Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Inlong HIGH 7.5
CVE-2023-31103

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Inlong MEDIUM 6.5
CVE-2023-31101

Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 th…

Mitigation only
Fix from $1,600 2023-05-22
Inlong CRITICAL 9.8
CVE-2023-31062

Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Inlong HIGH 7.5
CVE-2023-31064

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from …

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Inlong HIGH 7.5
CVE-2023-31206

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Inlong HIGH 7.5
CVE-2023-31453

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Inlong HIGH 7.5
CVE-2023-31454

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Inlong HIGH 7.5
CVE-2023-31058

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Tomcat HIGH 7.5
CVE-2023-28709EPSS 50%

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-d…

Fix: after 10.1.7
Fix from $1,950 2023-05-22
Sling Commons Json CRITICAL 9.8
CVE-2022-47937

Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted inpu…

Fix: after 2.0.20
Fix from $2,300 2023-05-15
Openmeetings HIGH 8.1
CVE-2023-29032

An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Version…

Fix: 7.1.0+
Fix from $1,950 2023-05-12
Openmeetings HIGH 7.2
CVE-2023-29246

An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affec…

Fix: 7.1.0+
Fix from $1,950 2023-05-12
Openmeetings MEDIUM 5.3
CVE-2023-28936

Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

Fix: 7.1.0+
Fix from $1,600 2023-05-12
Airflow CRITICAL 9.8
CVE-2023-25754

Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.

Fix: 2.6.0+
Fix from $2,300 2023-05-08
Airflow MEDIUM 5.4
CVE-2023-29247

Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.

Fix: 2.6.0+
Fix from $1,600 2023-05-08
Brpc CRITICAL 9.8
CVE-2023-31039

Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker tha…

Fix: 1.5.0+
Fix from $2,300 2023-05-08
Log4cxx HIGH 8.8
CVE-2023-31038

SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the database were properly escaped for S…

Fix: 1.1.0+
Fix from $1,950 2023-05-08
Ranger HIGH 8.8
CVE-2022-45048

Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe…

Mitigation only
Fix from $1,950 2023-05-05
Ranger HIGH 8.1
CVE-2021-40331

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on …

Fix: after 2.3.0
Fix from $1,950 2023-05-05
Couchdb MEDIUM 5.3
CVE-2023-26268

Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design d…

Fix: 3.2.3 / 3.3.2+
Fix from $1,600 2023-05-02
Spark HIGH 8.8
CVE-2023-32007EPSS 76%

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut…

Fix: after 3.2.1
Fix from $1,950 2023-05-02
Streampark CRITICAL 9.1
CVE-2022-46365

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Streampark CRITICAL 9.8
CVE-2022-45802

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Streampark MEDIUM 5.4
CVE-2022-45801

Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that constru…

Fix: 2.0.0+
Fix from $1,600 2023-05-01
Jena MEDIUM 5.4
CVE-2023-22665

There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to ex…

Fix: after 4.8.0
Fix from $1,600 2023-04-25
Superset MEDIUM 6.5
CVE-2023-30776

An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue…

Fix: after 2.0.1
Fix from $1,600 2023-04-24
Superset CRITICAL 9.8
CVE-2023-27524 KEVEPSS 97%

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K…

Fix: after 2.0.1
Fix from $2,300 2023-04-24
Superset MEDIUM 6.5
CVE-2023-25504

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu…

Fix: after 2.0.1
Fix from $1,600 2023-04-17
Spark CRITICAL 9.9
CVE-2023-22946

In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…

Fix: 3.4.0+
Fix from $2,300 2023-04-17
Iotdb Web Workbench CRITICAL 9.8
CVE-2023-30771

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd…

Mitigation only
Fix from $2,300 2023-04-17