Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-45505 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabili… Hertzbeat 1.6.1+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-45791 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Us… Hertzbeat 1.6.1+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-45784 Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability al… Airflow 2.10.3+ Fix from $1,9502024-11-15 CRITICAL 9.1 CVE-2024-50306 Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through… Traffic Server 9.2.6 / 10.0.2+ Fix from $2,3002024-11-14 HIGH 7.5 CVE-2024-50305 Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2… Traffic Server 9.2.6+ Fix from $1,9502024-11-14 HIGH 7.5 CVE-2024-38479 Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th… Traffic Server 9.2.6+ Fix from $1,9502024-11-14 CRITICAL 9.9 CVE-2024-50386 Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan… Cloudstack 4.18.2.5 / 4.19.1.3+ Fix from $2,3002024-11-12 CRITICAL 9.1 CVE-2024-51504 When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP bas… Zookeeper 3.9.3+ Fix from $2,3002024-11-07 HIGH 7.5 CVE-2024-38286 Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0… Tomcat 9.0.90 / 10.1.25+ Fix from $1,9502024-11-07 CRITICAL 9.1 CVE-2024-23590 Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to versio… Kylin 5.0.0+ Fix from $2,3002024-11-04 HIGH 8.1 CVE-2024-43383 Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8… Lucene.net Mitigation only Fix from $1,9502024-10-31 MEDIUM 6.1 CVE-2024-45031 When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored X… Syncope 3.0.9+ Fix from $1,6002024-10-24 HIGH 8.8 CVE-2024-45693 Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of t… Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-45216EPSS 91% Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen… Solr 8.11.4 / 9.7.0+ Fix from $2,3002024-10-16 HIGH 8.5 CVE-2024-45219 Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as … Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,9502024-10-16 HIGH 8.1 CVE-2024-45217 Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a config… Solr 8.11.4 / 9.7.0+ Fix from $1,9502024-10-16 HIGH 7.1 CVE-2024-45462 The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of th… Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,9502024-10-16 MEDIUM 6.3 CVE-2024-45461 The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. … Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,6002024-10-16 HIGH 8.8 CVE-2023-50780EPSS 17% Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia… Artemis 2.29.0+ Fix from $1,9502024-10-14 HIGH 7.8 CVE-2024-45720 On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead… Subversion 1.14.4+ Fix from $1,9502024-10-09 HIGH 7.5 CVE-2024-28168 Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: … Formatting Objects Processor Mitigation only Fix from $1,9502024-10-09 HIGH 7.3 CVE-2024-47561 Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgr… Avro 1.11.4+ Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-45772 Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before… Lucene Replicator 9.12.0+ Fix from $1,9502024-09-30 HIGH 7.5 CVE-2024-47197 Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This … Maven Archetype Mitigation only Fix from $1,9502024-09-26 MEDIUM 6.2 CVE-2024-23454 Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the oth… Hadoop 3.4.0+ Fix from $1,6002024-09-25 MEDIUM 5.3 CVE-2024-40761 Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's ema… Answer after 1.3.5 Fix from $1,6002024-09-25 HIGH 7.5 CVE-2024-39928 In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses t… Linkis 1.6.0+ Fix from $1,9502024-09-25 MEDIUM 5.9 CVE-2024-46544 Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configu… Tomcat Connectors 1.2.50+ Fix from $1,6002024-09-23 HIGH 8.8 CVE-2024-42323EPSS 8% SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attac… Hertzbeat 1.6.0+ Fix from $1,9502024-09-21 MEDIUM 6.5 CVE-2024-45537 Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se… Druid 30.0.1+ Fix from $1,6002024-09-17