Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2024-56196 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are rec… Traffic Server 10.0.4+ Fix from $1,6002025-03-06 MEDIUM 6.3 CVE-2024-38311 Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th… Traffic Server 9.2.9 / 10.0.4+ Fix from $1,6002025-03-06 CRITICAL 9.8 CVE-2024-55532 Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade… Ranger 2.6.0+ Fix from $2,3002025-03-03 MEDIUM 6.5 CVE-2024-24778 Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This i… Streampipes 0.97.0+ Fix from $1,6002025-03-03 CRITICAL 9.8 CVE-2024-56180 CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo… Eventmesh 1.11.0+ Fix from $2,3002025-02-14 CRITICAL 9.0 CVE-2024-52577 In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili… Ignite 2.17.0+ Fix from $2,3002025-02-14 HIGH 7.1 CVE-2024-46910 An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users a… Atlas 2.4.0+ Fix from $1,9502025-02-13 HIGH 8.8 CVE-2024-32838 SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that al… Fineract 1.10.1+ Fix from $1,9502025-02-12 MEDIUM 6.1 CVE-2025-25247 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Ap… Felix Webconsole 4.9.10 / 5.0.10+ Fix from $1,6002025-02-10 MEDIUM 6.5 CVE-2025-25069 A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a va… Kvrocks 2.11.1+ Fix from $1,6002025-02-07 HIGH 8.5 CVE-2022-31764 The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue af… Shardingsphere Elasticjob Ui 3.0.2+ Fix from $1,9502025-02-06 HIGH 7.5 CVE-2024-45626 Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu… James Server 3.7.6 / 3.8.2+ Fix from $1,9502025-02-06 HIGH 7.5 CVE-2024-37358 Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthent… James Server 3.7.6 / 3.8.2+ Fix from $1,9502025-02-06 MEDIUM 5.4 CVE-2024-48019 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in … Doris 2.1.8 / 3.0.3+ Fix from $1,6002025-02-04 MEDIUM 5.4 CVE-2025-24860 Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi… Cassandra 4.0.16 / 4.1.8+ Fix from $1,6002025-02-04 MEDIUM 5.3 CVE-2024-27137 In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI… Cassandra 4.0.15 / 4.1.8+ Fix from $1,6002025-02-04 HIGH 8.8 CVE-2025-23015 Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to s… Cassandra 3.0.31 / 3.11.18+ Fix from $1,9502025-02-04 MEDIUM 5.5 CVE-2024-29869 Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set exp… Hive 4.0.1+ Fix from $1,6002025-01-28 MEDIUM 6.5 CVE-2024-23953 Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary mes… Hive 4.0.0+ Fix from $1,6002025-01-28 HIGH 7.5 CVE-2025-24783 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects… Cocoon Mitigation only Fix from $1,9502025-01-27 MEDIUM 5.5 CVE-2025-24814 Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetSer… Solr 9.8.0+ Fix from $1,6002025-01-27 MEDIUM 5.4 CVE-2024-52012EPSS 47% Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a … Solr 9.8.0+ Fix from $1,6002025-01-27 MEDIUM 6.5 CVE-2024-53299 The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.… Wicket 9.19.0 / 10.3.0+ Fix from $1,6002025-01-23 CRITICAL 9.1 CVE-2024-45479 SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger… Ranger 2.5.0+ Fix from $2,3002025-01-21 HIGH 8.8 CVE-2024-51941 A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbit… Ambari after 2.7.8 Fix from $1,9502025-01-21 HIGH 8.8 CVE-2025-23196 A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell co… Ambari 2.7.9+ Fix from $1,9502025-01-21 HIGH 7.5 CVE-2025-23195 An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerab… Ambari 2.7.9+ Fix from $1,9502025-01-21 HIGH 7.5 CVE-2025-23184 A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutput… Cxf 3.5.10 / 3.6.5+ Fix from $1,9502025-01-21 MEDIUM 5.9 CVE-2024-45627 In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSou… Linkis 1.7.0+ Fix from $1,6002025-01-14 CRITICAL 9.8 CVE-2024-54676EPSS 65% Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions … Openmeetings 8.0.0+ Fix from $2,3002025-01-08