Vulnerability index

Browse CVEs

74 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Cloudstack CRITICAL 9.8
CVE-2024-39864

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio…

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05
Cloudstack CRITICAL 9.8
CVE-2024-38346

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05
Hive MEDIUM 6.6
CVE-2023-35701

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and…

Mitigation only
Fix from $1,600 2024-05-03
Zeppelin CRITICAL 9.8
CVE-2024-31864

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic…

Fix: 0.11.1+
Fix from $2,300 2024-04-09
Ambari HIGH 8.8
CVE-2023-50379

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cl…

Fix: 2.7.8+
Fix from $1,950 2024-02-27
Dolphinscheduler HIGH 7.5
CVE-2023-51770

Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr…

Fix: 3.2.1+
Fix from $1,950 2024-02-20
Dolphinscheduler CRITICAL 9.8
CVE-2023-49109

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr…

Fix: 3.2.1+
Fix from $2,300 2024-02-20
Iotdb CRITICAL 9.8
CVE-2023-46226

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to v…

Fix: 1.3.0+
Fix from $2,300 2024-01-15
Inlong CRITICAL 9.8
CVE-2023-51784

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, …

Fix: 1.10.0+
Fix from $2,300 2024-01-03
Hertzbeat HIGH 8.8
CVE-2023-51387

Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo…

Fix: 1.4.1+
Fix from $1,950 2023-12-22
Ofbiz CRITICAL 9.8
CVE-2023-49070EPSS 95%

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Us…

Fix: 18.12.10+
Fix from $2,300 2023-12-05
Nifi HIGH 8.8
CVE-2023-36542

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an …

Fix: after 1.22.0
Fix from $1,950 2023-07-29
Rocketmq CRITICAL 9.8
CVE-2023-37582EPSS 90%

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version …

Fix: after 5.1.1
Fix from $2,300 2023-07-12
Nifi HIGH 8.8
CVE-2023-34468EPSS 64%

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user …

Fix: 1.22.0+
Fix from $1,950 2023-06-12
Rocketmq CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu…

Fix: 4.9.6 / 5.1.1+
Fix from $2,300 2023-05-24
Airflow Hive Provider CRITICAL 9.8
CVE-2023-28706

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects…

Fix: 6.0.0+
Fix from $2,300 2023-04-07
Openoffice HIGH 7.8
CVE-2022-38745

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro…

Fix: 4.1.14+
Fix from $1,950 2023-03-24
Airflow HIGH 8.8
CVE-2022-40127EPSS 86%

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually …

Fix: 2.4.0+
Fix from $1,950 2022-11-14
Commons Text CRITICAL 9.8
CVE-2022-42889EPSS 100%

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…

Fix: 1.10.0 / 7.5.0+
Fix from $2,300 2022-10-13
Pinot CRITICAL 9.8
CVE-2022-26112

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…

Fix: 0.11.0+
Fix from $2,300 2022-09-23
Ofbiz HIGH 7.5
CVE-2022-25813EPSS 67%

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a …

Fix: 18.12.06+
Fix from $1,950 2022-09-02
Cassandra CRITICAL 9.1
CVE-2021-44521EPSS 55%

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…

Fix: 3.0.26 / 3.11.12+
Fix from $2,300 2022-02-11
Shenyu CRITICAL 9.8
CVE-2021-45029EPSS 6%

Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Mitigation only
Fix from $2,300 2022-01-25
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Solr HIGH 7.2
CVE-2019-0193 KEVEPSS 84%

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…

Fix: 7.7.3 / 8.1.2+
Fix from $1,950 2019-08-01
Spamassassin CRITICAL 9.8
CVE-2018-11780EPSS 11%

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

Fix: 3.4.2+
Fix from $2,300 2018-09-17
Spamassassin HIGH 7.8
CVE-2018-11781

Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

Fix: 3.4.2+
Fix from $1,950 2018-09-17
Mod Perl CRITICAL 9.8
CVE-2011-2767EPSS 9%

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do…

Fix: after 2.0.10
Fix from $2,300 2018-08-26
Roller HIGH 7.2
CVE-2015-0249

The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…

Mitigation only
Fix from $1,950 2017-07-17
Ambari CRITICAL 9.8
CVE-2014-3582

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo…

Fix: after 2.2.2
Fix from $2,300 2017-03-29