Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zeppelin CRITICAL 9.8
CVE-2024-31866

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding co…

Fix: 0.11.1+
Fix from $2,300 2024-04-09
Zeppelin MEDIUM 6.5
CVE-2024-31865

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 6.1
CVE-2024-31868

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal us…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.3
CVE-2024-31863

Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 bef…

Mitigation only
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.3
CVE-2022-47894

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is …

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.3
CVE-2024-31862

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.…

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.4
CVE-2021-28656

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue aff…

Fix: after 0.9.0
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 6.5
CVE-2024-31860

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files…

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Nimble HIGH 7.5
CVE-2024-24746

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in …

Fix: 1.7.0+
Fix from $1,950 2024-04-06
HTTP Server HIGH 7.5
CVE-2024-27316EPSS 91%

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do…

Fix: 2.4.59+
Fix from $1,950 2024-04-04
HTTP Server HIGH 7.3
CVE-2023-38709

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects…

Fix: 2.4.59 / 14.6+
Fix from $1,950 2024-04-04
HTTP Server MEDIUM 6.3
CVE-2024-24795

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applicat…

Fix: 2.4.59 / 14.6+
Fix from $1,600 2024-04-04
Cloudstack MEDIUM 6.4
CVE-2024-29008

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to…

Fix: 4.18.1.1+
Fix from $1,600 2024-04-04
Cloudstack CRITICAL 9.8
CVE-2024-29006

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead t…

Fix: 4.18.1.1+
Fix from $2,300 2024-04-04
Cloudstack HIGH 7.3
CVE-2024-29007

The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi…

Fix: 4.18.1.1+
Fix from $1,950 2024-04-04
Pulsar MEDIUM 6.4
CVE-2024-29834

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u…

Fix: 3.0.4 / 3.2.2+
Fix from $1,600 2024-04-02
Fineract CRITICAL 9.8
CVE-2024-23538

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…

Fix: 1.9.0+
Fix from $2,300 2024-03-29
Fineract CRITICAL 9.8
CVE-2024-23539

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…

Fix: 1.9.0+
Fix from $2,300 2024-03-29
Fineract HIGH 8.8
CVE-2024-23537

Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to versi…

Fix: 1.9.0+
Fix from $1,950 2024-03-29
Airflow MEDIUM 5.3
CVE-2024-29735

Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local fil…

Fix: after 2.8.4
Fix from $1,600 2024-03-26
Doris CRITICAL 9.8
CVE-2024-27438

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting …

Fix: 2.0.5+
Fix from $2,300 2024-03-21
Doris MEDIUM 5.3
CVE-2024-26307

Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out…

Fix: 1.2.8 / 2.0.4+
Fix from $1,600 2024-03-21
Commons Configuration HIGH 7.3
CVE-2024-29131

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are…

Fix: 2.10.1+
Fix from $1,950 2024-03-21
Commons Configuration MEDIUM 5.4
CVE-2024-29133

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are…

Fix: 2.10.1+
Fix from $1,600 2024-03-21
Wicket MEDIUM 6.5
CVE-2024-27439

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wick…

Fix: 9.17.0+
Fix from $1,600 2024-03-19
Hop Engine MEDIUM 6.5
CVE-2024-24683

Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to…

Fix: 2.8.0+
Fix from $1,600 2024-03-19
Cxf CRITICAL 9.3
CVE-2024-28752

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att…

Fix: 3.5.8 / 3.6.3+
Fix from $2,300 2024-03-15
Zookeeper MEDIUM 5.3
CVE-2024-23944

Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by…

Fix: 3.8.4 / 3.9.2+
Fix from $1,600 2024-03-15
Airflow HIGH 8.1
CVE-2024-28746

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such…

Fix: 2.8.3+
Fix from $1,950 2024-03-14
Tomcat HIGH 7.5
CVE-2024-24549EPSS 23%

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the requ…

Fix: 8.5.99 / 9.0.86+
Fix from $1,950 2024-03-13