Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iotdb CRITICAL 9.8
CVE-2023-24831

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu…

Fix: after 0.13.3
Fix from $2,300 2023-04-17
Ofbiz HIGH 7.5
CVE-2022-47501EPSS 10%

Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. Thi…

Fix: 18.12.07+
Fix from $1,950 2023-04-14
Apache Sling Engine CRITICAL 9.0
CVE-2022-45064

The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting is…

Fix: 2.14.0+
Fix from $2,300 2023-04-13
Inlong MEDIUM 5.3
CVE-2023-30465

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i…

Mitigation only
Fix from $1,600 2023-04-11
Linkis CRITICAL 9.8
CVE-2023-27603

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-29215

In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-29216

In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.1
CVE-2023-27987

In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the de…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-27602

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Airflow Hive Provider CRITICAL 9.8
CVE-2023-28706

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects…

Fix: 6.0.0+
Fix from $2,300 2023-04-07
Apache Airflow Providers Apache Drill HIGH 7.5
CVE-2023-28707

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider:…

Fix: 2.3.2+
Fix from $1,950 2023-04-07
Apache Airflow Providers Apache Spark HIGH 7.5
CVE-2023-28710

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider:…

Fix: 4.0.1+
Fix from $1,950 2023-04-07
James HIGH 7.8
CVE-2023-26269

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation b…

Fix: 3.7.4+
Fix from $1,950 2023-04-03
Unstructured Information Management Architecture HIGH 8.8
CVE-2023-28935

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software …

Mitigation only
Fix from $1,950 2023-03-30
Archiva MEDIUM 5.4
CVE-2023-28158

Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users…

Fix: 2.2.10+
Fix from $1,600 2023-03-29
Openmeetings CRITICAL 9.8
CVE-2023-28326

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privi…

Fix: 7.0.0+
Fix from $2,300 2023-03-28
Fineract HIGH 8.1
CVE-2023-25195

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain ac…

Fix: after 1.8.3
Fix from $1,950 2023-03-28
Fineract MEDIUM 6.3
CVE-2023-25197

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Aut…

Fix: after 1.8.2
Fix from $1,600 2023-03-28
Inlong HIGH 8.8
CVE-2023-27296

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong,…

Fix: after 1.5.0
Fix from $1,950 2023-03-27
Openoffice HIGH 7.8
CVE-2022-38745

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro…

Fix: 4.1.14+
Fix from $1,950 2023-03-24
Openoffice HIGH 7.8
CVE-2022-47502

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. …

Fix: after 4.1.13
Fix from $1,950 2023-03-24
Sling Resource Merger HIGH 7.5
CVE-2023-26513

Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.…

Fix: 1.4.2+
Fix from $1,950 2023-03-20
Airflow MEDIUM 5.3
CVE-2023-25695

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Air…

Fix: 2.5.2+
Fix from $1,600 2023-03-15
Log4j HIGH 7.5
CVE-2023-26464

** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t…

Fix: 2.0+
Fix from $1,950 2023-03-10
Dubbo CRITICAL 9.8
CVE-2023-23638

A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.…

Fix: after 3.1.5
Fix from $2,300 2023-03-08
HTTP Server CRITICAL 9.8
CVE-2023-25690EPSS 85%

Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affec…

Fix: after 2.4.55
Fix from $2,300 2023-03-07
HTTP Server HIGH 7.5
CVE-2023-27522

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. …

Fix: 2.0.22 / 2.4.56+
Fix from $1,950 2023-03-07
Apache Airflow Providers Google CRITICAL 9.8
CVE-2023-25691

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1…

Fix: 8.10.0+
Fix from $2,300 2023-02-24
Apache Airflow Providers Apache Sqoop CRITICAL 9.8
CVE-2023-25693

Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

Fix: 3.1.1+
Fix from $2,300 2023-02-24
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2023-25696

Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

Fix: 5.1.3+
Fix from $2,300 2023-02-24