Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Druid MEDIUM 5.3
CVE-2024-45384

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue a…

Fix: 30.0.1+
Fix from $1,600 2024-09-17
Seata CRITICAL 9.8
CVE-2024-22399

Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seat…

Fix: 1.8.1+
Fix from $2,300 2024-09-16
Airflow HIGH 8.8
CVE-2024-45034

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the…

Fix: 2.10.1+
Fix from $1,950 2024-09-07
Airflow HIGH 8.8
CVE-2024-45498

Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with o…

Patch available
Fix from $1,950 2024-09-07
Ofbiz CRITICAL 9.8
CVE-2024-45507EPSS 93%

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.16+
Fix from $2,300 2024-09-04
Ofbiz HIGH 7.5
CVE-2024-45195 KEVEPSS 100%

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrad…

Fix: 18.12.16+
Fix from $1,950 2024-09-04
Portable Runtime MEDIUM 5.5
CVE-2023-49582

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pot…

Fix: 1.7.5+
Fix from $1,600 2024-08-26
Airflow MEDIUM 6.1
CVE-2024-41937

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting atta…

Fix: 2.10.0+
Fix from $1,600 2024-08-21
Seatunnel HIGH 7.5
CVE-2023-49198

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allow…

Mitigation only
Fix from $1,950 2024-08-21
Helix HIGH 7.5
CVE-2024-22281

** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by genera…

Mitigation only
Fix from $1,950 2024-08-20
Hertzbeat CRITICAL 9.8
CVE-2024-42361

Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin…

Fix: 1.6.0+
Fix from $2,300 2024-08-20
Hertzbeat HIGH 8.8
CVE-2024-42362

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/…

Fix: 1.6.0+
Fix from $1,950 2024-08-20
Dolphinscheduler CRITICAL 9.8
CVE-2024-43202

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgr…

Fix: 3.2.2+
Fix from $2,300 2024-08-20
Mina Sshd MEDIUM 5.9
CVE-2024-41909

Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can inter…

Fix: after 2.11.0
Fix from $1,600 2024-08-12
Answer MEDIUM 5.3
CVE-2024-41888

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password …

Fix: 1.3.6+
Fix from $1,600 2024-08-12
Answer MEDIUM 5.3
CVE-2024-41890

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends mu…

Fix: 1.3.6+
Fix from $1,600 2024-08-12
Dolphinscheduler HIGH 8.1
CVE-2024-30188EPSS 6%

File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affect…

Fix: 3.2.2+
Fix from $1,950 2024-08-12
Dolphinscheduler HIGH 8.8
CVE-2024-29831

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.2.2+
Fix from $1,950 2024-08-12
Cloudstack HIGH 7.2
CVE-2024-42062

CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran…

Fix: 4.18.2.3 / 4.19.1.1+
Fix from $1,950 2024-08-07
Iotdb Workbench HIGH 7.3
CVE-2024-36448

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbenc…

Mitigation only
Fix from $1,950 2024-08-05
Ofbiz CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi…

Fix: 18.12.15+
Fix from $2,300 2024-08-05
Apache Airflow Providers Fab CRITICAL 9.8
CVE-2024-42447

Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used wit…

Patch available
Fix from $2,300 2024-08-05
Inlong CRITICAL 9.8
CVE-2024-36268

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12…

Fix: 1.13.0+
Fix from $2,300 2024-08-02
Linkis HIGH 8.8
CVE-2024-27181

In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Link…

Fix: 1.6.0+
Fix from $1,950 2024-08-02
Seatunnel CRITICAL 9.1
CVE-2023-48396

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in an…

Mitigation only
Fix from $2,300 2024-07-30
Traffic Server HIGH 8.2
CVE-2024-35296

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic…

Fix: 8.1.11 / 9.2.5+
Fix from $1,950 2024-07-26
Traffic Server HIGH 7.5
CVE-2024-35161

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead…

Fix: 8.1.11 / 9.2.5+
Fix from $1,950 2024-07-26
Traffic Server HIGH 7.5
CVE-2023-38522

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be uti…

Fix: 8.1.11 / 9.2.5+
Fix from $1,950 2024-07-26
Roller MEDIUM 5.4
CVE-2024-25090

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …

Fix: 6.1.3+
Fix from $1,600 2024-07-26
Drill HIGH 8.8
CVE-2023-48362

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi…

Fix: 1.21.2+
Fix from $1,950 2024-07-24