Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2024-45033 Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When us… Apache Airflow Providers Fab 1.5.2+ Fix from $1,9502025-01-08 MEDIUM 5.4 CVE-2024-56512 Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenc… Nifi 2.1.0+ Fix from $1,6002024-12-28 CRITICAL 9.8 CVE-2024-52046EPSS 24% The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary… Mina 2.0.27 / 2.1.10+ Fix from $2,3002024-12-25 CRITICAL 9.8 CVE-2024-43441EPSS 69% Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 bef… Hugegraph 1.5.0+ Fix from $2,3002024-12-24 HIGH 8.8 CVE-2024-45387EPSS 42% An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", … Traffic Control 8.0.2+ Fix from $1,9502024-12-23 MEDIUM 5.9 CVE-2024-23945 Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signatu… Hive 3.3.4 / 3.4.2+ Fix from $1,6002024-12-23 CRITICAL 9.8 CVE-2024-56337EPSS 9% Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, f… Tomcat 9.0.98 / 10.1.34+ Fix from $2,3002024-12-20 MEDIUM 5.3 CVE-2024-56128 Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Sal… Kafka 3.7.2+ Fix from $1,6002024-12-18 CRITICAL 9.8 CVE-2024-50379EPSS 44% Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file syste… Tomcat 9.0.98 / 10.1.34+ Fix from $2,3002024-12-17 MEDIUM 5.3 CVE-2024-54677 Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue a… Tomcat 9.0.98 / 10.1.34+ Fix from $1,6002024-12-17 MEDIUM 6.5 CVE-2024-55633 Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed… Superset 4.1.0+ Fix from $1,6002024-12-12 CRITICAL 9.8 CVE-2024-53677EPSS 78% File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th… Struts 6.4.0+ Fix from $2,3002024-12-11 CRITICAL 9.8 CVE-2024-53947 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s… Superset 4.1.0+ Fix from $2,3002024-12-09 MEDIUM 6.5 CVE-2024-53949 Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users … Superset 4.1.0+ Fix from $1,6002024-12-09 MEDIUM 5.3 CVE-2024-53948 Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users a… Superset 4.1.0+ Fix from $1,6002024-12-09 HIGH 8.3 CVE-2022-41137 Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is un… Hive Patch available Fix from $1,9502024-12-05 HIGH 8.1 CVE-2024-45106 Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t… Ozone Mitigation only Fix from $1,9502024-12-03 CRITICAL 9.8 CVE-2024-52338 Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut… Arrow 17.0.0+ Fix from $2,3002024-11-28 HIGH 7.5 CVE-2024-51569 Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access wh… Nimble 1.8.0+ Fix from $1,9502024-11-26 MEDIUM 6.3 CVE-2024-47248 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result i… Nimble 1.8.0+ Fix from $1,6002024-11-26 MEDIUM 5.0 CVE-2024-47249 Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bo… Nimble 1.8.0+ Fix from $1,6002024-11-26 MEDIUM 5.0 CVE-2024-47250 Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsin… Nimble 1.8.0+ Fix from $1,6002024-11-26 MEDIUM 6.5 CVE-2018-9481 In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information d… Traffic Server 7.1.10 / 8.0.7+ Fix from $1,6002024-11-20 MEDIUM 6.5 CVE-2024-31141 Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accep… Kafka after 3.6.2 Fix from $1,6002024-11-19 MEDIUM 6.1 CVE-2024-52318 Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommend… Tomcat Mitigation only Fix from $1,6002024-11-18 CRITICAL 9.8 CVE-2024-52316EPSS 6% Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuth… Tomcat 9.0.96 / 10.1.31+ Fix from $2,3002024-11-18 MEDIUM 6.5 CVE-2024-52317 Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could… Tomcat 9.0.96 / 10.1.31+ Fix from $1,6002024-11-18 CRITICAL 9.8 CVE-2024-47208 Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.17+ Fix from $2,3002024-11-18 HIGH 8.8 CVE-2024-48962 Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a… Ofbiz 18.12.17+ Fix from $1,9502024-11-18 HIGH 8.8 CVE-2024-41151 Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue … Hertzbeat 1.6.1+ Fix from $1,9502024-11-18