Vulnerability index

Browse CVEs

74 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-39864 The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio… Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05 CRITICAL 9.8 CVE-2024-38346 The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and … Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05 MEDIUM 6.6 CVE-2023-35701 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and… Hive Mitigation only Fix from $1,6002024-05-03 CRITICAL 9.8 CVE-2024-31864 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic… Zeppelin 0.11.1+ Fix from $2,3002024-04-09 HIGH 8.8 CVE-2023-50379 Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cl… Ambari 2.7.8+ Fix from $1,9502024-02-27 HIGH 7.5 CVE-2023-51770 Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr… Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2023-49109 Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr… Dolphinscheduler 3.2.1+ Fix from $2,3002024-02-20 CRITICAL 9.8 CVE-2023-46226 Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to v… Iotdb 1.3.0+ Fix from $2,3002024-01-15 CRITICAL 9.8 CVE-2023-51784 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, … Inlong 1.10.0+ Fix from $2,3002024-01-03 HIGH 8.8 CVE-2023-51387 Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo… Hertzbeat 1.4.1+ Fix from $1,9502023-12-22 CRITICAL 9.8 CVE-2023-49070EPSS 95% Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Us… Ofbiz 18.12.10+ Fix from $2,3002023-12-05 HIGH 8.8 CVE-2023-36542 Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an … Nifi after 1.22.0 Fix from $1,9502023-07-29 CRITICAL 9.8 CVE-2023-37582EPSS 90% The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version … Rocketmq after 5.1.1 Fix from $2,3002023-07-12 HIGH 8.8 CVE-2023-34468EPSS 64% The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user … Nifi 1.22.0+ Fix from $1,9502023-06-12 CRITICAL 9.8 CVE-2023-33246 KEVEPSS 97% For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu… Rocketmq 4.9.6 / 5.1.1+ Fix from $2,3002023-05-24 CRITICAL 9.8 CVE-2023-28706 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects… Airflow Hive Provider 6.0.0+ Fix from $2,3002023-04-07 HIGH 7.8 CVE-2022-38745 Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro… Openoffice 4.1.14+ Fix from $1,9502023-03-24 HIGH 8.8 CVE-2022-40127EPSS 86% A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually … Airflow 2.4.0+ Fix from $1,9502022-11-14 CRITICAL 9.8 CVE-2022-42889EPSS 100% Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat… Commons Text 1.10.0 / 7.5.0+ Fix from $2,3002022-10-13 CRITICAL 9.8 CVE-2022-26112 In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to… Pinot 0.11.0+ Fix from $2,3002022-09-23 HIGH 7.5 CVE-2022-25813EPSS 67% In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a … Ofbiz 18.12.06+ Fix from $1,9502022-09-02 CRITICAL 9.1 CVE-2021-44521EPSS 55% When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab… Cassandra 3.0.26 / 3.11.12+ Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2021-45029EPSS 6% Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Mitigation only Fix from $2,3002022-01-25 CRITICAL 9.9 CVE-2021-21345EPSS 72% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 7.2 CVE-2019-0193 KEVEPSS 84% In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh… Solr 7.7.3 / 8.1.2+ Fix from $1,9502019-08-01 CRITICAL 9.8 CVE-2018-11780EPSS 11% A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. Spamassassin 3.4.2+ Fix from $2,3002018-09-17 HIGH 7.8 CVE-2018-11781 Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. Spamassassin 3.4.2+ Fix from $1,9502018-09-17 CRITICAL 9.8 CVE-2011-2767EPSS 9% mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do… Mod Perl after 2.0.10 Fix from $2,3002018-08-26 HIGH 7.2 CVE-2015-0249 The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary… Roller Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.8 CVE-2014-3582 In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo… Ambari after 2.2.2 Fix from $2,3002017-03-29