Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Superset MEDIUM 5.3
CVE-2022-45438

When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard c…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Shiro HIGH 7.5
CVE-2023-22602

When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authe…

Fix: 1.11.0+
Fix from $1,950 2023-01-14
Sling Cms MEDIUM 5.4
CVE-2022-46769

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and pri…

Fix: 1.1.4+
Fix from $1,600 2023-01-09
James MEDIUM 5.5
CVE-2022-45787

Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. Th…

Fix: 0.8.9+
Fix from $1,600 2023-01-06
James MEDIUM 5.5
CVE-2022-45935

Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in tra…

Fix: after 3.7.2
Fix from $1,600 2023-01-06
Dolphinscheduler CRITICAL 9.8
CVE-2022-45875

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects…

Fix: 3.0.2+
Fix from $2,300 2023-01-04
Tomcat HIGH 7.5
CVE-2022-45143

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In…

Fix: 9.0.69+
Fix from $1,950 2023-01-03
Dubbo CRITICAL 9.8
CVE-2021-32824

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…

Fix: 2.6.10 / 2.7.10+
Fix from $2,300 2023-01-03
Kylin CRITICAL 9.8
CVE-2022-44621

Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

Fix: 4.0.3+
Fix from $2,300 2022-12-30
Kylin HIGH 8.8
CVE-2022-43396EPSS 55%

In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the com…

Fix: 4.0.3+
Fix from $1,950 2022-12-30
Shardingsphere CRITICAL 9.8
CVE-2022-45347

Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentic…

Fix: 5.3.0+
Fix from $2,300 2022-12-22
Karaf CRITICAL 9.8
CVE-2022-40145

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function …

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-12-21
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2022-46421

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P…

Fix: 5.0.0+
Fix from $2,300 2022-12-20
Traffic Server MEDIUM 6.1
CVE-2022-40743

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting an…

Fix: after 9.1.3
Fix from $1,600 2022-12-19
Helix MEDIUM 6.1
CVE-2022-47500

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache H…

Fix: after 1.0.4
Fix from $1,600 2022-12-19
Traffic Server HIGH 7.5
CVE-2022-32749

Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server …

Fix: 8.1.6 / 9.1.4+
Fix from $1,950 2022-12-19
Traffic Server MEDIUM 5.3
CVE-2022-37392

Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traf…

Fix: 8.1.6 / 9.1.4+
Fix from $1,600 2022-12-19
Zeppelin MEDIUM 5.4
CVE-2022-46870

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to ex…

Fix: 0.8.2+
Fix from $1,600 2022-12-16
Zeppelin MEDIUM 6.5
CVE-2021-28655

The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. …

Fix: after 0.9.0
Fix from $1,600 2022-12-16
Bookkeeper MEDIUM 5.9
CVE-2022-32531

The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verificati…

Fix: 4.14.6+
Fix from $1,600 2022-12-15
Atlas HIGH 8.8
CVE-2022-34271

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas ver…

Fix: after 2.2.0
Fix from $1,950 2022-12-14
Cxf CRITICAL 9.8
CVE-2022-46364

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…

Fix: 3.4.10 / 3.5.5+
Fix from $2,300 2022-12-13
Cxf HIGH 7.5
CVE-2022-46363

A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vul…

Fix: 3.4.10 / 3.5.5+
Fix from $1,950 2022-12-13
Manifoldcf MEDIUM 5.3
CVE-2022-45910

Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory …

Fix: after 2.23
Fix from $1,600 2022-12-07
Commons Net MEDIUM 6.5
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net co…

Fix: 3.9.0+
Fix from $1,600 2022-12-03
Tapestry CRITICAL 9.8
CVE-2022-46366

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…

Fix: 4.0.0+
Fix from $2,300 2022-12-02
Fineract HIGH 8.8
CVE-2022-44635EPSS 69%

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Ap…

Fix: 1.8.1+
Fix from $1,950 2022-11-29
Dolphinscheduler HIGH 7.5
CVE-2022-26885

When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.

Fix: 2.0.6+
Fix from $1,950 2022-11-24
Dolphinscheduler CRITICAL 9.8
CVE-2022-45462

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade…

Fix: 2.0.6+
Fix from $2,300 2022-11-23
Airflow CRITICAL 9.8
CVE-2022-40189

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22