Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-27820 A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered b… Httpclient 5.4.3+ Fix from $1,9502025-04-24 HIGH 7.5 CVE-2025-26413 Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it … Kvrocks 2.12.0+ Fix from $1,9502025-04-22 CRITICAL 9.8 CVE-2025-29953 Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client befor… Activemq Nms Openwire 2.1.1+ Fix from $2,3002025-04-18 MEDIUM 6.5 CVE-2024-56736 Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are rec… Hertzbeat 1.7.0+ Fix from $1,6002025-04-16 HIGH 8.8 CVE-2025-24859 A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after passwor… Roller 6.1.5+ Fix from $1,9502025-04-14 MEDIUM 6.5 CVE-2025-27391 Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when th… Artemis 2.40.0+ Fix from $1,6002025-04-09 MEDIUM 6.5 CVE-2025-30677 Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka … Pulsar 3.0.11 / 3.3.6+ Fix from $1,6002025-04-09 MEDIUM 5.3 CVE-2025-31672 Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file forma… Poi 5.4.0+ Fix from $1,6002025-04-09 HIGH 8.8 CVE-2025-30473 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using… Airflow Common Sql Provider 1.24.1+ Fix from $1,9502025-04-07 HIGH 7.5 CVE-2024-53868 Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through … Traffic Server 9.2.10 / 10.0.5+ Fix from $1,9502025-04-03 MEDIUM 6.1 CVE-2025-30676EPSS 65% Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… Ofbiz 18.12.19+ Fix from $1,6002025-04-01 MEDIUM 6.5 CVE-2025-30177 Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0… Camel 4.8.6 / 4.10.3+ Fix from $1,6002025-04-01 CRITICAL 9.8 CVE-2024-56325EPSS 79% Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Examp… Pinot 1.3.0+ Fix from $2,3002025-04-01 CRITICAL 9.8 CVE-2025-30065EPSS 41% Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are reco… Parquet Java 1.15.1+ Fix from $2,3002025-04-01 MEDIUM 6.5 CVE-2025-29868 Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user use… Answer after 1.4.2 Fix from $1,6002025-04-01 HIGH 7.2 CVE-2025-30067 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project adm… Kylin 5.0.2+ Fix from $1,9502025-03-27 MEDIUM 6.5 CVE-2024-48944 Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d… Kylin 5.0.2+ Fix from $1,6002025-03-27 MEDIUM 5.4 CVE-2024-53679 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with… Vcl 2.5.2+ Fix from $1,6002025-03-25 HIGH 8.8 CVE-2024-53678 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitte… Vcl 2.5.2+ Fix from $1,9502025-03-25 MEDIUM 5.0 CVE-2025-30474 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when … Commons Vfs 2.10.0+ Fix from $1,6002025-03-23 HIGH 7.5 CVE-2025-27553 Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a… Commons Vfs 2.10.0+ Fix from $1,9502025-03-23 MEDIUM 5.4 CVE-2025-26796 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. … Oozie Mitigation only Fix from $1,6002025-03-22 MEDIUM 5.4 CVE-2025-27888 Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… Druid 31.0.2+ Fix from $1,6002025-03-20 CRITICAL 9.8 CVE-2024-47552 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.… Seata 2.2.0+ Fix from $2,3002025-03-20 MEDIUM 6.3 CVE-2025-27018 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user trigg… Apache Airflow Providers Mysql 6.2.0+ Fix from $1,6002025-03-19 MEDIUM 6.5 CVE-2025-27017 Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB comp… Nifi 2.3.0+ Fix from $1,6002025-03-12 MEDIUM 5.6 CVE-2025-27867 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issu… Felix Http Webconsole Plugin 1.2.2+ Fix from $1,6002025-03-12 CRITICAL 9.8 CVE-2025-24813 KEVEPSS 100% Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade… Tomcat 9.0.99 / 10.1.35+ Fix from $2,3002025-03-10 MEDIUM 5.6 CVE-2025-27636EPSS 81% Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.… Camel 3.22.4 / 4.8.5+ Fix from $1,6002025-03-09 MEDIUM 6.3 CVE-2024-56195 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 thro… Traffic Server 9.2.9 / 10.0.4+ Fix from $1,6002025-03-06