Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Airflow HIGH 8.0
CVE-2023-40273

The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has bee…

Fix: after 2.7.0
Fix from $1,950 2023-08-23
Airflow MEDIUM 5.9
CVE-2023-39441

Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation …

Fix: 1.3.0 / 2.7.0+
Fix from $1,600 2023-08-23
Xml Graphics Batik HIGH 7.1
CVE-2022-44729

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik…

Fix: after 1.16
Fix from $1,950 2023-08-22
Ivy HIGH 8.2
CVE-2022-46751

Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache I…

Fix: 2.5.2+
Fix from $1,950 2023-08-21
Nifi MEDIUM 6.5
CVE-2023-40037

Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that …

Fix: 1.23.1+
Fix from $1,600 2023-08-18
Apache Airflow Providers Apache Spark HIGH 7.5
CVE-2023-40272

Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when est…

Fix: 4.1.3+
Fix from $1,950 2023-08-17
Apache Airflow Providers Apache Drill HIGH 7.5
CVE-2023-39553

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a …

Fix: 2.4.3+
Fix from $1,950 2023-08-11
Traffic Server CRITICAL 9.1
CVE-2023-33934

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

Fix: after 9.2.1
Fix from $2,300 2023-08-09
Traffic Server HIGH 7.5
CVE-2022-47185

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Ser…

Fix: after 9.2.1
Fix from $1,950 2023-08-09
Roller MEDIUM 5.4
CVE-2023-37581

Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all …

Fix: 6.1.2+
Fix from $1,600 2023-08-06
Airflow HIGH 8.8
CVE-2023-39508

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apach…

Fix: 2.6.0+
Fix from $1,950 2023-08-05
Nifi HIGH 8.8
CVE-2023-36542

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an …

Fix: after 1.22.0
Fix from $1,950 2023-07-29
Helix CRITICAL 9.8
CVE-2023-38647

An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S…

Fix: 1.3.0+
Fix from $2,300 2023-07-26
Felix Health Check Webconsole Plugin MEDIUM 6.1
CVE-2023-38435

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole…

Fix: 2.1.0+
Fix from $1,600 2023-07-25
Jackrabbit CRITICAL 9.8
CVE-2023-37895

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in…

Fix: 2.20.11 / 2.21.18+
Fix from $2,300 2023-07-25
Inlong CRITICAL 9.8
CVE-2023-35088

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i…

Fix: after 1.7.0
Fix from $2,300 2023-07-25
Inlong HIGH 7.5
CVE-2023-34434

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.…

Fix: after 1.7.0
Fix from $1,950 2023-07-25
Inlong MEDIUM 6.5
CVE-2023-34189

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1…

Fix: after 1.7.0
Fix from $1,600 2023-07-25
Shiro CRITICAL 9.8
CVE-2023-34478

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…

Fix: 1.12.0+
Fix from $2,300 2023-07-24
Shardingsphere HIGH 8.8
CVE-2023-28754

Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a sp…

Fix: 5.4.0+
Fix from $1,950 2023-07-19
Eventmesh Connector Rabbitmq CRITICAL 9.8
CVE-2023-26512

CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac…

Fix: after 1.8.0
Fix from $2,300 2023-07-17
Apache Airflow Providers Apache Hive HIGH 8.8
CVE-2023-37415

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before …

Fix: 6.1.2+
Fix from $1,950 2023-07-13
Rocketmq CRITICAL 9.8
CVE-2023-37582EPSS 90%

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version …

Fix: after 5.1.1
Fix from $2,300 2023-07-12
Pulsar MEDIUM 6.5
CVE-2023-37579

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, …

Fix: 2.10.4+
Fix from $1,600 2023-07-12
Pulsar MEDIUM 6.5
CVE-2023-31007

Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti…

Fix: 2.9.5+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-35908

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommende…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-36543

Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is …

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Ambari HIGH 8.8
CVE-2022-42009

SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remote…

Fix: 2.7.7+
Fix from $1,950 2023-07-12
Ambari HIGH 8.8
CVE-2022-45855

SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remo…

Fix: 2.7.7+
Fix from $1,950 2023-07-12
Pulsar HIGH 8.8
CVE-2023-30429

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Whe…

Fix: 2.10.4+
Fix from $1,950 2023-07-12