Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Apisix CRITICAL 9.8
CVE-2022-24112 KEVEPSS 96%

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX …

Fix: 2.10.4 / 2.12.1+
Fix from $2,300 2022-02-11
Cayenne HIGH 8.8
CVE-2022-24289

Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur…

Fix: 4.2+
Fix from $1,950 2022-02-11
Cassandra CRITICAL 9.1
CVE-2021-44521EPSS 55%

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…

Fix: 3.0.26 / 3.11.12+
Fix from $2,300 2022-02-11
Traffic Control HIGH 7.5
CVE-2022-23206

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted…

Fix: 5.1.6 / 6.1.0+
Fix from $1,950 2022-02-06
Artemis HIGH 7.5
CVE-2022-23913

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumptio…

Fix: 2.19.1+
Fix from $1,950 2022-02-04
Gobblin CRITICAL 9.8
CVE-2021-36152

Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to ver…

Fix: after 0.15.0
Fix from $2,300 2022-02-04
Gobblin MEDIUM 5.5
CVE-2021-36151

In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.…

Fix: after 0.15.0
Fix from $1,600 2022-02-04
Superset MEDIUM 6.5
CVE-2021-44451EPSS 8%

Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could b…

Fix: after 1.3.2
Fix from $1,600 2022-02-01
Pulsar MEDIUM 6.5
CVE-2021-41571

In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API…

Fix: 2.6.4 / 2.7.3+
Fix from $1,600 2022-02-01
Tomcat HIGH 7.0
CVE-2022-23181

The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, …

Fix: after 10.0.14
Fix from $1,950 2022-01-27
Karaf MEDIUM 5.3
CVE-2022-22932

Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk…

Fix: 4.2.15 / 4.3.6+
Fix from $1,600 2022-01-26
Karaf HIGH 8.1
CVE-2021-41766

Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…

Fix: 4.3.6+
Fix from $1,950 2022-01-26
Shenyu CRITICAL 9.1
CVE-2022-23944EPSS 79%

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $2,300 2022-01-25
Shenyu HIGH 7.5
CVE-2022-23223

On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to versio…

Patch available
Fix from $1,950 2022-01-25
Shenyu HIGH 7.5
CVE-2022-23945

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $1,950 2022-01-25
Shenyu CRITICAL 9.8
CVE-2021-45029EPSS 6%

Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Mitigation only
Fix from $2,300 2022-01-25
Xerces J MEDIUM 6.5
CVE-2022-23437

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the Xe…

Fix: 9.0+
Fix from $1,600 2022-01-24
Shardingsphere Elasticjob Ui MEDIUM 6.5
CVE-2022-22733EPSS 38%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco…

Mitigation only
Fix from $1,600 2022-01-20
Airflow MEDIUM 6.5
CVE-2021-45230

In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs f…

Fix: 2.2.0+
Fix from $1,600 2022-01-20
Log4j CRITICAL 9.8
CVE-2022-23305EPSS 67%

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from …

Fix: 1.2.18.2+
Fix from $2,300 2022-01-18
Log4j HIGH 8.8
CVE-2022-23302EPSS 64%

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration…

Fix: 1.2.18.1+
Fix from $1,950 2022-01-18
Chainsaw HIGH 8.8
CVE-2022-23307EPSS 54%

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j…

Fix: 1.2.18.1 / 2.0+
Fix from $1,950 2022-01-18
Knox MEDIUM 6.1
CVE-2021-42357

When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request t…

Fix: 1.6.1+
Fix from $1,600 2022-01-17
Guacamole HIGH 8.8
CVE-2021-43999

Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo…

Mitigation only
Fix from $1,950 2022-01-11
Guacamole MEDIUM 6.5
CVE-2021-41767

Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allo…

Fix: after 1.3.0
Fix from $1,600 2022-01-11
Dubbo CRITICAL 9.8
CVE-2021-43297EPSS 17%

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…

Fix: 2.6.12 / 2.7.15+
Fix from $2,300 2022-01-10
Avro HIGH 7.5
CVE-2021-43045

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. Th…

Fix: 1.11.0+
Fix from $1,950 2022-01-06
Kylin CRITICAL 9.8
CVE-2021-31522

Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…

Fix: 3.1.3+
Fix from $2,300 2022-01-06
Kylin CRITICAL 9.8
CVE-2021-45456EPSS 89%

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…

Mitigation only
Fix from $2,300 2022-01-06
Kylin HIGH 7.5
CVE-2021-45457

In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and p…

Fix: 3.1.3+
Fix from $1,950 2022-01-06