Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-51653 Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec… Hertzbeat 1.4.1+ Fix from $2,3002024-02-22 CRITICAL 9.1 CVE-2024-22393 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack b… Answer 1.2.5+ Fix from $2,3002024-02-22 MEDIUM 5.9 CVE-2024-26578 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache … Answer after 1.2.1 Fix from $1,6002024-02-22 MEDIUM 5.4 CVE-2024-23349 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer:… Answer after 1.2.1 Fix from $1,6002024-02-22 CRITICAL 9.1 CVE-2024-25141 When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte… Apache Airflow Providers Mongo 4.0.0+ Fix from $2,3002024-02-20 CRITICAL 9.8 CVE-2024-23114 Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa… Camel 3.21.4 / 4.0.4+ Fix from $2,3002024-02-20 HIGH 7.8 CVE-2024-22369 Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 b… Camel 3.21.4 / 4.0.4+ Fix from $1,9502024-02-20 HIGH 7.5 CVE-2023-51770 Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr… Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-20 HIGH 7.3 CVE-2023-49250 Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connectio… Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-20 MEDIUM 6.5 CVE-2023-50270 Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgr… Dolphinscheduler 3.2.1+ Fix from $1,6002024-02-20 CRITICAL 9.8 CVE-2023-49109 Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr… Dolphinscheduler 3.2.1+ Fix from $2,3002024-02-20 MEDIUM 5.5 CVE-2024-26308 Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 b… Commons Compress 1.26.0+ Fix from $1,6002024-02-19 MEDIUM 5.5 CVE-2024-25710 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 … Commons Compress 1.26.0+ Fix from $1,6002024-02-19 MEDIUM 6.5 CVE-2024-23952 This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be trig… Superset 2.1.3 / 3.0.2+ Fix from $1,6002024-02-14 HIGH 8.8 CVE-2023-50386EPSS 84% Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2023-50291 Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.… Solr 8.11.3 / 9.3.0+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2023-50292 Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This iss… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2023-50298 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, fr… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2024-23452 Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause D… Brpc 1.8.0+ Fix from $1,9502024-02-08 MEDIUM 5.3 CVE-2023-39196 Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container M… Ozone after 1.3.0 Fix from $1,6002024-02-07 HIGH 7.4 CVE-2023-51437 Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will … Pulsar 2.11.3 / 3.0.2+ Fix from $1,9502024-02-07 HIGH 7.5 CVE-2024-23673 Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sli… Sling Servlets Resolver 2.11.0+ Fix from $1,9502024-02-06 HIGH 7.5 CVE-2023-44312 Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Cente… Servicecomb 2.2.0+ Fix from $1,9502024-01-31 HIGH 7.5 CVE-2023-44313 Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec… Servicecomb 2.2.0+ Fix from $1,9502024-01-31 HIGH 7.5 CVE-2023-29055 In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain… Kylin 4.0.4+ Fix from $1,9502024-01-29 MEDIUM 6.5 CVE-2023-50944 Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't … Airflow 2.8.1+ Fix from $1,6002024-01-24 MEDIUM 6.5 CVE-2023-51702 Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes th… Airflow 2.6.1 / 7.0.0+ Fix from $1,6002024-01-24 HIGH 7.5 CVE-2023-50943 Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "… Airflow 2.8.1+ Fix from $1,9502024-01-24 MEDIUM 5.4 CVE-2023-49657 A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on… Superset 3.0.3+ Fix from $1,6002024-01-23 MEDIUM 5.3 CVE-2024-21733EPSS 14% Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.… Tomcat 8.5.64 / 9.0.44+ Fix from $1,6002024-01-19