Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-40725 A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handler… HTTP Server Mitigation only Fix from $1,6002024-07-18 MEDIUM 6.2 CVE-2024-39884 A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and si… HTTP Server Mitigation only Fix from $1,6002024-07-04 CRITICAL 9.8 CVE-2024-36265 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co… Submarine Mitigation only Fix from $2,3002024-06-12 CRITICAL 9.1 CVE-2024-34365 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A… Karaf Cave Mitigation only Fix from $2,3002024-05-14 MEDIUM 6.6 CVE-2023-35701 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and… Hive Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.3 CVE-2024-32638 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue af… Apisix Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.3 CVE-2024-31863 Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 bef… Zeppelin Mitigation only Fix from $1,6002024-04-09 HIGH 7.5 CVE-2024-27139 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated… Archiva Mitigation only Fix from $1,9502024-03-01 MEDIUM 5.4 CVE-2024-27140 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva… Archiva Mitigation only Fix from $1,6002024-03-01 HIGH 7.5 CVE-2024-27138 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, … Archiva Mitigation only Fix from $1,9502024-03-01 CRITICAL 9.1 CVE-2024-27905 ** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte… Aurora Mitigation only Fix from $2,3002024-02-27 HIGH 7.1 CVE-2023-51747 Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ… James Mitigation only Fix from $1,9502024-02-27 CRITICAL 9.8 CVE-2023-51518 Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi… James Mitigation only Fix from $2,3002024-02-27 CRITICAL 9.8 CVE-2023-46279 Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the … Dubbo Mitigation only Fix from $2,3002023-12-15 HIGH 7.5 CVE-2023-49735 ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML… Tiles Mitigation only Fix from $1,9502023-11-30 MEDIUM 6.5 CVE-2023-25753 There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip… Shenyu Mitigation only Fix from $1,6002023-10-19 HIGH 7.5 CVE-2023-34981 A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header… Tomcat Mitigation only Fix from $1,9502023-06-21 CRITICAL 9.8 CVE-2023-34340 Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta… Accumulo Mitigation only Fix from $2,3002023-06-21 MEDIUM 6.5 CVE-2023-31101 Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 th… Inlong Mitigation only Fix from $1,6002023-05-22 HIGH 8.8 CVE-2022-45048 Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe… Ranger Mitigation only Fix from $1,9502023-05-05 CRITICAL 9.8 CVE-2023-30771 Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd… Iotdb Web Workbench Mitigation only Fix from $2,3002023-04-17 MEDIUM 5.3 CVE-2023-30465 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i… Inlong Mitigation only Fix from $1,6002023-04-11 HIGH 8.8 CVE-2023-28935 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software … Unstructured Information Management Architecture Mitigation only Fix from $1,9502023-03-30 HIGH 8.8 CVE-2022-42735 Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators… Shenyu Mitigation only Fix from $1,9502023-02-15 CRITICAL 9.8 CVE-2022-24963 Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a … Portable Runtime Mitigation only Fix from $2,3002023-01-31 HIGH 7.5 CVE-2022-40146EPSS 6% Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec… Batik Mitigation only Fix from $1,9502022-09-22 MEDIUM 5.3 CVE-2022-38398 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a… Batik Mitigation only Fix from $1,6002022-09-22 MEDIUM 5.3 CVE-2022-38648 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A… Batik Mitigation only Fix from $1,6002022-09-22 HIGH 7.5 CVE-2022-40705 An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files … Soap Mitigation only Fix from $1,9502022-09-22 HIGH 8.8 CVE-2022-38369 Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue. Iotdb No fix yet Fix from $1,9502022-09-05