Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Apache Airflow Providers Google HIGH 7.5
CVE-2023-25692

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1…

Fix: 8.10.0+
Fix from $1,950 2023-02-24
Apache Airflow Providers Amazon HIGH 7.5
CVE-2023-25956

Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS…

Fix: 7.2.1+
Fix from $1,950 2023-02-24
Sling I18n MEDIUM 6.5
CVE-2023-25621

Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the reposito…

Fix: 2.6.2+
Fix from $1,600 2023-02-23
Kerby Ldap Backend CRITICAL 9.8
CVE-2023-25613

An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. 

Fix: 2.0.3+
Fix from $2,300 2023-02-20
Commons Fileupload HIGH 7.5
CVE-2023-24998EPSS 47%

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin…

Fix: 1.5+
Fix from $1,950 2023-02-20
Shenyu HIGH 8.8
CVE-2022-42735

Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators…

Mitigation only
Fix from $1,950 2023-02-15
Sling Jcr Base HIGH 7.5
CVE-2023-25141

Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct…

Fix: 3.1.12+
Fix from $1,950 2023-02-14
Nifi HIGH 7.5
CVE-2023-22832

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that i…

Fix: after 1.19.1
Fix from $1,950 2023-02-10
Kafka Connect HIGH 8.8
CVE-2023-25194EPSS 96%

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to…

Fix: after 3.3.2
Fix from $1,950 2023-02-07
Age HIGH 8.1
CVE-2022-45786

There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for Postgre…

Fix: after 1.1.0
Fix from $1,950 2023-02-04
Sling Cms MEDIUM 6.1
CVE-2023-22849

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and pri…

Fix: 1.1.6+
Fix from $1,600 2023-02-04
Inlong CRITICAL 9.8
CVE-2023-24997

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.…

Fix: after 1.5.0
Fix from $2,300 2023-02-01
Inlong HIGH 7.5
CVE-2023-24977

Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are ad…

Fix: after 1.5.0
Fix from $1,950 2023-02-01
Portable Runtime CRITICAL 9.8
CVE-2022-24963

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a …

Mitigation only
Fix from $2,300 2023-01-31
Portable Runtime CRITICAL 9.8
CVE-2022-28331

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int…

Fix: after 1.7.0
Fix from $2,300 2023-01-31
Portable Runtime Utility MEDIUM 6.5
CVE-2022-25147

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond…

Fix: after 1.6.1
Fix from $1,600 2023-01-31
Linkis HIGH 8.8
CVE-2022-44645

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…

Fix: after 1.3.0
Fix from $1,950 2023-01-31
Iotdb HIGH 8.8
CVE-2023-24829

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 bef…

Fix: 0.13.3+
Fix from $1,950 2023-01-31
Linkis MEDIUM 6.5
CVE-2022-44644

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files b…

Fix: after 1.3.0
Fix from $1,600 2023-01-31
Iotdb HIGH 7.5
CVE-2023-24830

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before…

Fix: 0.13.3+
Fix from $1,950 2023-01-30
Airflow CRITICAL 9.8
CVE-2023-22884EPSS 11%

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…

Fix: 2.5.1 / 4.0.0+
Fix from $2,300 2023-01-21
HTTP Server CRITICAL 9.0
CVE-2022-36760

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to sm…

Fix: 2.4.55+
Fix from $2,300 2023-01-17
HTTP Server HIGH 7.5
CVE-2006-20001

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header va…

Fix: 2.4.55+
Fix from $1,950 2023-01-17
HTTP Server MEDIUM 5.3
CVE-2022-37436EPSS 58%

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorpo…

Fix: 2.4.55+
Fix from $1,600 2023-01-17
Superset HIGH 8.8
CVE-2022-43719

Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…

Fix: after 1.5.2
Fix from $1,950 2023-01-16
Superset MEDIUM 5.4
CVE-2022-41703

A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subquerie…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Superset MEDIUM 5.4
CVE-2022-43717

Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Superset MEDIUM 5.4
CVE-2022-43718

Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with databas…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Superset MEDIUM 5.4
CVE-2022-43720

An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the t…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Superset MEDIUM 5.4
CVE-2022-43721

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh…

Fix: after 1.5.2
Fix from $1,600 2023-01-16