Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pulsar HIGH 8.1
CVE-2023-30428

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP…

Fix: 2.10.4+
Fix from $1,950 2023-07-12
Airflow MEDIUM 6.5
CVE-2022-46651

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Co…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-22887

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intende…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-22888

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_i…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Jena HIGH 8.8
CVE-2023-32200

There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascr…

Fix: after 4.8.0
Fix from $1,950 2023-07-12
Johnzon MEDIUM 5.3
CVE-2023-33008

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input tha…

Fix: 1.2.21+
Fix from $1,600 2023-07-07
Any23 MEDIUM 5.3
CVE-2023-34150

** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.

Fix: after 2.7
Fix from $1,600 2023-07-05
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2023-35797

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Pro…

Fix: 6.1.1+
Fix from $2,300 2023-07-03
Apache Airflow Providers Jdbc HIGH 8.8
CVE-2023-22886

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection UR…

Fix: 4.0.0+
Fix from $1,950 2023-06-29
Apache Airflow Providers Odbc HIGH 7.8
CVE-2023-34395

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Pr…

Fix: 4.0.0+
Fix from $1,950 2023-06-27
Streampipes HIGH 8.8
CVE-2023-31469

A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi…

Fix: after 0.91.0
Fix from $1,950 2023-06-23
Tomcat HIGH 7.5
CVE-2023-34981

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header…

Mitigation only
Fix from $1,950 2023-06-21
Accumulo CRITICAL 9.8
CVE-2023-34340

Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta…

Mitigation only
Fix from $2,300 2023-06-21
Airflow MEDIUM 6.5
CVE-2023-35005

In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact…

Fix: 2.6.2+
Fix from $1,600 2023-06-19
Traffic Server HIGH 7.5
CVE-2023-30631

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Traffic Server HIGH 7.5
CVE-2023-33933

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Struts HIGH 7.5
CVE-2023-34396EPSS 6%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…

Fix: 2.5.31 / 6.1.2.1+
Fix from $1,950 2023-06-14
Struts MEDIUM 6.5
CVE-2023-34149EPSS 5%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…

Fix: 2.5.31 / 6.1.2.1+
Fix from $1,600 2023-06-14
Traffic Server HIGH 7.5
CVE-2022-47184

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Nifi HIGH 8.8
CVE-2023-34468EPSS 64%

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user …

Fix: 1.22.0+
Fix from $1,950 2023-06-12
Nifi MEDIUM 6.5
CVE-2023-34212

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all…

Fix: after 1.21.0
Fix from $1,600 2023-06-12
Guacamole HIGH 8.1
CVE-2023-30576

Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to ex…

Fix: 1.5.2+
Fix from $1,950 2023-06-07
Guacamole HIGH 7.5
CVE-2023-30575

Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentia…

Fix: 1.5.2+
Fix from $1,950 2023-06-07
Apache Airflow Providers Cncf Kubernetes HIGH 7.2
CVE-2023-33234

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow …

Fix: 7.0.0+
Fix from $1,950 2023-05-30
Cassandra HIGH 7.8
CVE-2023-30601

Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This iss…

Fix: 4.0.10 / 4.1.2+
Fix from $1,950 2023-05-30
Jspwiki MEDIUM 6.1
CVE-2022-46907

A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execut…

Fix: 2.12.0+
Fix from $1,600 2023-05-25
Rocketmq CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu…

Fix: 4.9.6 / 5.1.1+
Fix from $2,300 2023-05-24
Inlong CRITICAL 9.8
CVE-2023-31098

Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  Wh…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Inlong CRITICAL 9.1
CVE-2023-31065

Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Inlong CRITICAL 9.1
CVE-2023-31066

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from …

Fix: after 1.6.0
Fix from $2,300 2023-05-22