Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-38370 Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users… Iotdb Mitigation only Fix from $1,9502022-09-05 CRITICAL 9.8 CVE-2022-32533 Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett… Jetspeed Mitigation only Fix from $2,3002022-07-06 HIGH 7.5 CVE-2022-30522EPSS 90% If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m… HTTP Server Mitigation only Fix from $1,9502022-06-09 CRITICAL 9.8 CVE-2022-28890 A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers… Jena Mitigation only Fix from $2,3002022-05-05 CRITICAL 9.8 CVE-2021-45029EPSS 6% Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Mitigation only Fix from $2,3002022-01-25 MEDIUM 6.5 CVE-2022-22733EPSS 38% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco… Shardingsphere Elasticjob Ui Mitigation only Fix from $1,6002022-01-20 HIGH 8.8 CVE-2021-43999 Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo… Guacamole Mitigation only Fix from $1,9502022-01-11 CRITICAL 9.8 CVE-2021-45456EPSS 89% Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet… Kylin Mitigation only Fix from $2,3002022-01-06 MEDIUM 6.1 CVE-2021-36739 The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) at… Pluto Mitigation only Fix from $1,6002022-01-06 HIGH 7.4 CVE-2021-44549 Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "… Sling Commons Messaging Mail Mitigation only Fix from $1,9502021-12-14 CRITICAL 9.8 CVE-2021-37580EPSS 40% A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff… Shenyu Mitigation only Fix from $2,3002021-11-16 HIGH 7.8 CVE-2021-28129 While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi… Openoffice Mitigation only Fix from $1,9502021-10-07 CRITICAL 9.8 CVE-2021-41616 Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR… Ddlutils Mitigation only Fix from $2,3002021-09-30 MEDIUM 5.3 CVE-2021-33190 In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external net… Apisix Dashboard Mitigation only Fix from $1,6002021-06-08 HIGH 7.5 CVE-2021-27737 Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin. Traffic Server No fix yet Fix from $1,9502021-05-14 MEDIUM 6.5 CVE-2021-26559 Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur… Airflow Mitigation only Fix from $1,6002021-02-17 MEDIUM 5.3 CVE-2021-26697 The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h… Airflow Mitigation only Fix from $1,6002021-02-17 HIGH 7.5 CVE-2021-26118 While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 … Artemis Mitigation only Fix from $1,9502021-01-27 HIGH 7.0 CVE-2020-17534 There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/J… Html\/java Api Mitigation only Fix from $1,9502021-01-11 MEDIUM 6.5 CVE-2020-13922 Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter… Dolphinscheduler Mitigation only Fix from $1,6002021-01-11 CRITICAL 9.8 CVE-2020-11974EPSS 8% In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database. Dolphinscheduler Mitigation only Fix from $2,3002020-12-18 MEDIUM 6.5 CVE-2020-17520 In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing… Pulsar Manager Mitigation only Fix from $1,6002020-12-18 HIGH 8.8 CVE-2018-11764 Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even … Hadoop Mitigation only Fix from $1,9502020-10-21 MEDIUM 5.3 CVE-2020-13937EPSS 78% Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alph… Kylin Mitigation only Fix from $1,6002020-10-19 MEDIUM 6.1 CVE-2020-9496EPSS 99% XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 Ofbiz No fix yet Fix from $1,6002020-07-15 CRITICAL 9.8 CVE-2020-1955 CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e… Couchdb Mitigation only Fix from $2,3002020-05-20 HIGH 8.8 CVE-2019-0235EPSS 33% Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. Ofbiz No fix yet Fix from $1,9502020-04-30 HIGH 7.5 CVE-2019-12425 Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host Ofbiz Mitigation only Fix from $1,9502020-04-30 CRITICAL 9.8 CVE-2020-1964 It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to … Heron Mitigation only Fix from $2,3002020-04-16 MEDIUM 6.5 CVE-2020-1958 When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali… Druid Mitigation only Fix from $1,6002020-04-01