Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fory CRITICAL 9.8
CVE-2025-61622EPSS 41%

Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…

Fix: after 0.12.2
Fix from $2,300 2025-10-01
Airflow MEDIUM 6.5
CVE-2025-54831

Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connecti…

Mitigation only
Fix from $1,600 2025-09-26
Iotdb MEDIUM 5.3
CVE-2025-48459

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to…

Fix: 2.0.5+
Fix from $1,600 2025-09-24
Iotdb HIGH 7.5
CVE-2025-48392

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to…

Fix: 2.0.5+
Fix from $1,950 2025-09-24
Fory MEDIUM 6.5
CVE-2025-59328

A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr…

Fix: 0.12.2+
Fix from $1,600 2025-09-15
Hertzbeat HIGH 8.8
CVE-2025-24404

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated accou…

Fix: 1.7.0+
Fix from $1,950 2025-09-09
Hertzbeat HIGH 8.8
CVE-2025-48208

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker nee…

Fix: 1.7.3+
Fix from $1,950 2025-09-09
Jackrabbit MEDIUM 6.5
CVE-2025-58782

Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Co…

Fix: 2.22.2+
Fix from $1,600 2025-09-08
Dolphinscheduler CRITICAL 9.8
CVE-2024-43166

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recomme…

Fix: 3.2.2+
Fix from $2,300 2025-09-03
Dolphinscheduler HIGH 8.8
CVE-2024-43115

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This…

Fix: 3.2.2+
Fix from $1,950 2025-09-03
Cassandra HIGH 8.8
CVE-2025-26467

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to s…

Fix: 3.0.31 / 3.11.18+
Fix from $1,950 2025-08-25
Log4cxx HIGH 7.5
CVE-2025-54813

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an at…

Fix: 1.5.0+
Fix from $1,950 2025-08-22
Log4cxx MEDIUM 5.4
CVE-2025-54812

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing …

Fix: 1.5.0+
Fix from $1,600 2025-08-22
Streampark HIGH 7.6
CVE-2024-48988

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade t…

Fix: 2.1.6+
Fix from $1,950 2025-08-22
Tika HIGH 8.4
CVE-2025-54988EPSS 9%

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out…

Fix: 3.2.2+
Fix from $1,950 2025-08-20
Eventmesh MEDIUM 6.3
CVE-2024-39954

CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse…

Fix: 1.12.0+
Fix from $1,600 2025-08-20
Commons Ognl HIGH 8.8
CVE-2025-53192

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Ap…

Mitigation only
Fix from $1,950 2025-08-18
Ofbiz CRITICAL 9.8
CVE-2025-54466EPSS 15%

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects A…

Fix: 24.09.02+
Fix from $2,300 2025-08-15
Superset MEDIUM 6.5
CVE-2025-55674

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a…

Fix: 5.0.0+
Fix from $1,600 2025-08-14
Superset MEDIUM 6.5
CVE-2025-55675

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated use…

Fix: 5.0.0+
Fix from $1,600 2025-08-14
Superset MEDIUM 5.4
CVE-2025-55672

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit cha…

Fix: 5.0.0+
Fix from $1,600 2025-08-14
Brpc HIGH 7.5
CVE-2025-54472

Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi…

Fix: 1.14.1+
Fix from $1,950 2025-08-14
Tomcat MEDIUM 6.5
CVE-2025-55668

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 t…

Fix: 9.0.106 / 10.1.42+
Fix from $1,600 2025-08-13
Tomcat HIGH 7.5
CVE-2025-48989

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache …

Fix: 9.0.108 / 10.1.44+
Fix from $1,950 2025-08-13
Seata CRITICAL 9.8
CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm…

Mitigation only
Fix from $2,300 2025-08-08
Cxf CRITICAL 9.8
CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…

Fix: 3.6.8 / 4.0.9+
Fix from $2,300 2025-08-08
Zeppelin MEDIUM 5.3
CVE-2024-51775

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without …

Fix: 0.12.0+
Fix from $1,600 2025-08-03
Zeppelin MEDIUM 6.1
CVE-2024-41177

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recomme…

Fix: 0.12.0+
Fix from $1,600 2025-08-03
Zeppelin MEDIUM 5.3
CVE-2024-52279

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. …

Fix: 0.12.0+
Fix from $1,600 2025-08-03
Jspwiki MEDIUM 6.1
CVE-2025-24854

A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute …

Fix: 2.12.3+
Fix from $1,600 2025-07-31