Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-38474 Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by th… HTTP Server 2.4.60+ Fix from $2,3002024-07-01 CRITICAL 9.8 CVE-2024-38476EPSS 42% Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend a… HTTP Server 2.4.60+ Fix from $2,3002024-07-01 CRITICAL 9.1 CVE-2024-38475 KEVEPSS 100% Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p… HTTP Server 2.4.60 / 10.2.1.14-75sv+ Fix from $2,3002024-07-01 HIGH 8.1 CVE-2024-38473EPSS 26% Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, po… HTTP Server 2.4.60+ Fix from $1,9502024-07-01 HIGH 7.5 CVE-2024-38472EPSS 69% SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users … HTTP Server 2.4.60+ Fix from $1,9502024-07-01 MEDIUM 5.4 CVE-2024-36387 Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, de… HTTP Server after 2.4.59 Fix from $1,6002024-07-01 CRITICAL 9.1 CVE-2024-29868EPSS 6% Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery … Streampipes after 0.93.0 Fix from $2,3002024-06-24 MEDIUM 6.1 CVE-2024-27136EPSS 59% XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive infor… Jspwiki 2.12.2+ Fix from $1,6002024-06-24 MEDIUM 5.3 CVE-2024-34693 Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile ena… Superset 3.1.3 / 4.0.1+ Fix from $1,6002024-06-20 MEDIUM 5.5 CVE-2024-25142 Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynami… Airflow 2.9.2+ Fix from $1,6002024-06-14 CRITICAL 9.8 CVE-2024-36265 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Co… Submarine Mitigation only Fix from $2,3002024-06-12 CRITICAL 9.8 CVE-2024-36264 ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari… Submarine Patch available Fix from $2,3002024-06-12 HIGH 8.1 CVE-2024-36263 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarin… Submarine Patch available Fix from $1,9502024-06-12 HIGH 7.5 CVE-2024-36471 Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp… Allura 1.17.0+ Fix from $1,9502024-06-10 CRITICAL 9.1 CVE-2024-36104EPSS 87% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… Ofbiz 18.12.14+ Fix from $2,3002024-06-04 MEDIUM 5.4 CVE-2024-32077 Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users a… Airflow Patch available Fix from $1,6002024-05-14 CRITICAL 9.1 CVE-2024-34365 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A… Karaf Cave Mitigation only Fix from $2,3002024-05-14 CRITICAL 9.8 CVE-2024-32113 KEVEPSS 99% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before … Ofbiz 18.12.13+ Fix from $2,3002024-05-08 CRITICAL 9.8 CVE-2024-26579 Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can by… Inlong 1.12.0+ Fix from $2,3002024-05-08 MEDIUM 6.6 CVE-2023-35701 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and… Hive Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.3 CVE-2024-32638 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue af… Apisix Mitigation only Fix from $1,6002024-05-02 HIGH 8.8 CVE-2024-32114EPSS 7% In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are loc… Activemq 6.1.2+ Fix from $1,9502024-05-02 CRITICAL 9.8 CVE-2024-27348 KEVEPSS 99% RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & … Hugegraph 1.3.0+ Fix from $2,3002024-04-22 CRITICAL 9.1 CVE-2024-27349 Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. User… Hugegraph 1.3.0+ Fix from $2,3002024-04-22 MEDIUM 5.3 CVE-2024-27347 Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Use… Hugegraph Hubble 1.3.0+ Fix from $1,6002024-04-22 MEDIUM 6.5 CVE-2024-31391 Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Opera… Solr Operator 0.8.1+ Fix from $1,6002024-04-12 HIGH 7.4 CVE-2024-27309 While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditi… Kafka after 3.6.1 Fix from $1,9502024-04-12 HIGH 7.5 CVE-2024-31309EPSS 95% HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0… Traffic Server 8.1.10 / 9.2.4+ Fix from $1,9502024-04-10 MEDIUM 6.5 CVE-2024-31867 Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties… Zeppelin 0.11.1+ Fix from $1,6002024-04-09 CRITICAL 9.8 CVE-2024-31864 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic… Zeppelin 0.11.1+ Fix from $2,3002024-04-09