Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ofbiz CRITICAL 9.8
CVE-2023-49070EPSS 95%

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Us…

Fix: 18.12.10+
Fix from $2,300 2023-12-05
Tiles HIGH 7.5
CVE-2023-49735

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML…

Mitigation only
Fix from $1,950 2023-11-30
Cocoon CRITICAL 9.8
CVE-2023-49733

Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. User…

Fix: 2.3.0+
Fix from $2,300 2023-11-30
Dolphinscheduler MEDIUM 6.5
CVE-2023-49620

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), …

Fix: 3.1.0+
Fix from $1,600 2023-11-30
Cocoon CRITICAL 9.8
CVE-2022-45135

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon:…

Fix: 2.3.0+
Fix from $2,300 2023-11-30
Superset MEDIUM 6.5
CVE-2023-42504

An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial…

Fix: 3.0.0+
Fix from $1,600 2023-11-28
Superset MEDIUM 5.4
CVE-2023-42502

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users co…

Fix: 3.0.0+
Fix from $1,600 2023-11-28
Activemq HIGH 8.8
CVE-2022-41678EPSS 86%

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows…

Fix: 5.16.6 / 5.17.4+
Fix from $1,950 2023-11-28
Tomcat HIGH 7.5
CVE-2023-46589

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 thro…

Fix: 8.5.96 / 9.0.83+
Fix from $1,950 2023-11-28
Nifi MEDIUM 5.4
CVE-2023-49145

Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable …

Fix: 1.24.0+
Fix from $1,600 2023-11-27
Superset HIGH 8.8
CVE-2023-40610

Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…

Fix: 2.1.2+
Fix from $1,950 2023-11-27
Superset MEDIUM 5.4
CVE-2023-43701

Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code int…

Fix: 2.1.2+
Fix from $1,600 2023-11-27
Dolphinscheduler HIGH 7.5
CVE-2023-49068

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: befor…

Fix: 3.2.1+
Fix from $1,950 2023-11-27
Dolphinscheduler HIGH 7.5
CVE-2023-48796

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors …

Fix: 3.0.2+
Fix from $1,950 2023-11-24
Storm MEDIUM 5.5
CVE-2023-43123

On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set th…

Fix: 2.6.0+
Fix from $1,600 2023-11-23
Submarine CRITICAL 9.8
CVE-2023-37924EPSS 7%

Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now …

Fix: 0.8.0+
Fix from $2,300 2023-11-22
Derby CRITICAL 9.8
CVE-2022-46337

A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up …

Fix: 10.14.3.0 / 10.15.2.1+
Fix from $2,300 2023-11-20
Submarine CRITICAL 9.8
CVE-2023-46302

Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail…

Fix: 0.8.0+
Fix from $2,300 2023-11-20
Hadoop HIGH 7.5
CVE-2023-26031

Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If th…

Fix: after 3.3.4
Fix from $1,950 2023-11-16
Airflow MEDIUM 6.5
CVE-2023-42781

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat…

Fix: 2.7.3+
Fix from $1,600 2023-11-12
Pyarrow CRITICAL 9.8
CVE-2023-47248EPSS 14%

Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is …

Fix: after 14.0.0
Fix from $2,300 2023-11-09
Uimaj HIGH 8.8
CVE-2023-39913

Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apach…

Fix: 3.5.0+
Fix from $1,950 2023-11-08
Ofbiz MEDIUM 5.3
CVE-2023-46819

Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.  Use…

Fix: 18.12.09+
Fix from $1,600 2023-11-07
Airflow HIGH 7.5
CVE-2023-46215

Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as cl…

Fix: 2.7.0+
Fix from $1,950 2023-10-28
Activemq CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to…

Fix: 5.15.16 / 5.16.7+
Fix from $2,300 2023-10-27
HTTP Server HIGH 7.5
CVE-2023-43622EPSS 71%

An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP …

Fix: 2.4.58+
Fix from $1,950 2023-10-23
HTTP Server MEDIUM 5.9
CVE-2023-45802

When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. I…

Fix: 2.4.58+
Fix from $1,600 2023-10-23
Santuario Xml Security For Java MEDIUM 6.5
CVE-2023-44483

All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue whe…

Fix: 2.2.6 / 2.3.4+
Fix from $1,600 2023-10-20
Inlong HIGH 7.5
CVE-2023-46227

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.…

Fix: 1.9.0+
Fix from $1,950 2023-10-19
Shenyu MEDIUM 6.5
CVE-2023-25753

There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip…

Mitigation only
Fix from $1,600 2023-10-19