Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-46226 Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to v… Iotdb 1.3.0+ Fix from $2,3002024-01-15 MEDIUM 6.5 CVE-2023-46749 Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe… Shiro 1.13.0+ Fix from $1,6002024-01-15 MEDIUM 6.5 CVE-2023-50290EPSS 68% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment v… Solr 9.3.0+ Fix from $1,6002024-01-15 HIGH 7.2 CVE-2023-51441 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss… Axis after 1.3 Fix from $1,9502024-01-06 CRITICAL 9.8 CVE-2023-51784 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, … Inlong 1.10.0+ Fix from $2,3002024-01-03 HIGH 7.5 CVE-2023-51785 Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a… Inlong after 1.9.0 Fix from $1,9502024-01-03 HIGH 8.8 CVE-2023-49299 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed … Dolphinscheduler 3.1.9+ Fix from $1,9502023-12-30 HIGH 8.8 CVE-2023-47804 Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. … Openoffice 4.1.15+ Fix from $1,9502023-12-29 CRITICAL 9.8 CVE-2023-51467EPSS 96% The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code Ofbiz 18.12.11+ Fix from $2,3002023-12-26 HIGH 7.5 CVE-2023-50968EPSS 63% Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th… Ofbiz 18.12.11+ Fix from $1,9502023-12-26 HIGH 7.5 CVE-2023-51650 Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized acc… Hertzbeat 1.4.1+ Fix from $1,9502023-12-22 HIGH 8.8 CVE-2023-51387 Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo… Hertzbeat 1.4.1+ Fix from $1,9502023-12-22 HIGH 7.5 CVE-2022-39337 Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v… Hertzbeat 1.2.1+ Fix from $1,9502023-12-22 CRITICAL 9.8 CVE-2023-51656 Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended t… Iotdb after 0.13.4 Fix from $2,3002023-12-21 MEDIUM 6.5 CVE-2023-49920 Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. A… Airflow after 2.7.3 Fix from $1,6002023-12-21 MEDIUM 6.5 CVE-2023-50783 Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to upda… Airflow 2.8.0+ Fix from $1,6002023-12-21 MEDIUM 5.4 CVE-2023-47265 Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript… Airflow after 2.7.3 Fix from $1,6002023-12-21 HIGH 7.5 CVE-2023-37544 Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication… Pulsar 2.10.5 / 2.11.2+ Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-43826 Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user con… Guacamole after 1.5.3 Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-49736 A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup… Superset 2.1.2 / 3.0.2+ Fix from $1,9502023-12-19 MEDIUM 6.5 CVE-2023-49734 An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the… Superset 2.1.2 / 3.0.2+ Fix from $1,6002023-12-19 MEDIUM 6.5 CVE-2023-46104 Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.… Superset 2.1.3 / 3.0.1+ Fix from $1,6002023-12-19 HIGH 8.2 CVE-2023-41314 The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Plea… Doris 2.0.3+ Fix from $1,9502023-12-18 HIGH 7.2 CVE-2023-49898 In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of … Streampark 2.1.2+ Fix from $1,9502023-12-15 CRITICAL 9.8 CVE-2023-29234EPSS 7% A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug… Dubbo after 3.2.4 Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-46279 Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the … Dubbo Mitigation only Fix from $2,3002023-12-15 MEDIUM 6.1 CVE-2023-46750 URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Sh… Shiro 1.13.0+ Fix from $1,6002023-12-14 MEDIUM 5.7 CVE-2023-45725 Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the do… Couchdb after 3.3.2 Fix from $1,6002023-12-13 CRITICAL 9.8 CVE-2023-50164EPSS 81% An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file whic… Struts 2.5.33 / 6.3.0.2+ Fix from $2,3002023-12-07 HIGH 7.5 CVE-2023-41835EPSS 6% When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.save… Struts 2.5.32 / 6.3.0.1+ Fix from $1,9502023-12-05