Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Skywalking MEDIUM 6.1
CVE-2025-54057

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalki…

Fix: 10.3.0+
Fix from $1,600 2025-11-27
Druid CRITICAL 9.8
CVE-2025-59390

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…

Fix: 35.0.0+
Fix from $2,300 2025-11-26
Hive MEDIUM 5.4
CVE-2025-62728

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i…

Mitigation only
Fix from $1,600 2025-11-26
Syncope HIGH 7.5
CVE-2025-65998

Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default optio…

Fix: 3.0.15 / 4.0.3+
Fix from $1,950 2025-11-24
Causeway MEDIUM 6.3
CVE-2025-64408EPSS 11%

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul…

Fix: 3.5.0+
Fix from $1,600 2025-11-19
Openoffice MEDIUM 5.3
CVE-2025-64407

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Ofbiz HIGH 7.3
CVE-2025-59118

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommen…

Fix: 24.09.03+
Fix from $1,950 2025-11-12
Ofbiz MEDIUM 6.5
CVE-2025-61623

Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to…

Fix: 24.09.03+
Fix from $1,600 2025-11-12
Openoffice HIGH 8.1
CVE-2025-64403

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64404

Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64405

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Openoffice MEDIUM 6.5
CVE-2025-64402

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,600 2025-11-12
Openoffice HIGH 7.5
CVE-2025-64401

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…

Fix: 4.1.16+
Fix from $1,950 2025-11-12
Doris Mcp Server MEDIUM 5.4
CVE-2025-58337

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that s…

Fix: 0.6.0+
Fix from $1,600 2025-11-05
Apisix HIGH 7.5
CVE-2025-62232

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…

Fix: 3.14.0+
Fix from $1,950 2025-10-31
Airflow MEDIUM 5.4
CVE-2025-62402

API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environmen…

Fix: 3.1.1+
Fix from $1,600 2025-10-30
Tomcat MEDIUM 5.3
CVE-2025-61795

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a m…

Fix: 9.0.110 / 10.0.27+
Fix from $1,600 2025-10-27
Tomcat CRITICAL 9.6
CVE-2025-55754EPSS 10%

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log mes…

Fix: 9.0.109 / 10.0.27+
Fix from $2,300 2025-10-27
Tomcat HIGH 7.5
CVE-2025-55752EPSS 67%

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized b…

Fix: 9.0.109 / 10.0.27+
Fix from $1,950 2025-10-27
Syncope HIGH 7.2
CVE-2025-57738EPSS 23%

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few …

Fix: 3.0.14 / 4.0.2+
Fix from $1,950 2025-10-20
Geode HIGH 8.8
CVE-2025-47410

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricke…

Fix: 1.15.2+
Fix from $1,950 2025-10-18
Traffic Control HIGH 7.5
CVE-2025-61581

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic…

Fix: after 8.0.2
Fix from $1,950 2025-10-16
Activemq Nms Amqp CRITICAL 9.8
CVE-2025-54539

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ …

Fix: 2.4.0+
Fix from $2,300 2025-10-16
Spark MEDIUM 6.5
CVE-2025-55039

This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure defau…

Fix: 3.4.4 / 3.5.2+
Fix from $1,600 2025-10-15
Geode MEDIUM 6.1
CVE-2024-44088

Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a…

Fix: 1.15.2+
Fix from $1,600 2025-10-14
Streampark HIGH 7.3
CVE-2025-30001

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users a…

Fix: 2.1.6+
Fix from $1,950 2025-10-10
Flink Cdc HIGH 8.8
CVE-2025-62228

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.…

Mitigation only
Fix from $1,950 2025-10-09
Kylin HIGH 7.5
CVE-2025-61734EPSS 18%

Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin acce…

Fix: 5.0.3+
Fix from $1,950 2025-10-02
Kylin HIGH 7.3
CVE-2025-61735

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as…

Fix: 5.0.3+
Fix from $1,950 2025-10-02
Kylin HIGH 7.5
CVE-2025-61733

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. …

Fix: 5.0.3+
Fix from $1,950 2025-10-02