Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hertzbeat CRITICAL 9.8
CVE-2023-51653

Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec…

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Answer CRITICAL 9.1
CVE-2024-22393

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack b…

Fix: 1.2.5+
Fix from $2,300 2024-02-22
Answer MEDIUM 5.9
CVE-2024-26578

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache …

Fix: after 1.2.1
Fix from $1,600 2024-02-22
Answer MEDIUM 5.4
CVE-2024-23349

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer:…

Fix: after 1.2.1
Fix from $1,600 2024-02-22
Apache Airflow Providers Mongo CRITICAL 9.1
CVE-2024-25141

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte…

Fix: 4.0.0+
Fix from $2,300 2024-02-20
Camel CRITICAL 9.8
CVE-2024-23114

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa…

Fix: 3.21.4 / 4.0.4+
Fix from $2,300 2024-02-20
Camel HIGH 7.8
CVE-2024-22369

Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 b…

Fix: 3.21.4 / 4.0.4+
Fix from $1,950 2024-02-20
Dolphinscheduler HIGH 7.5
CVE-2023-51770

Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr…

Fix: 3.2.1+
Fix from $1,950 2024-02-20
Dolphinscheduler HIGH 7.3
CVE-2023-49250

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connectio…

Fix: 3.2.1+
Fix from $1,950 2024-02-20
Dolphinscheduler MEDIUM 6.5
CVE-2023-50270

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgr…

Fix: 3.2.1+
Fix from $1,600 2024-02-20
Dolphinscheduler CRITICAL 9.8
CVE-2023-49109

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr…

Fix: 3.2.1+
Fix from $2,300 2024-02-20
Commons Compress MEDIUM 5.5
CVE-2024-26308

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 b…

Fix: 1.26.0+
Fix from $1,600 2024-02-19
Commons Compress MEDIUM 5.5
CVE-2024-25710

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 …

Fix: 1.26.0+
Fix from $1,600 2024-02-19
Superset MEDIUM 6.5
CVE-2024-23952

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be trig…

Fix: 2.1.3 / 3.0.2+
Fix from $1,600 2024-02-14
Solr HIGH 8.8
CVE-2023-50386EPSS 84%

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Solr HIGH 7.5
CVE-2023-50291

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.…

Fix: 8.11.3 / 9.3.0+
Fix from $1,950 2024-02-09
Solr HIGH 7.5
CVE-2023-50292

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This iss…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Solr HIGH 7.5
CVE-2023-50298

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, fr…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Brpc HIGH 7.5
CVE-2024-23452

Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause D…

Fix: 1.8.0+
Fix from $1,950 2024-02-08
Ozone MEDIUM 5.3
CVE-2023-39196

Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container M…

Fix: after 1.3.0
Fix from $1,600 2024-02-07
Pulsar HIGH 7.4
CVE-2023-51437

Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will …

Fix: 2.11.3 / 3.0.2+
Fix from $1,950 2024-02-07
Sling Servlets Resolver HIGH 7.5
CVE-2024-23673

Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sli…

Fix: 2.11.0+
Fix from $1,950 2024-02-06
Servicecomb HIGH 7.5
CVE-2023-44312

Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Cente…

Fix: 2.2.0+
Fix from $1,950 2024-01-31
Servicecomb HIGH 7.5
CVE-2023-44313

Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec…

Fix: 2.2.0+
Fix from $1,950 2024-01-31
Kylin HIGH 7.5
CVE-2023-29055

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain…

Fix: 4.0.4+
Fix from $1,950 2024-01-29
Airflow MEDIUM 6.5
CVE-2023-50944

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …

Fix: 2.8.1+
Fix from $1,600 2024-01-24
Airflow MEDIUM 6.5
CVE-2023-51702

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes th…

Fix: 2.6.1 / 7.0.0+
Fix from $1,600 2024-01-24
Airflow HIGH 7.5
CVE-2023-50943

Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "…

Fix: 2.8.1+
Fix from $1,950 2024-01-24
Superset MEDIUM 5.4
CVE-2023-49657

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on…

Fix: 3.0.3+
Fix from $1,600 2024-01-23
Tomcat MEDIUM 5.3
CVE-2024-21733EPSS 14%

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.…

Fix: 8.5.64 / 9.0.44+
Fix from $1,600 2024-01-19