Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-39676 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. U… Pinot 1.0.0+ Fix from $1,9502024-07-24 HIGH 7.5 CVE-2024-41178 Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using… Arrow after 0.10.1 Fix from $1,9502024-07-23 CRITICAL 9.1 CVE-2024-29070 On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" … Streampark 2.1.4+ Fix from $2,3002024-07-23 MEDIUM 5.4 CVE-2024-38503 When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The… Syncope 3.0.8+ Fix from $1,6002024-07-22 MEDIUM 6.5 CVE-2024-34457 On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'… Streampark 2.1.4+ Fix from $1,6002024-07-22 HIGH 8.8 CVE-2024-23321 For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i… Rocketmq 5.3.0+ Fix from $1,9502024-07-22 HIGH 8.1 CVE-2024-41107EPSS 18% The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is en… Cloudstack 4.18.2.2 / 4.19.1.0+ Fix from $1,9502024-07-19 HIGH 7.5 CVE-2024-41172 In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instan… Cxf 3.6.4 / 4.0.5+ Fix from $1,9502024-07-19 CRITICAL 9.1 CVE-2024-29736 A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att… Cxf 3.5.9 / 3.6.4+ Fix from $2,3002024-07-19 HIGH 7.5 CVE-2024-32007 An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of… Cxf 3.5.9 / 3.6.4+ Fix from $1,9502024-07-19 HIGH 8.8 CVE-2024-29178 On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker … Streampark 2.1.4+ Fix from $1,9502024-07-18 HIGH 7.5 CVE-2024-40898 SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF… HTTP Server 2.4.62+ Fix from $1,9502024-07-18 MEDIUM 5.3 CVE-2024-40725 A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handler… HTTP Server Mitigation only Fix from $1,6002024-07-18 MEDIUM 5.9 CVE-2024-29120 In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication… Streampark 2.1.4+ Fix from $1,6002024-07-17 HIGH 8.8 CVE-2024-31411 Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead … Streampipes 0.95.0+ Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-39877 Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that … Airflow 2.9.3+ Fix from $1,9502024-07-17 MEDIUM 5.4 CVE-2024-39863 Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider… Airflow 2.9.3+ Fix from $1,6002024-07-17 CRITICAL 9.8 CVE-2024-39887 An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa… Superset 4.0.2+ Fix from $2,3002024-07-16 HIGH 8.1 CVE-2023-52290 In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en… Streampark 2.1.4+ Fix from $1,9502024-07-16 HIGH 8.8 CVE-2023-46801 In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version … Linkis 1.6.0+ Fix from $1,9502024-07-15 HIGH 8.8 CVE-2023-49566 In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSourc… Linkis 1.6.0+ Fix from $1,9502024-07-15 MEDIUM 6.5 CVE-2023-41916 In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSou… Linkis 1.6.0+ Fix from $1,6002024-07-15 CRITICAL 9.8 CVE-2024-36522 The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste… Wicket 8.16.0 / 9.18.0+ Fix from $2,3002024-07-12 MEDIUM 5.4 CVE-2024-37389EPSS 24% Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable… Nifi 1.27.0+ Fix from $1,6002024-07-08 CRITICAL 9.8 CVE-2024-39864 The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio… Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05 CRITICAL 9.8 CVE-2024-38346 The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and … Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05 MEDIUM 6.2 CVE-2024-39884 A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and si… HTTP Server Mitigation only Fix from $1,6002024-07-04 HIGH 7.5 CVE-2024-34750 Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomc… Tomcat 9.0.90 / 10.1.25+ Fix from $1,9502024-07-03 HIGH 7.5 CVE-2024-38477 null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users … HTTP Server 2.4.60+ Fix from $1,9502024-07-01 HIGH 7.5 CVE-2024-39573EPSS 35% Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to… HTTP Server 2.4.60+ Fix from $1,9502024-07-01