Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ozone HIGH 8.8
CVE-2021-39232

In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

Fix: 1.2.0+
Fix from $1,950 2021-11-19
Ozone HIGH 8.8
CVE-2021-39236

In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

Fix: 1.2.0+
Fix from $1,950 2021-11-19
Ozone MEDIUM 6.8
CVE-2021-39234

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Ozone MEDIUM 6.5
CVE-2021-39235

In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block to…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Ozone MEDIUM 5.3
CVE-2021-41532

In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Ozone CRITICAL 9.8
CVE-2021-36372

In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authentica…

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Superset MEDIUM 6.5
CVE-2021-42250

Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject ma…

Fix: 1.3.2+
Fix from $1,600 2021-11-17
Shenyu CRITICAL 9.8
CVE-2021-37580EPSS 40%

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…

Mitigation only
Fix from $2,300 2021-11-16
Superset MEDIUM 6.5
CVE-2021-41972

Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed …

Fix: after 1.3.1
Fix from $1,600 2021-11-12
Traffic Control CRITICAL 9.8
CVE-2021-43350

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…

Fix: 5.1.4 / 6.0.1+
Fix from $2,300 2021-11-11
Shardingsphere Ui HIGH 7.5
CVE-2021-26558

Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa…

Fix: 5.0.0+
Fix from $1,950 2021-11-11
Traffic Server CRITICAL 9.8
CVE-2021-43082

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an…

Fix: after 9.1.0
Fix from $2,300 2021-11-03
Traffic Server HIGH 8.1
CVE-2021-38161

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap…

Fix: after 8.0.8
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-37148

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.0.1
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-37149

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-41585

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting…

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-37147

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Dolphinscheduler HIGH 8.8
CVE-2021-27644

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so…

Fix: 1.3.6+
Fix from $1,950 2021-11-01
Mina MEDIUM 6.5
CVE-2021-41973

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the H…

Fix: 2.0.22 / 2.1.5+
Fix from $1,600 2021-11-01
Storm CRITICAL 9.8
CVE-2021-40865EPSS 66%

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Storm CRITICAL 9.8
CVE-2021-38294EPSS 84%

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Superset HIGH 8.8
CVE-2021-41971

Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic…

Fix: after 1.3.0
Fix from $1,950 2021-10-18
Superset MEDIUM 5.4
CVE-2021-32609

Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a…

Fix: after 1.1
Fix from $1,600 2021-10-18
Tomcat HIGH 7.5
CVE-2021-42340EPSS 12%

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memor…

Fix: 8.5.72 / 9.0.54+
Fix from $1,950 2021-10-14
Couchdb HIGH 7.3
CVE-2021-38295

In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB…

Fix: 3.1.2+
Fix from $1,950 2021-10-14
Openoffice HIGH 7.5
CVE-2021-41832

It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are…

Fix: 4.1.11+
Fix from $1,950 2021-10-11
Openoffice HIGH 7.5
CVE-2021-41830

It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice u…

Fix: 4.1.11+
Fix from $1,950 2021-10-11
Openoffice MEDIUM 5.3
CVE-2021-41831

It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users ar…

Fix: 4.1.11+
Fix from $1,600 2021-10-11
HTTP Server CRITICAL 9.8
CVE-2021-42013 KEVEPSS 100%

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs…

Fix: 9.2.6.0 / 18.1.0.1.0+
Fix from $2,300 2021-10-07
Openoffice MEDIUM 6.5
CVE-2021-40439

Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia…

Fix: after 4.1.10
Fix from $1,600 2021-10-07