Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-31866 Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding co… Zeppelin 0.11.1+ Fix from $2,3002024-04-09 MEDIUM 6.5 CVE-2024-31865 Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the… Zeppelin 0.11.1+ Fix from $1,6002024-04-09 MEDIUM 6.1 CVE-2024-31868 Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal us… Zeppelin 0.11.1+ Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2024-31863 Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 bef… Zeppelin Mitigation only Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2022-47894 Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is … Zeppelin 0.11.0+ Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2024-31862 Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.… Zeppelin 0.11.0+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2021-28656 Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue aff… Zeppelin after 0.9.0 Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-31860 Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files… Zeppelin 0.11.0+ Fix from $1,6002024-04-09 HIGH 7.5 CVE-2024-24746 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in … Nimble 1.7.0+ Fix from $1,9502024-04-06 HIGH 7.5 CVE-2024-27316EPSS 91% HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do… HTTP Server 2.4.59+ Fix from $1,9502024-04-04 HIGH 7.3 CVE-2023-38709 Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects… HTTP Server 2.4.59 / 14.6+ Fix from $1,9502024-04-04 MEDIUM 6.3 CVE-2024-24795 HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applicat… HTTP Server 2.4.59 / 14.6+ Fix from $1,6002024-04-04 MEDIUM 6.4 CVE-2024-29008 A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to… Cloudstack 4.18.1.1+ Fix from $1,6002024-04-04 CRITICAL 9.8 CVE-2024-29006 By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead t… Cloudstack 4.18.1.1+ Fix from $2,3002024-04-04 HIGH 7.3 CVE-2024-29007 The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi… Cloudstack 4.18.1.1+ Fix from $1,9502024-04-04 MEDIUM 6.4 CVE-2024-29834 This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u… Pulsar 3.0.4 / 3.2.2+ Fix from $1,6002024-04-02 CRITICAL 9.8 CVE-2024-23538 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer… Fineract 1.9.0+ Fix from $2,3002024-03-29 CRITICAL 9.8 CVE-2024-23539 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer… Fineract 1.9.0+ Fix from $2,3002024-03-29 HIGH 8.8 CVE-2024-23537 Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to versi… Fineract 1.9.0+ Fix from $1,9502024-03-29 MEDIUM 5.3 CVE-2024-29735 Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local fil… Airflow after 2.8.4 Fix from $1,6002024-03-26 CRITICAL 9.8 CVE-2024-27438 Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting … Doris 2.0.5+ Fix from $2,3002024-03-21 MEDIUM 5.3 CVE-2024-26307 Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out… Doris 1.2.8 / 2.0.4+ Fix from $1,6002024-03-21 HIGH 7.3 CVE-2024-29131 Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are… Commons Configuration 2.10.1+ Fix from $1,9502024-03-21 MEDIUM 5.4 CVE-2024-29133 Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are… Commons Configuration 2.10.1+ Fix from $1,6002024-03-21 MEDIUM 6.5 CVE-2024-27439 An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wick… Wicket 9.17.0+ Fix from $1,6002024-03-19 MEDIUM 6.5 CVE-2024-24683 Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to… Hop Engine 2.8.0+ Fix from $1,6002024-03-19 CRITICAL 9.3 CVE-2024-28752 A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att… Cxf 3.5.8 / 3.6.3+ Fix from $2,3002024-03-15 MEDIUM 5.3 CVE-2024-23944 Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by… Zookeeper 3.8.4 / 3.9.2+ Fix from $1,6002024-03-15 HIGH 8.1 CVE-2024-28746 Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such… Airflow 2.8.3+ Fix from $1,9502024-03-14 HIGH 7.5 CVE-2024-24549EPSS 23% Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the requ… Tomcat 8.5.99 / 9.0.86+ Fix from $1,9502024-03-13