Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-54057 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalki… Skywalking 10.3.0+ Fix from $1,6002025-11-27 CRITICAL 9.8 CVE-2025-59390 Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is… Druid 35.0.0+ Fix from $2,3002025-11-26 MEDIUM 5.4 CVE-2025-62728 SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i… Hive Mitigation only Fix from $1,6002025-11-26 HIGH 7.5 CVE-2025-65998 Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default optio… Syncope 3.0.15 / 4.0.3+ Fix from $1,9502025-11-24 MEDIUM 6.3 CVE-2025-64408EPSS 11% Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul… Causeway 3.5.0+ Fix from $1,6002025-11-19 MEDIUM 5.3 CVE-2025-64407 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,6002025-11-12 HIGH 7.3 CVE-2025-59118 Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommen… Ofbiz 24.09.03+ Fix from $1,9502025-11-12 MEDIUM 6.5 CVE-2025-61623 Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to… Ofbiz 24.09.03+ Fix from $1,6002025-11-12 HIGH 8.1 CVE-2025-64403 Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64404 Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft… Openoffice 4.1.16+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64405 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,9502025-11-12 MEDIUM 6.5 CVE-2025-64402 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,6002025-11-12 HIGH 7.5 CVE-2025-64401 Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha… Openoffice 4.1.16+ Fix from $1,9502025-11-12 MEDIUM 5.4 CVE-2025-58337 An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that s… Doris Mcp Server 0.6.0+ Fix from $1,6002025-11-05 HIGH 7.5 CVE-2025-62232 Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo… Apisix 3.14.0+ Fix from $1,9502025-10-31 MEDIUM 5.4 CVE-2025-62402 API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environmen… Airflow 3.1.1+ Fix from $1,6002025-10-30 MEDIUM 5.3 CVE-2025-61795 Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a m… Tomcat 9.0.110 / 10.0.27+ Fix from $1,6002025-10-27 CRITICAL 9.6 CVE-2025-55754EPSS 10% Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log mes… Tomcat 9.0.109 / 10.0.27+ Fix from $2,3002025-10-27 HIGH 7.5 CVE-2025-55752EPSS 67% Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized b… Tomcat 9.0.109 / 10.0.27+ Fix from $1,9502025-10-27 HIGH 7.2 CVE-2025-57738EPSS 23% Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few … Syncope 3.0.14 / 4.0.2+ Fix from $1,9502025-10-20 HIGH 8.8 CVE-2025-47410 Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricke… Geode 1.15.2+ Fix from $1,9502025-10-18 HIGH 7.5 CVE-2025-61581 ** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic… Traffic Control after 8.0.2 Fix from $1,9502025-10-16 CRITICAL 9.8 CVE-2025-54539 A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ … Activemq Nms Amqp 2.4.0+ Fix from $2,3002025-10-16 MEDIUM 6.5 CVE-2025-55039 This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure defau… Spark 3.4.4 / 3.5.2+ Fix from $1,6002025-10-15 MEDIUM 6.1 CVE-2024-44088 Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a… Geode 1.15.2+ Fix from $1,6002025-10-14 HIGH 7.3 CVE-2025-30001 Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users a… Streampark 2.1.6+ Fix from $1,9502025-10-10 HIGH 8.8 CVE-2025-62228 Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.… Flink Cdc Mitigation only Fix from $1,9502025-10-09 HIGH 7.5 CVE-2025-61734EPSS 18% Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin acce… Kylin 5.0.3+ Fix from $1,9502025-10-02 HIGH 7.3 CVE-2025-61735 Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as… Kylin 5.0.3+ Fix from $1,9502025-10-02 HIGH 7.5 CVE-2025-61733 Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. … Kylin 5.0.3+ Fix from $1,9502025-10-02