Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Traffic Server HIGH 7.5
CVE-2023-39456EPSS 53%

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th…

Fix: 9.2.3+
Fix from $1,950 2023-10-17
Traffic Server HIGH 7.5
CVE-2023-41752

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.…

Fix: 8.1.9 / 9.2.3+
Fix from $1,950 2023-10-17
Brpc MEDIUM 6.1
CVE-2023-45757

Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can sen…

Fix: 1.6.1+
Fix from $1,600 2023-10-16
Inlong CRITICAL 9.8
CVE-2023-43668

Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se…

Fix: after 1.8.0
Fix from $2,300 2023-10-16
Inlong HIGH 7.5
CVE-2023-43667

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects …

Fix: after 1.8.0
Fix from $1,950 2023-10-16
Inlong MEDIUM 6.5
CVE-2023-43666

Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General u…

Fix: after 1.8.0
Fix from $1,600 2023-10-16
Airflow MEDIUM 6.5
CVE-2023-42780

Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, …

Fix: 2.7.2+
Fix from $1,600 2023-10-14
Airflow MEDIUM 6.5
CVE-2023-42792

Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to …

Fix: 2.7.2+
Fix from $1,600 2023-10-14
Airflow MEDIUM 6.5
CVE-2023-42663

Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat…

Fix: 2.7.2+
Fix from $1,600 2023-10-14
Zookeeper CRITICAL 9.1
CVE-2023-44981

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru…

Fix: 3.7.2 / 3.8.3+
Fix from $2,300 2023-10-11
Xerces C\+\+ HIGH 8.8
CVE-2023-37536

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

Fix: 9.5.23 / 10.0.10+
Fix from $1,950 2023-10-11
Tomcat MEDIUM 5.3
CVE-2023-45648EPSS 6%

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro…

Fix: 8.5.94 / 9.0.81+
Fix from $1,600 2023-10-10
Tomcat MEDIUM 5.9
CVE-2023-42794

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5…

Fix: 8.5.94 / 9.0.81+
Fix from $1,600 2023-10-10
Tomcat MEDIUM 5.3
CVE-2023-42795

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10…

Fix: 8.5.94 / 9.0.81+
Fix from $1,600 2023-10-10
Avro HIGH 7.5
CVE-2023-39410

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of …

Fix: 1.11.3+
Fix from $1,950 2023-09-29
Flink Stateful Functions MEDIUM 6.1
CVE-2023-41834

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject…

Fix: after 3.2.0
Fix from $1,600 2023-09-19
Commons Compress MEDIUM 5.5
CVE-2023-42503

Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common…

Fix: 1.24.0+
Fix from $1,600 2023-09-14
Airflow Hdfs Provider HIGH 7.8
CVE-2023-41267

In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package…

Fix: 4.1.1+
Fix from $1,950 2023-09-14
Tomcat Connectors HIGH 7.5
CVE-2023-41081

Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration…

Fix: 1.2.49+
Fix from $1,950 2023-09-13
Airflow MEDIUM 6.5
CVE-2023-40712

Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, …

Fix: 2.7.1+
Fix from $1,600 2023-09-12
Superset MEDIUM 6.6
CVE-2023-37941EPSS 29%

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to …

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Superset MEDIUM 6.5
CVE-2023-39265EPSS 84%

Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+p…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Superset MEDIUM 5.4
CVE-2023-36387

An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test d…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Superset MEDIUM 5.4
CVE-2023-36388

Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Axis CRITICAL 9.8
CVE-2023-40743

** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S…

Fix: 2023-08-01+
Fix from $2,300 2023-09-05
Nifi Minifi C\+\+ MEDIUM 5.9
CVE-2023-41180

Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate…

Fix: after 0.14.0
Fix from $1,600 2023-09-03
Airflow Sqoop Provider HIGH 8.8
CVE-2023-27604

Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, wh…

Fix: 4.0.0+
Fix from $1,950 2023-08-28
Airflow Spark Provider HIGH 8.8
CVE-2023-40195

Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo…

Fix: 4.1.3+
Fix from $1,950 2023-08-28
Tomcat MEDIUM 6.1
CVE-2023-41080EPSS 6%

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from…

Fix: after 10.1.12
Fix from $1,600 2023-08-25
Airflow HIGH 8.1
CVE-2023-37379

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…

Fix: 2.7.0+
Fix from $1,950 2023-08-23