Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-39456EPSS 53% Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th… Traffic Server 9.2.3+ Fix from $1,9502023-10-17 HIGH 7.5 CVE-2023-41752 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.… Traffic Server 8.1.9 / 9.2.3+ Fix from $1,9502023-10-17 MEDIUM 6.1 CVE-2023-45757 Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can sen… Brpc 1.6.1+ Fix from $1,6002023-10-16 CRITICAL 9.8 CVE-2023-43668 Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se… Inlong after 1.8.0 Fix from $2,3002023-10-16 HIGH 7.5 CVE-2023-43667 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects … Inlong after 1.8.0 Fix from $1,9502023-10-16 MEDIUM 6.5 CVE-2023-43666 Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General u… Inlong after 1.8.0 Fix from $1,6002023-10-16 MEDIUM 6.5 CVE-2023-42780 Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, … Airflow 2.7.2+ Fix from $1,6002023-10-14 MEDIUM 6.5 CVE-2023-42792 Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to … Airflow 2.7.2+ Fix from $1,6002023-10-14 MEDIUM 6.5 CVE-2023-42663 Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat… Airflow 2.7.2+ Fix from $1,6002023-10-14 CRITICAL 9.1 CVE-2023-44981 Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru… Zookeeper 3.7.2 / 3.8.3+ Fix from $2,3002023-10-11 HIGH 8.8 CVE-2023-37536 An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. Xerces C\+\+ 9.5.23 / 10.0.10+ Fix from $1,9502023-10-11 MEDIUM 5.3 CVE-2023-45648EPSS 6% Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro… Tomcat 8.5.94 / 9.0.81+ Fix from $1,6002023-10-10 MEDIUM 5.9 CVE-2023-42794 Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5… Tomcat 8.5.94 / 9.0.81+ Fix from $1,6002023-10-10 MEDIUM 5.3 CVE-2023-42795 Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10… Tomcat 8.5.94 / 9.0.81+ Fix from $1,6002023-10-10 HIGH 7.5 CVE-2023-39410 When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of … Avro 1.11.3+ Fix from $1,9502023-09-29 MEDIUM 6.1 CVE-2023-41834 Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject… Flink Stateful Functions after 3.2.0 Fix from $1,6002023-09-19 MEDIUM 5.5 CVE-2023-42503 Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common… Commons Compress 1.24.0+ Fix from $1,6002023-09-14 HIGH 7.8 CVE-2023-41267 In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package… Airflow Hdfs Provider 4.1.1+ Fix from $1,9502023-09-14 HIGH 7.5 CVE-2023-41081 Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration… Tomcat Connectors 1.2.49+ Fix from $1,9502023-09-13 MEDIUM 6.5 CVE-2023-40712 Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, … Airflow 2.7.1+ Fix from $1,6002023-09-12 MEDIUM 6.6 CVE-2023-37941EPSS 29% If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to … Superset after 2.1.0 Fix from $1,6002023-09-06 MEDIUM 6.5 CVE-2023-39265EPSS 84% Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+p… Superset after 2.1.0 Fix from $1,6002023-09-06 MEDIUM 5.4 CVE-2023-36387 An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test d… Superset after 2.1.0 Fix from $1,6002023-09-06 MEDIUM 5.4 CVE-2023-36388 Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib… Superset after 2.1.0 Fix from $1,6002023-09-06 CRITICAL 9.8 CVE-2023-40743 ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S… Axis 2023-08-01+ Fix from $2,3002023-09-05 MEDIUM 5.9 CVE-2023-41180 Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate… Nifi Minifi C\+\+ after 0.14.0 Fix from $1,6002023-09-03 HIGH 8.8 CVE-2023-27604 Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, wh… Airflow Sqoop Provider 4.0.0+ Fix from $1,9502023-08-28 HIGH 8.8 CVE-2023-40195 Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo… Airflow Spark Provider 4.1.3+ Fix from $1,9502023-08-28 MEDIUM 6.1 CVE-2023-41080EPSS 6% URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from… Tomcat after 10.1.12 Fix from $1,6002023-08-25 HIGH 8.1 CVE-2023-37379 Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed… Airflow 2.7.0+ Fix from $1,9502023-08-23