE-2025-30473 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using… Airflow Common Sql Provider 1.24.1+ Fix from $1,9502025-04-07 HIGH 8.8 CVE-2024-53678 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitte… Vcl 2.5.2+ Fix from $1,9502025-03-25 MEDIUM 6.3 CVE-2025-27018 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user trigg… Apache Airflow Providers Mysql 6.2.0+ Fix from $1,6002025-03-19 HIGH 8.8 CVE-2024-32838 SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that al… Fineract 1.10.1+ Fix from $1,9502025-02-12 HIGH 8.8 CVE-2024-45387EPSS 42% An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", … Traffic Control 8.0.2+ Fix from $1,9502024-12-23 CRITICAL 9.8 CVE-2024-53947 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s… Superset 4.1.0+ Fix from $2,3002024-12-09 CRITICAL 9.8 CVE-2024-42361 Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin… Hertzbeat 1.6.0+ Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-39887 An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa… Superset 4.0.2+ Fix from $2,3002024-07-16 HIGH 8.1 CVE-2023-52290 In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en… Streampark 2.1.4+ Fix from $1,9502024-07-16 HIGH 8.1 CVE-2024-36263 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarin… Submarine Patch available Fix from $1,9502024-06-12 CRITICAL 9.8 CVE-2024-23538 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer… Fineract 1.9.0+ Fix from $2,3002024-03-29 CRITICAL 9.8 CVE-2024-23539 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer… Fineract 1.9.0+ Fix from $2,3002024-03-29