Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat MEDIUM 6.3
CVE-2024-23672

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open lea…

Fix: 8.5.99 / 9.0.86+
Fix from $1,600 2024-03-13
Pulsar MEDIUM 5.4
CVE-2024-28098

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off…

Fix: 2.10.6 / 2.11.4+
Fix from $1,600 2024-03-12
Pulsar CRITICAL 9.9
CVE-2024-27135EPSS 6%

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function w…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Pulsar CRITICAL 9.9
CVE-2024-27317EPSS 57%

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Pulsar HIGH 8.8
CVE-2024-27894

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referen…

Fix: 2.10.6 / 2.11.4+
Fix from $1,950 2024-03-12
Pulsar HIGH 8.2
CVE-2022-34321

Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The v…

Fix: 2.10.6 / 2.11.3+
Fix from $1,950 2024-03-12
Doris CRITICAL 9.8
CVE-2023-41313

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 +…

Fix: 1.2.8+
Fix from $2,300 2024-03-12
Linkis MEDIUM 5.3
CVE-2023-50740

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users …

Fix: 1.5.0+
Fix from $1,600 2024-03-06
Inlong CRITICAL 9.1
CVE-2024-26580

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use…

Fix: 1.11.0+
Fix from $2,300 2024-03-06
Archiva HIGH 7.5
CVE-2024-27139

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated…

Mitigation only
Fix from $1,950 2024-03-01
Archiva MEDIUM 5.4
CVE-2024-27140

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva…

Mitigation only
Fix from $1,600 2024-03-01
Archiva HIGH 7.5
CVE-2024-27138

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, …

Mitigation only
Fix from $1,950 2024-03-01
Ambari MEDIUM 6.1
CVE-2023-50378

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited …

Fix: 2.7.8+
Fix from $1,600 2024-03-01
Airflow MEDIUM 5.9
CVE-2024-27906

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not hav…

Fix: 2.8.2+
Fix from $1,600 2024-02-29
Ofbiz CRITICAL 9.1
CVE-2024-25065EPSS 48%

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $2,300 2024-02-29
Ofbiz MEDIUM 5.3
CVE-2024-23946

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $1,600 2024-02-29
Xerces C\+\+ CRITICAL 9.8
CVE-2024-23807

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. User…

Fix: 3.2.5+
Fix from $2,300 2024-02-29
Superset MEDIUM 6.5
CVE-2024-24773

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apa…

Fix: 3.0.4 / 3.1.1+
Fix from $1,600 2024-02-28
Superset MEDIUM 6.5
CVE-2024-24779

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual dat…

Fix: 3.1.1+
Fix from $1,600 2024-02-28
Superset MEDIUM 5.4
CVE-2024-26016

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby …

Fix: 3.0.4 / 3.1.1+
Fix from $1,600 2024-02-28
James Mime4j MEDIUM 5.3
CVE-2024-21742

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an atta…

Fix: after 0.8.9
Fix from $1,600 2024-02-27
Ambari MEDIUM 6.5
CVE-2023-50380

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More De…

Fix: 2.7.8+
Fix from $1,600 2024-02-27
Aurora CRITICAL 9.1
CVE-2024-27905

** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte…

Mitigation only
Fix from $2,300 2024-02-27
James HIGH 7.1
CVE-2023-51747

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ…

Mitigation only
Fix from $1,950 2024-02-27
James CRITICAL 9.8
CVE-2023-51518

Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi…

Mitigation only
Fix from $2,300 2024-02-27
Ambari HIGH 8.8
CVE-2023-50379

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cl…

Fix: 2.7.8+
Fix from $1,950 2024-02-27
Camel HIGH 7.5
CVE-2024-22371

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerabi…

Fix: 3.21.4 / 4.0.4+
Fix from $1,950 2024-02-26
Dolphinscheduler HIGH 8.8
CVE-2024-23320

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.2.1+
Fix from $1,950 2024-02-23
Hertzbeat CRITICAL 9.8
CVE-2023-51388

Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no …

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Hertzbeat CRITICAL 9.8
CVE-2023-51389

Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co…

Fix: 1.4.1+
Fix from $2,300 2024-02-22