Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Traffic Server MEDIUM 6.3
CVE-2024-56196

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are rec…

Fix: 10.0.4+
Fix from $1,600 2025-03-06
Traffic Server MEDIUM 6.3
CVE-2024-38311

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…

Fix: 9.2.9 / 10.0.4+
Fix from $1,600 2025-03-06
Ranger CRITICAL 9.8
CVE-2024-55532

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade…

Fix: 2.6.0+
Fix from $2,300 2025-03-03
Streampipes MEDIUM 6.5
CVE-2024-24778

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This i…

Fix: 0.97.0+
Fix from $1,600 2025-03-03
Eventmesh CRITICAL 9.8
CVE-2024-56180

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo…

Fix: 1.11.0+
Fix from $2,300 2025-02-14
Ignite CRITICAL 9.0
CVE-2024-52577

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili…

Fix: 2.17.0+
Fix from $2,300 2025-02-14
Atlas HIGH 7.1
CVE-2024-46910

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users a…

Fix: 2.4.0+
Fix from $1,950 2025-02-13
Fineract HIGH 8.8
CVE-2024-32838

SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that al…

Fix: 1.10.1+
Fix from $1,950 2025-02-12
Felix Webconsole MEDIUM 6.1
CVE-2025-25247

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Ap…

Fix: 4.9.10 / 5.0.10+
Fix from $1,600 2025-02-10
Kvrocks MEDIUM 6.5
CVE-2025-25069

A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a va…

Fix: 2.11.1+
Fix from $1,600 2025-02-07
Shardingsphere Elasticjob Ui HIGH 8.5
CVE-2022-31764

The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue af…

Fix: 3.0.2+
Fix from $1,950 2025-02-06
James Server HIGH 7.5
CVE-2024-45626

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu…

Fix: 3.7.6 / 3.8.2+
Fix from $1,950 2025-02-06
James Server HIGH 7.5
CVE-2024-37358

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthent…

Fix: 3.7.6 / 3.8.2+
Fix from $1,950 2025-02-06
Doris MEDIUM 5.4
CVE-2024-48019

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …

Fix: 2.1.8 / 3.0.3+
Fix from $1,600 2025-02-04
Cassandra MEDIUM 5.4
CVE-2025-24860

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi…

Fix: 4.0.16 / 4.1.8+
Fix from $1,600 2025-02-04
Cassandra MEDIUM 5.3
CVE-2024-27137

In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI…

Fix: 4.0.15 / 4.1.8+
Fix from $1,600 2025-02-04
Cassandra HIGH 8.8
CVE-2025-23015

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to s…

Fix: 3.0.31 / 3.11.18+
Fix from $1,950 2025-02-04
Hive MEDIUM 5.5
CVE-2024-29869

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set exp…

Fix: 4.0.1+
Fix from $1,600 2025-01-28
Hive MEDIUM 6.5
CVE-2024-23953

Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary mes…

Fix: 4.0.0+
Fix from $1,600 2025-01-28
Cocoon HIGH 7.5
CVE-2025-24783

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects…

Mitigation only
Fix from $1,950 2025-01-27
Solr MEDIUM 5.5
CVE-2025-24814

Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetSer…

Fix: 9.8.0+
Fix from $1,600 2025-01-27
Solr MEDIUM 5.4
CVE-2024-52012EPSS 47%

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a …

Fix: 9.8.0+
Fix from $1,600 2025-01-27
Wicket MEDIUM 6.5
CVE-2024-53299

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.…

Fix: 9.19.0 / 10.3.0+
Fix from $1,600 2025-01-23
Ranger CRITICAL 9.1
CVE-2024-45479

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger…

Fix: 2.5.0+
Fix from $2,300 2025-01-21
Ambari HIGH 8.8
CVE-2024-51941

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbit…

Fix: after 2.7.8
Fix from $1,950 2025-01-21
Ambari HIGH 8.8
CVE-2025-23196

A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell co…

Fix: 2.7.9+
Fix from $1,950 2025-01-21
Ambari HIGH 7.5
CVE-2025-23195

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerab…

Fix: 2.7.9+
Fix from $1,950 2025-01-21
Cxf HIGH 7.5
CVE-2025-23184

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutput…

Fix: 3.5.10 / 3.6.5+
Fix from $1,950 2025-01-21
Linkis MEDIUM 5.9
CVE-2024-45627

In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSou…

Fix: 1.7.0+
Fix from $1,600 2025-01-14
Openmeetings CRITICAL 9.8
CVE-2024-54676EPSS 65%

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions …

Fix: 8.0.0+
Fix from $2,300 2025-01-08