Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Iotdb HIGH 7.5
CVE-2022-38370

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…

Mitigation only
Fix from $1,950 2022-09-05
Jetspeed CRITICAL 9.8
CVE-2022-32533

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…

Mitigation only
Fix from $2,300 2022-07-06
HTTP Server HIGH 7.5
CVE-2022-30522EPSS 90%

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m…

Mitigation only
Fix from $1,950 2022-06-09
Jena CRITICAL 9.8
CVE-2022-28890

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…

Mitigation only
Fix from $2,300 2022-05-05
Shenyu CRITICAL 9.8
CVE-2021-45029EPSS 6%

Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Mitigation only
Fix from $2,300 2022-01-25
Shardingsphere Elasticjob Ui MEDIUM 6.5
CVE-2022-22733EPSS 38%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco…

Mitigation only
Fix from $1,600 2022-01-20
Guacamole HIGH 8.8
CVE-2021-43999

Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo…

Mitigation only
Fix from $1,950 2022-01-11
Kylin CRITICAL 9.8
CVE-2021-45456EPSS 89%

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…

Mitigation only
Fix from $2,300 2022-01-06
Pluto MEDIUM 6.1
CVE-2021-36739

The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) at…

Mitigation only
Fix from $1,600 2022-01-06
Sling Commons Messaging Mail HIGH 7.4
CVE-2021-44549

Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "…

Mitigation only
Fix from $1,950 2021-12-14
Shenyu CRITICAL 9.8
CVE-2021-37580EPSS 40%

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…

Mitigation only
Fix from $2,300 2021-11-16
Openoffice HIGH 7.8
CVE-2021-28129

While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi…

Mitigation only
Fix from $1,950 2021-10-07
Ddlutils CRITICAL 9.8
CVE-2021-41616

Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…

Mitigation only
Fix from $2,300 2021-09-30
Apisix Dashboard MEDIUM 5.3
CVE-2021-33190

In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external net…

Mitigation only
Fix from $1,600 2021-06-08
Traffic Server HIGH 7.5
CVE-2021-27737

Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

No fix yet
Fix from $1,950 2021-05-14
Airflow MEDIUM 6.5
CVE-2021-26559

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur…

Mitigation only
Fix from $1,600 2021-02-17
Airflow MEDIUM 5.3
CVE-2021-26697

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…

Mitigation only
Fix from $1,600 2021-02-17
Artemis HIGH 7.5
CVE-2021-26118

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 …

Mitigation only
Fix from $1,950 2021-01-27
Html\/java Api HIGH 7.0
CVE-2020-17534

There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/J…

Mitigation only
Fix from $1,950 2021-01-11
Dolphinscheduler MEDIUM 6.5
CVE-2020-13922

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter…

Mitigation only
Fix from $1,600 2021-01-11
Dolphinscheduler CRITICAL 9.8
CVE-2020-11974EPSS 8%

In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.

Mitigation only
Fix from $2,300 2020-12-18
Pulsar Manager MEDIUM 6.5
CVE-2020-17520

In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing…

Mitigation only
Fix from $1,600 2020-12-18
Hadoop HIGH 8.8
CVE-2018-11764

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even …

Mitigation only
Fix from $1,950 2020-10-21
Kylin MEDIUM 5.3
CVE-2020-13937EPSS 78%

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alph…

Mitigation only
Fix from $1,600 2020-10-19
Ofbiz MEDIUM 6.1
CVE-2020-9496EPSS 99%

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

No fix yet
Fix from $1,600 2020-07-15
Couchdb CRITICAL 9.8
CVE-2020-1955

CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…

Mitigation only
Fix from $2,300 2020-05-20
Ofbiz HIGH 8.8
CVE-2019-0235EPSS 33%

Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

No fix yet
Fix from $1,950 2020-04-30
Ofbiz HIGH 7.5
CVE-2019-12425

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

Mitigation only
Fix from $1,950 2020-04-30
Heron CRITICAL 9.8
CVE-2020-1964

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …

Mitigation only
Fix from $2,300 2020-04-16
Druid MEDIUM 6.5
CVE-2020-1958

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…

Mitigation only
Fix from $1,600 2020-04-01