Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hertzbeat HIGH 8.8
CVE-2024-45505

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabili…

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Hertzbeat HIGH 7.5
CVE-2024-45791

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Us…

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Airflow HIGH 7.5
CVE-2024-45784

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability al…

Fix: 2.10.3+
Fix from $1,950 2024-11-15
Traffic Server CRITICAL 9.1
CVE-2024-50306

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through…

Fix: 9.2.6 / 10.0.2+
Fix from $2,300 2024-11-14
Traffic Server HIGH 7.5
CVE-2024-50305

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2…

Fix: 9.2.6+
Fix from $1,950 2024-11-14
Traffic Server HIGH 7.5
CVE-2024-38479

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…

Fix: 9.2.6+
Fix from $1,950 2024-11-14
Cloudstack CRITICAL 9.9
CVE-2024-50386

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan…

Fix: 4.18.2.5 / 4.19.1.3+
Fix from $2,300 2024-11-12
Zookeeper CRITICAL 9.1
CVE-2024-51504

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP bas…

Fix: 3.9.3+
Fix from $2,300 2024-11-07
Tomcat HIGH 7.5
CVE-2024-38286

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0…

Fix: 9.0.90 / 10.1.25+
Fix from $1,950 2024-11-07
Kylin CRITICAL 9.1
CVE-2024-23590

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to versio…

Fix: 5.0.0+
Fix from $2,300 2024-11-04
Lucene.net HIGH 8.1
CVE-2024-43383

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8…

Mitigation only
Fix from $1,950 2024-10-31
Syncope MEDIUM 6.1
CVE-2024-45031

When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored X…

Fix: 3.0.9+
Fix from $1,600 2024-10-24
Cloudstack HIGH 8.8
CVE-2024-45693

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of t…

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,950 2024-10-16
Solr CRITICAL 9.8
CVE-2024-45216EPSS 91%

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…

Fix: 8.11.4 / 9.7.0+
Fix from $2,300 2024-10-16
Cloudstack HIGH 8.5
CVE-2024-45219

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as …

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,950 2024-10-16
Solr HIGH 8.1
CVE-2024-45217

Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a config…

Fix: 8.11.4 / 9.7.0+
Fix from $1,950 2024-10-16
Cloudstack HIGH 7.1
CVE-2024-45462

The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of th…

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,950 2024-10-16
Cloudstack MEDIUM 6.3
CVE-2024-45461

The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. …

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,600 2024-10-16
Artemis HIGH 8.8
CVE-2023-50780EPSS 17%

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia…

Fix: 2.29.0+
Fix from $1,950 2024-10-14
Subversion HIGH 7.8
CVE-2024-45720

On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead…

Fix: 1.14.4+
Fix from $1,950 2024-10-09
Formatting Objects Processor HIGH 7.5
CVE-2024-28168

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: …

Mitigation only
Fix from $1,950 2024-10-09
Avro HIGH 7.3
CVE-2024-47561

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgr…

Fix: 1.11.4+
Fix from $1,950 2024-10-03
Lucene Replicator HIGH 8.0
CVE-2024-45772

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before…

Fix: 9.12.0+
Fix from $1,950 2024-09-30
Maven Archetype HIGH 7.5
CVE-2024-47197

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This …

Mitigation only
Fix from $1,950 2024-09-26
Hadoop MEDIUM 6.2
CVE-2024-23454

Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the oth…

Fix: 3.4.0+
Fix from $1,600 2024-09-25
Answer MEDIUM 5.3
CVE-2024-40761

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's ema…

Fix: after 1.3.5
Fix from $1,600 2024-09-25
Linkis HIGH 7.5
CVE-2024-39928

In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses t…

Fix: 1.6.0+
Fix from $1,950 2024-09-25
Tomcat Connectors MEDIUM 5.9
CVE-2024-46544

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configu…

Fix: 1.2.50+
Fix from $1,600 2024-09-23
Hertzbeat HIGH 8.8
CVE-2024-42323EPSS 8%

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attac…

Fix: 1.6.0+
Fix from $1,950 2024-09-21
Druid MEDIUM 6.5
CVE-2024-45537

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se…

Fix: 30.0.1+
Fix from $1,600 2024-09-17