Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Isis MEDIUM 6.1
CVE-2022-42466

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be render…

Fix: 2.0.0+
Fix from $1,600 2022-10-19
Isis MEDIUM 5.3
CVE-2022-42467

When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to dir…

Fix: 2.0.0+
Fix from $1,600 2022-10-19
Dubbo CRITICAL 9.8
CVE-2022-39198

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…

Fix: after 3.0.11
Fix from $2,300 2022-10-18
Commons Text CRITICAL 9.8
CVE-2022-42889EPSS 100%

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…

Fix: 1.10.0 / 7.5.0+
Fix from $2,300 2022-10-13
Kylin CRITICAL 9.8
CVE-2022-24697EPSS 85%

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can…

Fix: 2.6.6+
Fix from $2,300 2022-10-13
Shiro CRITICAL 9.8
CVE-2022-40664

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

Fix: 1.10.0+
Fix from $2,300 2022-10-12
Airflow HIGH 8.1
CVE-2022-41672

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the U…

Fix: after 2.4.1
Fix from $1,950 2022-10-07
Commons Jxpath MEDIUM 6.5
CVE-2022-40160

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Commons Jxpath MEDIUM 6.5
CVE-2022-40159

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Pulsar MEDIUM 6.5
CVE-2022-24280

Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from…

Fix: 2.7.5 / 2.8.3+
Fix from $1,600 2022-09-23
Pulsar MEDIUM 5.9
CVE-2022-33681

Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connectio…

Fix: 2.7.5 / 2.8.4+
Fix from $1,600 2022-09-23
Pulsar MEDIUM 5.9
CVE-2022-33682

TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's J…

Fix: 2.7.5 / 2.8.4+
Fix from $1,600 2022-09-23
Pulsar MEDIUM 5.9
CVE-2022-33683

Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnec…

Fix: 2.7.5 / 2.8.4+
Fix from $1,600 2022-09-23
Pinot CRITICAL 9.8
CVE-2022-26112

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…

Fix: 0.11.0+
Fix from $2,300 2022-09-23
Batik HIGH 7.5
CVE-2022-40146EPSS 6%

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec…

Mitigation only
Fix from $1,950 2022-09-22
Batik MEDIUM 5.3
CVE-2022-38398

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a…

Mitigation only
Fix from $1,600 2022-09-22
Batik MEDIUM 5.3
CVE-2022-38648

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A…

Mitigation only
Fix from $1,600 2022-09-22
Soap HIGH 7.5
CVE-2022-40705

An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files …

Mitigation only
Fix from $1,950 2022-09-22
Airflow HIGH 7.5
CVE-2022-40604

In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.

Fix: after 2.3.4
Fix from $1,950 2022-09-21
Airflow MEDIUM 6.1
CVE-2022-40754

In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.

Fix: after 2.3.4
Fix from $1,600 2022-09-21
Inlong HIGH 8.8
CVE-2022-40955

In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi…

Fix: 1.3.0+
Fix from $1,950 2022-09-20
Kafka HIGH 7.5
CVE-2022-34917

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated…

Fix: 2.8.2 / 3.0.2+
Fix from $1,950 2022-09-20
Calcite CRITICAL 9.8
CVE-2022-39135

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe…

Fix: 1.32.0+
Fix from $2,300 2022-09-11
James HIGH 7.5
CVE-2022-28220

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, …

Fix: after 3.6.2
Fix from $1,950 2022-09-08
Iotdb HIGH 8.8
CVE-2022-38369

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

No fix yet
Fix from $1,950 2022-09-05
Iotdb HIGH 7.5
CVE-2022-38370

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…

Mitigation only
Fix from $1,950 2022-09-05
Ofbiz CRITICAL 9.8
CVE-2022-25371

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Ofbiz CRITICAL 9.8
CVE-2022-29063

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Airflow CRITICAL 9.8
CVE-2022-38054

In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

Fix: after 2.3.3
Fix from $2,300 2022-09-02
Ofbiz HIGH 7.5
CVE-2022-25813EPSS 67%

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a …

Fix: 18.12.06+
Fix from $1,950 2022-09-02