Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server CRITICAL 9.8
CVE-2024-38474

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by th…

Fix: 2.4.60+
Fix from $2,300 2024-07-01
HTTP Server CRITICAL 9.8
CVE-2024-38476EPSS 42%

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend a…

Fix: 2.4.60+
Fix from $2,300 2024-07-01
HTTP Server CRITICAL 9.1
CVE-2024-38475 KEVEPSS 100%

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p…

Fix: 2.4.60 / 10.2.1.14-75sv+
Fix from $2,300 2024-07-01
HTTP Server HIGH 8.1
CVE-2024-38473EPSS 26%

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, po…

Fix: 2.4.60+
Fix from $1,950 2024-07-01
HTTP Server HIGH 7.5
CVE-2024-38472EPSS 69%

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users …

Fix: 2.4.60+
Fix from $1,950 2024-07-01
HTTP Server MEDIUM 5.4
CVE-2024-36387

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, de…

Fix: after 2.4.59
Fix from $1,600 2024-07-01
Streampipes CRITICAL 9.1
CVE-2024-29868EPSS 6%

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery …

Fix: after 0.93.0
Fix from $2,300 2024-06-24
Jspwiki MEDIUM 6.1
CVE-2024-27136EPSS 59%

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive infor…

Fix: 2.12.2+
Fix from $1,600 2024-06-24
Superset MEDIUM 5.3
CVE-2024-34693

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile ena…

Fix: 3.1.3 / 4.0.1+
Fix from $1,600 2024-06-20
Airflow MEDIUM 5.5
CVE-2024-25142

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynami…

Fix: 2.9.2+
Fix from $1,600 2024-06-14
Submarine CRITICAL 9.8
CVE-2024-36265

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co…

Mitigation only
Fix from $2,300 2024-06-12
Submarine CRITICAL 9.8
CVE-2024-36264

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari…

Patch available
Fix from $2,300 2024-06-12
Submarine HIGH 8.1
CVE-2024-36263

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarin…

Patch available
Fix from $1,950 2024-06-12
Allura HIGH 7.5
CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp…

Fix: 1.17.0+
Fix from $1,950 2024-06-10
Ofbiz CRITICAL 9.1
CVE-2024-36104EPSS 87%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…

Fix: 18.12.14+
Fix from $2,300 2024-06-04
Airflow MEDIUM 5.4
CVE-2024-32077

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users a…

Patch available
Fix from $1,600 2024-05-14
Karaf Cave CRITICAL 9.1
CVE-2024-34365

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A…

Mitigation only
Fix from $2,300 2024-05-14
Ofbiz CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …

Fix: 18.12.13+
Fix from $2,300 2024-05-08
Inlong CRITICAL 9.8
CVE-2024-26579

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can by…

Fix: 1.12.0+
Fix from $2,300 2024-05-08
Hive MEDIUM 6.6
CVE-2023-35701

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and…

Mitigation only
Fix from $1,600 2024-05-03
Apisix MEDIUM 6.3
CVE-2024-32638

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue af…

Mitigation only
Fix from $1,600 2024-05-02
Activemq HIGH 8.8
CVE-2024-32114EPSS 7%

In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are loc…

Fix: 6.1.2+
Fix from $1,950 2024-05-02
Hugegraph CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Hugegraph CRITICAL 9.1
CVE-2024-27349

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. User…

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Hugegraph Hubble MEDIUM 5.3
CVE-2024-27347

Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Use…

Fix: 1.3.0+
Fix from $1,600 2024-04-22
Solr Operator MEDIUM 6.5
CVE-2024-31391

Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Opera…

Fix: 0.8.1+
Fix from $1,600 2024-04-12
Kafka HIGH 7.4
CVE-2024-27309

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditi…

Fix: after 3.6.1
Fix from $1,950 2024-04-12
Traffic Server HIGH 7.5
CVE-2024-31309EPSS 95%

HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0…

Fix: 8.1.10 / 9.2.4+
Fix from $1,950 2024-04-10
Zeppelin MEDIUM 6.5
CVE-2024-31867

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Zeppelin CRITICAL 9.8
CVE-2024-31864

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic…

Fix: 0.11.1+
Fix from $2,300 2024-04-09