Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pinot HIGH 7.5
CVE-2024-39676

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. U…

Fix: 1.0.0+
Fix from $1,950 2024-07-24
Arrow HIGH 7.5
CVE-2024-41178

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using…

Fix: after 0.10.1
Fix from $1,950 2024-07-23
Streampark CRITICAL 9.1
CVE-2024-29070

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …

Fix: 2.1.4+
Fix from $2,300 2024-07-23
Syncope MEDIUM 5.4
CVE-2024-38503

When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The…

Fix: 3.0.8+
Fix from $1,600 2024-07-22
Streampark MEDIUM 6.5
CVE-2024-34457

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'…

Fix: 2.1.4+
Fix from $1,600 2024-07-22
Rocketmq HIGH 8.8
CVE-2024-23321

For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i…

Fix: 5.3.0+
Fix from $1,950 2024-07-22
Cloudstack HIGH 8.1
CVE-2024-41107EPSS 18%

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is en…

Fix: 4.18.2.2 / 4.19.1.0+
Fix from $1,950 2024-07-19
Cxf HIGH 7.5
CVE-2024-41172

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instan…

Fix: 3.6.4 / 4.0.5+
Fix from $1,950 2024-07-19
Cxf CRITICAL 9.1
CVE-2024-29736

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…

Fix: 3.5.9 / 3.6.4+
Fix from $2,300 2024-07-19
Cxf HIGH 7.5
CVE-2024-32007

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of…

Fix: 3.5.9 / 3.6.4+
Fix from $1,950 2024-07-19
Streampark HIGH 8.8
CVE-2024-29178

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …

Fix: 2.1.4+
Fix from $1,950 2024-07-18
HTTP Server HIGH 7.5
CVE-2024-40898

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF…

Fix: 2.4.62+
Fix from $1,950 2024-07-18
HTTP Server MEDIUM 5.3
CVE-2024-40725

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handler…

Mitigation only
Fix from $1,600 2024-07-18
Streampark MEDIUM 5.9
CVE-2024-29120

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication…

Fix: 2.1.4+
Fix from $1,600 2024-07-17
Streampipes HIGH 8.8
CVE-2024-31411

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead …

Fix: 0.95.0+
Fix from $1,950 2024-07-17
Airflow HIGH 8.8
CVE-2024-39877

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that …

Fix: 2.9.3+
Fix from $1,950 2024-07-17
Airflow MEDIUM 5.4
CVE-2024-39863

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider…

Fix: 2.9.3+
Fix from $1,600 2024-07-17
Superset CRITICAL 9.8
CVE-2024-39887

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…

Fix: 4.0.2+
Fix from $2,300 2024-07-16
Streampark HIGH 8.1
CVE-2023-52290

In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…

Fix: 2.1.4+
Fix from $1,950 2024-07-16
Linkis HIGH 8.8
CVE-2023-46801

In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version …

Fix: 1.6.0+
Fix from $1,950 2024-07-15
Linkis HIGH 8.8
CVE-2023-49566

In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSourc…

Fix: 1.6.0+
Fix from $1,950 2024-07-15
Linkis MEDIUM 6.5
CVE-2023-41916

In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSou…

Fix: 1.6.0+
Fix from $1,600 2024-07-15
Wicket CRITICAL 9.8
CVE-2024-36522

The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…

Fix: 8.16.0 / 9.18.0+
Fix from $2,300 2024-07-12
Nifi MEDIUM 5.4
CVE-2024-37389EPSS 24%

Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable…

Fix: 1.27.0+
Fix from $1,600 2024-07-08
Cloudstack CRITICAL 9.8
CVE-2024-39864

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio…

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05
Cloudstack CRITICAL 9.8
CVE-2024-38346

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05
HTTP Server MEDIUM 6.2
CVE-2024-39884

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and si…

Mitigation only
Fix from $1,600 2024-07-04
Tomcat HIGH 7.5
CVE-2024-34750

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomc…

Fix: 9.0.90 / 10.1.25+
Fix from $1,950 2024-07-03
HTTP Server HIGH 7.5
CVE-2024-38477

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users …

Fix: 2.4.60+
Fix from $1,950 2024-07-01
HTTP Server HIGH 7.5
CVE-2024-39573EPSS 35%

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to…

Fix: 2.4.60+
Fix from $1,950 2024-07-01