Vulnerability index

Browse CVEs

74 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Ranger CRITICAL 9.8
CVE-2026-42537

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-44416

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-55799

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi…

No fix yet
Fix from $5,750 2026-08-10
Ofbiz HIGH 8.8
CVE-2026-50223

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataR…

Fix: 24.09.07+
Fix from $1,950 2026-06-10
Activemq HIGH 8.8
CVE-2026-45505

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Activemq HIGH 8.1
CVE-2026-42588

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Ofbiz HIGH 8.8
CVE-2026-46586

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vul…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-35086

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 2…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Flink HIGH 8.1
CVE-2026-35194

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr…

Fix: 1.20.4 / 2.0.2+
Fix from $1,950 2026-05-15
Cloudstack HIGH 8.8
CVE-2026-25077

Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp…

Fix: 4.20.3.0 / 4.22.0.1+
Fix from $1,950 2026-05-08
Atlas HIGH 8.1
CVE-2026-40563

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that …

Fix: 2.5.0+
Fix from $1,950 2026-05-04
Activemq HIGH 8.8
CVE-2026-40466

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Activemq HIGH 8.8
CVE-2026-41044

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Airflow HIGH 8.1
CVE-2025-54550

The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be ex…

Fix: 3.2.0+
Fix from $1,950 2026-04-15
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Ranger CRITICAL 9.8
CVE-2025-59059

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to…

Fix: 2.8.0+
Fix from $2,300 2026-03-03
Airflow HIGH 8.4
CVE-2024-56373

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server…

Fix: 2.11.1+
Fix from $1,950 2026-02-24
Avro HIGH 7.3
CVE-2025-33042

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro …

Fix: 1.11.5+
Fix from $1,950 2026-02-13
Ofbiz CRITICAL 9.8
CVE-2025-54466EPSS 15%

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects A…

Fix: 24.09.02+
Fix from $2,300 2025-08-15
Iotdb CRITICAL 9.8
CVE-2024-24780

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…

Fix: 1.3.4+
Fix from $2,300 2025-05-14
Kylin HIGH 7.2
CVE-2025-30067

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project adm…

Fix: 5.0.2+
Fix from $1,950 2025-03-27
Ambari HIGH 8.8
CVE-2024-51941

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbit…

Fix: after 2.7.8
Fix from $1,950 2025-01-21
Ofbiz CRITICAL 9.8
CVE-2024-47208

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.17+
Fix from $2,300 2024-11-18
Ofbiz HIGH 8.8
CVE-2024-48962

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…

Fix: 18.12.17+
Fix from $1,950 2024-11-18
Ofbiz CRITICAL 9.8
CVE-2024-45507EPSS 93%

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.16+
Fix from $2,300 2024-09-04
Dolphinscheduler CRITICAL 9.8
CVE-2024-43202

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgr…

Fix: 3.2.2+
Fix from $2,300 2024-08-20
Inlong CRITICAL 9.8
CVE-2024-36268

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12…

Fix: 1.13.0+
Fix from $2,300 2024-08-02
Streampark HIGH 8.8
CVE-2024-29178

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …

Fix: 2.1.4+
Fix from $1,950 2024-07-18
Airflow HIGH 8.8
CVE-2024-39877

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that …

Fix: 2.9.3+
Fix from $1,950 2024-07-17