Vulnerability index

Browse CVEs

74 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2026-42537 Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-44416 Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-55799 Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi… Ranger No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2026-50223 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataR… Ofbiz 24.09.07+ Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-45505 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 HIGH 8.1 CVE-2026-42588 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 HIGH 8.8 CVE-2026-46586 Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vul… Ofbiz 24.09.06+ Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-35086 Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 2… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-31379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 HIGH 8.1 CVE-2026-35194 Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr… Flink 1.20.4 / 2.0.2+ Fix from $1,9502026-05-15 HIGH 8.8 CVE-2026-25077 Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp… Cloudstack 4.20.3.0 / 4.22.0.1+ Fix from $1,9502026-05-08 HIGH 8.1 CVE-2026-40563 Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that … Atlas 2.5.0+ Fix from $1,9502026-05-04 HIGH 8.8 CVE-2026-40466 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41044 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 HIGH 8.1 CVE-2025-54550 The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be ex… Airflow 3.2.0+ Fix from $1,9502026-04-15 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to… Ranger 2.8.0+ Fix from $2,3002026-03-03 HIGH 8.4 CVE-2024-56373 DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server… Airflow 2.11.1+ Fix from $1,9502026-02-24 HIGH 7.3 CVE-2025-33042 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro … Avro 1.11.5+ Fix from $1,9502026-02-13 CRITICAL 9.8 CVE-2025-54466EPSS 15% Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects A… Ofbiz 24.09.02+ Fix from $2,3002025-08-15 CRITICAL 9.8 CVE-2024-24780 Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu… Iotdb 1.3.4+ Fix from $2,3002025-05-14 HIGH 7.2 CVE-2025-30067 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project adm… Kylin 5.0.2+ Fix from $1,9502025-03-27 HIGH 8.8 CVE-2024-51941 A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbit… Ambari after 2.7.8 Fix from $1,9502025-01-21 CRITICAL 9.8 CVE-2024-47208 Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.17+ Fix from $2,3002024-11-18 HIGH 8.8 CVE-2024-48962 Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a… Ofbiz 18.12.17+ Fix from $1,9502024-11-18 CRITICAL 9.8 CVE-2024-45507EPSS 93% Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.16+ Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-43202 Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgr… Dolphinscheduler 3.2.2+ Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-36268 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12… Inlong 1.13.0+ Fix from $2,3002024-08-02 HIGH 8.8 CVE-2024-29178 On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker … Streampark 2.1.4+ Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-39877 Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that … Airflow 2.9.3+ Fix from $1,9502024-07-17