Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.0 CVE-2023-40273 The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has bee… Airflow after 2.7.0 Fix from $1,9502023-08-23 MEDIUM 5.9 CVE-2023-39441 Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation … Airflow 1.3.0 / 2.7.0+ Fix from $1,6002023-08-23 HIGH 7.1 CVE-2022-44729 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik… Xml Graphics Batik after 1.16 Fix from $1,9502023-08-22 HIGH 8.2 CVE-2022-46751 Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache I… Ivy 2.5.2+ Fix from $1,9502023-08-21 MEDIUM 6.5 CVE-2023-40037 Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that … Nifi 1.23.1+ Fix from $1,6002023-08-18 HIGH 7.5 CVE-2023-40272 Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when est… Apache Airflow Providers Apache Spark 4.1.3+ Fix from $1,9502023-08-17 HIGH 7.5 CVE-2023-39553 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a … Apache Airflow Providers Apache Drill 2.4.3+ Fix from $1,9502023-08-11 CRITICAL 9.1 CVE-2023-33934 Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. Traffic Server after 9.2.1 Fix from $2,3002023-08-09 HIGH 7.5 CVE-2022-47185 Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Ser… Traffic Server after 9.2.1 Fix from $1,9502023-08-09 MEDIUM 5.4 CVE-2023-37581 Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all … Roller 6.1.2+ Fix from $1,6002023-08-06 HIGH 8.8 CVE-2023-39508 Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apach… Airflow 2.6.0+ Fix from $1,9502023-08-05 HIGH 8.8 CVE-2023-36542 Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an … Nifi after 1.22.0 Fix from $1,9502023-07-29 CRITICAL 9.8 CVE-2023-38647 An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S… Helix 1.3.0+ Fix from $2,3002023-07-26 MEDIUM 6.1 CVE-2023-38435 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole… Felix Health Check Webconsole Plugin 2.1.0+ Fix from $1,6002023-07-25 CRITICAL 9.8 CVE-2023-37895 Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in… Jackrabbit 2.20.11 / 2.21.18+ Fix from $2,3002023-07-25 CRITICAL 9.8 CVE-2023-35088 Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i… Inlong after 1.7.0 Fix from $2,3002023-07-25 HIGH 7.5 CVE-2023-34434 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.… Inlong after 1.7.0 Fix from $1,9502023-07-25 MEDIUM 6.5 CVE-2023-34189 Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1… Inlong after 1.7.0 Fix from $1,6002023-07-25 CRITICAL 9.8 CVE-2023-34478 Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth… Shiro 1.12.0+ Fix from $2,3002023-07-24 HIGH 8.8 CVE-2023-28754 Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a sp… Shardingsphere 5.4.0+ Fix from $1,9502023-07-19 CRITICAL 9.8 CVE-2023-26512 CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac… Eventmesh Connector Rabbitmq after 1.8.0 Fix from $2,3002023-07-17 HIGH 8.8 CVE-2023-37415 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before … Apache Airflow Providers Apache Hive 6.1.2+ Fix from $1,9502023-07-13 CRITICAL 9.8 CVE-2023-37582EPSS 90% The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version … Rocketmq after 5.1.1 Fix from $2,3002023-07-12 MEDIUM 6.5 CVE-2023-37579 Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, … Pulsar 2.10.4+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-31007 Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti… Pulsar 2.9.5+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-35908 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommende… Airflow 2.6.3+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-36543 Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is … Airflow 2.6.3+ Fix from $1,6002023-07-12 HIGH 8.8 CVE-2022-42009 SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remote… Ambari 2.7.7+ Fix from $1,9502023-07-12 HIGH 8.8 CVE-2022-45855 SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remo… Ambari 2.7.7+ Fix from $1,9502023-07-12 HIGH 8.8 CVE-2023-30429 Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Whe… Pulsar 2.10.4+ Fix from $1,9502023-07-12