Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HTTP Server MEDIUM 5.3
CVE-2024-40725

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handler…

Mitigation only
Fix from $1,600 2024-07-18
HTTP Server MEDIUM 6.2
CVE-2024-39884

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and si…

Mitigation only
Fix from $1,600 2024-07-04
Submarine CRITICAL 9.8
CVE-2024-36265

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co…

Mitigation only
Fix from $2,300 2024-06-12
Karaf Cave CRITICAL 9.1
CVE-2024-34365

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A…

Mitigation only
Fix from $2,300 2024-05-14
Hive MEDIUM 6.6
CVE-2023-35701

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and…

Mitigation only
Fix from $1,600 2024-05-03
Apisix MEDIUM 6.3
CVE-2024-32638

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue af…

Mitigation only
Fix from $1,600 2024-05-02
Zeppelin MEDIUM 5.3
CVE-2024-31863

Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 bef…

Mitigation only
Fix from $1,600 2024-04-09
Archiva HIGH 7.5
CVE-2024-27139

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated…

Mitigation only
Fix from $1,950 2024-03-01
Archiva MEDIUM 5.4
CVE-2024-27140

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva…

Mitigation only
Fix from $1,600 2024-03-01
Archiva HIGH 7.5
CVE-2024-27138

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, …

Mitigation only
Fix from $1,950 2024-03-01
Aurora CRITICAL 9.1
CVE-2024-27905

** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte…

Mitigation only
Fix from $2,300 2024-02-27
James HIGH 7.1
CVE-2023-51747

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ…

Mitigation only
Fix from $1,950 2024-02-27
James CRITICAL 9.8
CVE-2023-51518

Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi…

Mitigation only
Fix from $2,300 2024-02-27
Dubbo CRITICAL 9.8
CVE-2023-46279

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the …

Mitigation only
Fix from $2,300 2023-12-15
Tiles HIGH 7.5
CVE-2023-49735

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML…

Mitigation only
Fix from $1,950 2023-11-30
Shenyu MEDIUM 6.5
CVE-2023-25753

There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip…

Mitigation only
Fix from $1,600 2023-10-19
Tomcat HIGH 7.5
CVE-2023-34981

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header…

Mitigation only
Fix from $1,950 2023-06-21
Accumulo CRITICAL 9.8
CVE-2023-34340

Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta…

Mitigation only
Fix from $2,300 2023-06-21
Inlong MEDIUM 6.5
CVE-2023-31101

Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 th…

Mitigation only
Fix from $1,600 2023-05-22
Ranger HIGH 8.8
CVE-2022-45048

Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe…

Mitigation only
Fix from $1,950 2023-05-05
Iotdb Web Workbench CRITICAL 9.8
CVE-2023-30771

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd…

Mitigation only
Fix from $2,300 2023-04-17
Inlong MEDIUM 5.3
CVE-2023-30465

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i…

Mitigation only
Fix from $1,600 2023-04-11
Unstructured Information Management Architecture HIGH 8.8
CVE-2023-28935

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software …

Mitigation only
Fix from $1,950 2023-03-30
Shenyu HIGH 8.8
CVE-2022-42735

Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators…

Mitigation only
Fix from $1,950 2023-02-15
Portable Runtime CRITICAL 9.8
CVE-2022-24963

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a …

Mitigation only
Fix from $2,300 2023-01-31
Batik HIGH 7.5
CVE-2022-40146EPSS 6%

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec…

Mitigation only
Fix from $1,950 2022-09-22
Batik MEDIUM 5.3
CVE-2022-38398

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a…

Mitigation only
Fix from $1,600 2022-09-22
Batik MEDIUM 5.3
CVE-2022-38648

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A…

Mitigation only
Fix from $1,600 2022-09-22
Soap HIGH 7.5
CVE-2022-40705

An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files …

Mitigation only
Fix from $1,950 2022-09-22
Iotdb HIGH 8.8
CVE-2022-38369

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

No fix yet
Fix from $1,950 2022-09-05