Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iotdb CRITICAL 9.8
CVE-2023-46226

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to v…

Fix: 1.3.0+
Fix from $2,300 2024-01-15
Shiro MEDIUM 6.5
CVE-2023-46749

Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe…

Fix: 1.13.0+
Fix from $1,600 2024-01-15
Solr MEDIUM 6.5
CVE-2023-50290EPSS 68%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment v…

Fix: 9.3.0+
Fix from $1,600 2024-01-15
Axis HIGH 7.2
CVE-2023-51441

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss…

Fix: after 1.3
Fix from $1,950 2024-01-06
Inlong CRITICAL 9.8
CVE-2023-51784

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, …

Fix: 1.10.0+
Fix from $2,300 2024-01-03
Inlong HIGH 7.5
CVE-2023-51785

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a…

Fix: after 1.9.0
Fix from $1,950 2024-01-03
Dolphinscheduler HIGH 8.8
CVE-2023-49299

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.1.9+
Fix from $1,950 2023-12-30
Openoffice HIGH 8.8
CVE-2023-47804

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. …

Fix: 4.1.15+
Fix from $1,950 2023-12-29
Ofbiz CRITICAL 9.8
CVE-2023-51467EPSS 96%

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

Fix: 18.12.11+
Fix from $2,300 2023-12-26
Ofbiz HIGH 7.5
CVE-2023-50968EPSS 63%

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th…

Fix: 18.12.11+
Fix from $1,950 2023-12-26
Hertzbeat HIGH 7.5
CVE-2023-51650

Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized acc…

Fix: 1.4.1+
Fix from $1,950 2023-12-22
Hertzbeat HIGH 8.8
CVE-2023-51387

Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo…

Fix: 1.4.1+
Fix from $1,950 2023-12-22
Hertzbeat HIGH 7.5
CVE-2022-39337

Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v…

Fix: 1.2.1+
Fix from $1,950 2023-12-22
Iotdb CRITICAL 9.8
CVE-2023-51656

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended t…

Fix: after 0.13.4
Fix from $2,300 2023-12-21
Airflow MEDIUM 6.5
CVE-2023-49920

Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. A…

Fix: after 2.7.3
Fix from $1,600 2023-12-21
Airflow MEDIUM 6.5
CVE-2023-50783

Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to upda…

Fix: 2.8.0+
Fix from $1,600 2023-12-21
Airflow MEDIUM 5.4
CVE-2023-47265

Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript…

Fix: after 2.7.3
Fix from $1,600 2023-12-21
Pulsar HIGH 7.5
CVE-2023-37544

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication…

Fix: 2.10.5 / 2.11.2+
Fix from $1,950 2023-12-20
Guacamole HIGH 8.8
CVE-2023-43826

Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user con…

Fix: after 1.5.3
Fix from $1,950 2023-12-19
Superset HIGH 8.8
CVE-2023-49736

A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup…

Fix: 2.1.2 / 3.0.2+
Fix from $1,950 2023-12-19
Superset MEDIUM 6.5
CVE-2023-49734

An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the…

Fix: 2.1.2 / 3.0.2+
Fix from $1,600 2023-12-19
Superset MEDIUM 6.5
CVE-2023-46104

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.…

Fix: 2.1.3 / 3.0.1+
Fix from $1,600 2023-12-19
Doris HIGH 8.2
CVE-2023-41314

The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Plea…

Fix: 2.0.3+
Fix from $1,950 2023-12-18
Streampark HIGH 7.2
CVE-2023-49898

In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of …

Fix: 2.1.2+
Fix from $1,950 2023-12-15
Dubbo CRITICAL 9.8
CVE-2023-29234EPSS 7%

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…

Fix: after 3.2.4
Fix from $2,300 2023-12-15
Dubbo CRITICAL 9.8
CVE-2023-46279

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the …

Mitigation only
Fix from $2,300 2023-12-15
Shiro MEDIUM 6.1
CVE-2023-46750

URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Sh…

Fix: 1.13.0+
Fix from $1,600 2023-12-14
Couchdb MEDIUM 5.7
CVE-2023-45725

Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the do…

Fix: after 3.3.2
Fix from $1,600 2023-12-13
Struts CRITICAL 9.8
CVE-2023-50164EPSS 81%

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file whic…

Fix: 2.5.33 / 6.3.0.2+
Fix from $2,300 2023-12-07
Struts HIGH 7.5
CVE-2023-41835EPSS 6%

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.save…

Fix: 2.5.32 / 6.3.0.1+
Fix from $1,950 2023-12-05