Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-61622EPSS 41% Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows… Fory after 0.12.2 Fix from $2,3002025-10-01 MEDIUM 6.5 CVE-2025-54831 Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connecti… Airflow Mitigation only Fix from $1,6002025-09-26 MEDIUM 5.3 CVE-2025-48459 Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to… Iotdb 2.0.5+ Fix from $1,6002025-09-24 HIGH 7.5 CVE-2025-48392 A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to… Iotdb 2.0.5+ Fix from $1,9502025-09-24 MEDIUM 6.5 CVE-2025-59328 A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr… Fory 0.12.2+ Fix from $1,6002025-09-15 HIGH 8.8 CVE-2025-24404 XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated accou… Hertzbeat 1.7.0+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-48208 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker nee… Hertzbeat 1.7.3+ Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-58782 Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Co… Jackrabbit 2.22.2+ Fix from $1,6002025-09-08 CRITICAL 9.8 CVE-2024-43166 Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recomme… Dolphinscheduler 3.2.2+ Fix from $2,3002025-09-03 HIGH 8.8 CVE-2024-43115 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This… Dolphinscheduler 3.2.2+ Fix from $1,9502025-09-03 HIGH 8.8 CVE-2025-26467 Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to s… Cassandra 3.0.31 / 3.11.18+ Fix from $1,9502025-08-25 HIGH 7.5 CVE-2025-54813 Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an at… Log4cxx 1.5.0+ Fix from $1,9502025-08-22 MEDIUM 5.4 CVE-2025-54812 Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing … Log4cxx 1.5.0+ Fix from $1,6002025-08-22 HIGH 7.6 CVE-2024-48988 SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade t… Streampark 2.1.6+ Fix from $1,9502025-08-22 HIGH 8.4 CVE-2025-54988EPSS 9% Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out… Tika 3.2.2+ Fix from $1,9502025-08-20 MEDIUM 6.3 CVE-2024-39954 CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse… Eventmesh 1.12.0+ Fix from $1,6002025-08-20 HIGH 8.8 CVE-2025-53192 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Ap… Commons Ognl Mitigation only Fix from $1,9502025-08-18 CRITICAL 9.8 CVE-2025-54466EPSS 15% Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects A… Ofbiz 24.09.02+ Fix from $2,3002025-08-15 MEDIUM 6.5 CVE-2025-55674 A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a… Superset 5.0.0+ Fix from $1,6002025-08-14 MEDIUM 6.5 CVE-2025-55675 Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated use… Superset 5.0.0+ Fix from $1,6002025-08-14 MEDIUM 5.4 CVE-2025-55672 A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit cha… Superset 5.0.0+ Fix from $1,6002025-08-14 HIGH 7.5 CVE-2025-54472 Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi… Brpc 1.14.1+ Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2025-55668 Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 t… Tomcat 9.0.106 / 10.1.42+ Fix from $1,6002025-08-13 HIGH 7.5 CVE-2025-48989 Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache … Tomcat 9.0.108 / 10.1.44+ Fix from $1,9502025-08-13 CRITICAL 9.8 CVE-2025-53606 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm… Seata Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.8 CVE-2025-48913 If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap… Cxf 3.6.8 / 4.0.9+ Fix from $2,3002025-08-08 MEDIUM 5.3 CVE-2024-51775 Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without … Zeppelin 0.12.0+ Fix from $1,6002025-08-03 MEDIUM 6.1 CVE-2024-41177 Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recomme… Zeppelin 0.12.0+ Fix from $1,6002025-08-03 MEDIUM 5.3 CVE-2024-52279 Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. … Zeppelin 0.12.0+ Fix from $1,6002025-08-03 MEDIUM 6.1 CVE-2025-24854 A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute … Jspwiki 2.12.3+ Fix from $1,6002025-07-31