Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Httpclient HIGH 7.5
CVE-2025-27820

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered b…

Fix: 5.4.3+
Fix from $1,950 2025-04-24
Kvrocks HIGH 7.5
CVE-2025-26413

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it …

Fix: 2.12.0+
Fix from $1,950 2025-04-22
Activemq Nms Openwire CRITICAL 9.8
CVE-2025-29953

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client befor…

Fix: 2.1.1+
Fix from $2,300 2025-04-18
Hertzbeat MEDIUM 6.5
CVE-2024-56736

Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are rec…

Fix: 1.7.0+
Fix from $1,600 2025-04-16
Roller HIGH 8.8
CVE-2025-24859

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after passwor…

Fix: 6.1.5+
Fix from $1,950 2025-04-14
Artemis MEDIUM 6.5
CVE-2025-27391

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when th…

Fix: 2.40.0+
Fix from $1,600 2025-04-09
Pulsar MEDIUM 6.5
CVE-2025-30677

Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka …

Fix: 3.0.11 / 3.3.6+
Fix from $1,600 2025-04-09
Poi MEDIUM 5.3
CVE-2025-31672

Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file forma…

Fix: 5.4.0+
Fix from $1,600 2025-04-09
Airflow Common Sql Provider HIGH 8.8
CVE-2025-30473

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using…

Fix: 1.24.1+
Fix from $1,950 2025-04-07
Traffic Server HIGH 7.5
CVE-2024-53868

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through …

Fix: 9.2.10 / 10.0.5+
Fix from $1,950 2025-04-03
Ofbiz MEDIUM 6.1
CVE-2025-30676EPSS 65%

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…

Fix: 18.12.19+
Fix from $1,600 2025-04-01
Camel MEDIUM 6.5
CVE-2025-30177

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0…

Fix: 4.8.6 / 4.10.3+
Fix from $1,600 2025-04-01
Pinot CRITICAL 9.8
CVE-2024-56325EPSS 79%

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Examp…

Fix: 1.3.0+
Fix from $2,300 2025-04-01
Parquet Java CRITICAL 9.8
CVE-2025-30065EPSS 41%

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are reco…

Fix: 1.15.1+
Fix from $2,300 2025-04-01
Answer MEDIUM 6.5
CVE-2025-29868

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user use…

Fix: after 1.4.2
Fix from $1,600 2025-04-01
Kylin HIGH 7.2
CVE-2025-30067

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project adm…

Fix: 5.0.2+
Fix from $1,950 2025-03-27
Kylin MEDIUM 6.5
CVE-2024-48944

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d…

Fix: 5.0.2+
Fix from $1,600 2025-03-27
Vcl MEDIUM 5.4
CVE-2024-53679

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with…

Fix: 2.5.2+
Fix from $1,600 2025-03-25
Vcl HIGH 8.8
CVE-2024-53678

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitte…

Fix: 2.5.2+
Fix from $1,950 2025-03-25
Commons Vfs MEDIUM 5.0
CVE-2025-30474

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when …

Fix: 2.10.0+
Fix from $1,600 2025-03-23
Commons Vfs HIGH 7.5
CVE-2025-27553

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a…

Fix: 2.10.0+
Fix from $1,950 2025-03-23
Oozie MEDIUM 5.4
CVE-2025-26796

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. …

Mitigation only
Fix from $1,600 2025-03-22
Druid MEDIUM 5.4
CVE-2025-27888

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…

Fix: 31.0.2+
Fix from $1,600 2025-03-20
Seata CRITICAL 9.8
CVE-2024-47552

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.…

Fix: 2.2.0+
Fix from $2,300 2025-03-20
Apache Airflow Providers Mysql MEDIUM 6.3
CVE-2025-27018

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user trigg…

Fix: 6.2.0+
Fix from $1,600 2025-03-19
Nifi MEDIUM 6.5
CVE-2025-27017

Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB comp…

Fix: 2.3.0+
Fix from $1,600 2025-03-12
Felix Http Webconsole Plugin MEDIUM 5.6
CVE-2025-27867

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issu…

Fix: 1.2.2+
Fix from $1,600 2025-03-12
Tomcat CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…

Fix: 9.0.99 / 10.1.35+
Fix from $2,300 2025-03-10
Camel MEDIUM 5.6
CVE-2025-27636EPSS 81%

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.…

Fix: 3.22.4 / 4.8.5+
Fix from $1,600 2025-03-09
Traffic Server MEDIUM 6.3
CVE-2024-56195

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 thro…

Fix: 9.2.9 / 10.0.4+
Fix from $1,600 2025-03-06