Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2023-30428 Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP… Pulsar 2.10.4+ Fix from $1,9502023-07-12 MEDIUM 6.5 CVE-2022-46651 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Co… Airflow 2.6.3+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-22887 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intende… Airflow 2.6.3+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-22888 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_i… Airflow 2.6.3+ Fix from $1,6002023-07-12 HIGH 8.8 CVE-2023-32200 There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascr… Jena after 4.8.0 Fix from $1,9502023-07-12 MEDIUM 5.3 CVE-2023-33008 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input tha… Johnzon 1.2.21+ Fix from $1,6002023-07-07 MEDIUM 5.3 CVE-2023-34150 ** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage. Any23 after 2.7 Fix from $1,6002023-07-05 CRITICAL 9.8 CVE-2023-35797 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Pro… Apache Airflow Providers Apache Hive 6.1.1+ Fix from $2,3002023-07-03 HIGH 8.8 CVE-2023-22886 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection UR… Apache Airflow Providers Jdbc 4.0.0+ Fix from $1,9502023-06-29 HIGH 7.8 CVE-2023-34395 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Pr… Apache Airflow Providers Odbc 4.0.0+ Fix from $1,9502023-06-27 HIGH 8.8 CVE-2023-31469 A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi… Streampipes after 0.91.0 Fix from $1,9502023-06-23 HIGH 7.5 CVE-2023-34981 A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header… Tomcat Mitigation only Fix from $1,9502023-06-21 CRITICAL 9.8 CVE-2023-34340 Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta… Accumulo Mitigation only Fix from $2,3002023-06-21 MEDIUM 6.5 CVE-2023-35005 In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact… Airflow 2.6.2+ Fix from $1,6002023-06-19 HIGH 7.5 CVE-2023-30631 Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_… Traffic Server 8.1.7 / 9.2.1+ Fix from $1,9502023-06-14 HIGH 7.5 CVE-2023-33933 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach… Traffic Server 8.1.7 / 9.2.1+ Fix from $1,9502023-06-14 HIGH 7.5 CVE-2023-34396EPSS 6% Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro… Struts 2.5.31 / 6.1.2.1+ Fix from $1,9502023-06-14 MEDIUM 6.5 CVE-2023-34149EPSS 5% Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro… Struts 2.5.31 / 6.1.2.1+ Fix from $1,6002023-06-14 HIGH 7.5 CVE-2022-47184 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach… Traffic Server 8.1.7 / 9.2.1+ Fix from $1,9502023-06-14 HIGH 8.8 CVE-2023-34468EPSS 64% The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user … Nifi 1.22.0+ Fix from $1,9502023-06-12 MEDIUM 6.5 CVE-2023-34212 The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all… Nifi after 1.21.0 Fix from $1,6002023-06-12 HIGH 8.1 CVE-2023-30576 Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to ex… Guacamole 1.5.2+ Fix from $1,9502023-06-07 HIGH 7.5 CVE-2023-30575 Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentia… Guacamole 1.5.2+ Fix from $1,9502023-06-07 HIGH 7.2 CVE-2023-33234 Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow … Apache Airflow Providers Cncf Kubernetes 7.0.0+ Fix from $1,9502023-05-30 HIGH 7.8 CVE-2023-30601 Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This iss… Cassandra 4.0.10 / 4.1.2+ Fix from $1,9502023-05-30 MEDIUM 6.1 CVE-2022-46907 A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execut… Jspwiki 2.12.0+ Fix from $1,6002023-05-25 CRITICAL 9.8 CVE-2023-33246 KEVEPSS 97% For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu… Rocketmq 4.9.6 / 5.1.1+ Fix from $2,3002023-05-24 CRITICAL 9.8 CVE-2023-31098 Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  Wh… Inlong after 1.6.0 Fix from $2,3002023-05-22 CRITICAL 9.1 CVE-2023-31065 Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.… Inlong after 1.6.0 Fix from $2,3002023-05-22 CRITICAL 9.1 CVE-2023-31066 Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from … Inlong after 1.6.0 Fix from $2,3002023-05-22