Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Apache Airflow Providers Fab HIGH 8.1
CVE-2024-45033

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When us…

Fix: 1.5.2+
Fix from $1,950 2025-01-08
Nifi MEDIUM 5.4
CVE-2024-56512

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenc…

Fix: 2.1.0+
Fix from $1,600 2024-12-28
Mina CRITICAL 9.8
CVE-2024-52046EPSS 24%

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary…

Fix: 2.0.27 / 2.1.10+
Fix from $2,300 2024-12-25
Hugegraph CRITICAL 9.8
CVE-2024-43441EPSS 69%

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 bef…

Fix: 1.5.0+
Fix from $2,300 2024-12-24
Traffic Control HIGH 8.8
CVE-2024-45387EPSS 42%

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …

Fix: 8.0.2+
Fix from $1,950 2024-12-23
Hive MEDIUM 5.9
CVE-2024-23945

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signatu…

Fix: 3.3.4 / 3.4.2+
Fix from $1,600 2024-12-23
Tomcat CRITICAL 9.8
CVE-2024-56337EPSS 9%

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, f…

Fix: 9.0.98 / 10.1.34+
Fix from $2,300 2024-12-20
Kafka MEDIUM 5.3
CVE-2024-56128

Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Sal…

Fix: 3.7.2+
Fix from $1,600 2024-12-18
Tomcat CRITICAL 9.8
CVE-2024-50379EPSS 44%

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file syste…

Fix: 9.0.98 / 10.1.34+
Fix from $2,300 2024-12-17
Tomcat MEDIUM 5.3
CVE-2024-54677

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue a…

Fix: 9.0.98 / 10.1.34+
Fix from $1,600 2024-12-17
Superset MEDIUM 6.5
CVE-2024-55633

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed…

Fix: 4.1.0+
Fix from $1,600 2024-12-12
Struts CRITICAL 9.8
CVE-2024-53677EPSS 78%

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th…

Fix: 6.4.0+
Fix from $2,300 2024-12-11
Superset CRITICAL 9.8
CVE-2024-53947

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s…

Fix: 4.1.0+
Fix from $2,300 2024-12-09
Superset MEDIUM 6.5
CVE-2024-53949

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users …

Fix: 4.1.0+
Fix from $1,600 2024-12-09
Superset MEDIUM 5.3
CVE-2024-53948

Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users a…

Fix: 4.1.0+
Fix from $1,600 2024-12-09
Hive HIGH 8.3
CVE-2022-41137

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is un…

Patch available
Fix from $1,950 2024-12-05
Ozone HIGH 8.1
CVE-2024-45106

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…

Mitigation only
Fix from $1,950 2024-12-03
Arrow CRITICAL 9.8
CVE-2024-52338

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut…

Fix: 17.0.0+
Fix from $2,300 2024-11-28
Nimble HIGH 7.5
CVE-2024-51569

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access wh…

Fix: 1.8.0+
Fix from $1,950 2024-11-26
Nimble MEDIUM 6.3
CVE-2024-47248

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result i…

Fix: 1.8.0+
Fix from $1,600 2024-11-26
Nimble MEDIUM 5.0
CVE-2024-47249

Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bo…

Fix: 1.8.0+
Fix from $1,600 2024-11-26
Nimble MEDIUM 5.0
CVE-2024-47250

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsin…

Fix: 1.8.0+
Fix from $1,600 2024-11-26
Traffic Server MEDIUM 6.5
CVE-2018-9481

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information d…

Fix: 7.1.10 / 8.0.7+
Fix from $1,600 2024-11-20
Kafka MEDIUM 6.5
CVE-2024-31141

Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accep…

Fix: after 3.6.2
Fix from $1,600 2024-11-19
Tomcat MEDIUM 6.1
CVE-2024-52318

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommend…

Mitigation only
Fix from $1,600 2024-11-18
Tomcat CRITICAL 9.8
CVE-2024-52316EPSS 6%

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuth…

Fix: 9.0.96 / 10.1.31+
Fix from $2,300 2024-11-18
Tomcat MEDIUM 6.5
CVE-2024-52317

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could…

Fix: 9.0.96 / 10.1.31+
Fix from $1,600 2024-11-18
Ofbiz CRITICAL 9.8
CVE-2024-47208

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.17+
Fix from $2,300 2024-11-18
Ofbiz HIGH 8.8
CVE-2024-48962

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…

Fix: 18.12.17+
Fix from $1,950 2024-11-18
Hertzbeat HIGH 8.8
CVE-2024-41151

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue …

Fix: 1.6.1+
Fix from $1,950 2024-11-18