Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2024-23672 Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open lea… Tomcat 8.5.99 / 9.0.86+ Fix from $1,6002024-03-13 MEDIUM 5.4 CVE-2024-28098 The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off… Pulsar 2.10.6 / 2.11.4+ Fix from $1,6002024-03-12 CRITICAL 9.9 CVE-2024-27135EPSS 6% Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function w… Pulsar 2.10.6 / 2.11.4+ Fix from $2,3002024-03-12 CRITICAL 9.9 CVE-2024-27317EPSS 57% In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu… Pulsar 2.10.6 / 2.11.4+ Fix from $2,3002024-03-12 HIGH 8.8 CVE-2024-27894 The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referen… Pulsar 2.10.6 / 2.11.4+ Fix from $1,9502024-03-12 HIGH 8.2 CVE-2022-34321 Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The v… Pulsar 2.10.6 / 2.11.3+ Fix from $1,9502024-03-12 CRITICAL 9.8 CVE-2023-41313 The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 +… Doris 1.2.8+ Fix from $2,3002024-03-12 MEDIUM 5.3 CVE-2023-50740 In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users … Linkis 1.5.0+ Fix from $1,6002024-03-06 CRITICAL 9.1 CVE-2024-26580 Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use… Inlong 1.11.0+ Fix from $2,3002024-03-06 HIGH 7.5 CVE-2024-27139 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated… Archiva Mitigation only Fix from $1,9502024-03-01 MEDIUM 5.4 CVE-2024-27140 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva… Archiva Mitigation only Fix from $1,6002024-03-01 HIGH 7.5 CVE-2024-27138 ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, … Archiva Mitigation only Fix from $1,9502024-03-01 MEDIUM 6.1 CVE-2023-50378 Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited … Ambari 2.7.8+ Fix from $1,6002024-03-01 MEDIUM 5.9 CVE-2024-27906 Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not hav… Airflow 2.8.2+ Fix from $1,6002024-02-29 CRITICAL 9.1 CVE-2024-25065EPSS 48% Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Ofbiz 18.12.12+ Fix from $2,3002024-02-29 MEDIUM 5.3 CVE-2024-23946 Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Ofbiz 18.12.12+ Fix from $1,6002024-02-29 CRITICAL 9.8 CVE-2024-23807 The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. User… Xerces C\+\+ 3.2.5+ Fix from $2,3002024-02-29 MEDIUM 6.5 CVE-2024-24773 Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apa… Superset 3.0.4 / 3.1.1+ Fix from $1,6002024-02-28 MEDIUM 6.5 CVE-2024-24779 Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual dat… Superset 3.1.1+ Fix from $1,6002024-02-28 MEDIUM 5.4 CVE-2024-26016 A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby … Superset 3.0.4 / 3.1.1+ Fix from $1,6002024-02-28 MEDIUM 5.3 CVE-2024-21742 Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an atta… James Mime4j after 0.8.9 Fix from $1,6002024-02-27 MEDIUM 6.5 CVE-2023-50380 XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More De… Ambari 2.7.8+ Fix from $1,6002024-02-27 CRITICAL 9.1 CVE-2024-27905 ** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte… Aurora Mitigation only Fix from $2,3002024-02-27 HIGH 7.1 CVE-2023-51747 Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ… James Mitigation only Fix from $1,9502024-02-27 CRITICAL 9.8 CVE-2023-51518 Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi… James Mitigation only Fix from $2,3002024-02-27 HIGH 8.8 CVE-2023-50379 Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cl… Ambari 2.7.8+ Fix from $1,9502024-02-27 HIGH 7.5 CVE-2024-22371 Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerabi… Camel 3.21.4 / 4.0.4+ Fix from $1,9502024-02-26 HIGH 8.8 CVE-2024-23320 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed … Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-23 CRITICAL 9.8 CVE-2023-51388 Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no … Hertzbeat 1.4.1+ Fix from $2,3002024-02-22 CRITICAL 9.8 CVE-2023-51389 Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co… Hertzbeat 1.4.1+ Fix from $2,3002024-02-22