Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-31103 Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1… Inlong after 1.6.0 Fix from $1,9502023-05-22 MEDIUM 6.5 CVE-2023-31101 Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 th… Inlong Mitigation only Fix from $1,6002023-05-22 CRITICAL 9.8 CVE-2023-31062 Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.… Inlong after 1.6.0 Fix from $2,3002023-05-22 HIGH 7.5 CVE-2023-31064 Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from … Inlong after 1.6.0 Fix from $1,9502023-05-22 HIGH 7.5 CVE-2023-31206 Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1… Inlong after 1.6.0 Fix from $1,9502023-05-22 HIGH 7.5 CVE-2023-31453 Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro… Inlong after 1.6.0 Fix from $1,9502023-05-22 HIGH 7.5 CVE-2023-31454 Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro… Inlong after 1.6.0 Fix from $1,9502023-05-22 HIGH 7.5 CVE-2023-31058 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.… Inlong after 1.6.0 Fix from $1,9502023-05-22 HIGH 7.5 CVE-2023-28709EPSS 50% The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-d… Tomcat after 10.1.7 Fix from $1,9502023-05-22 CRITICAL 9.8 CVE-2022-47937 Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted inpu… Sling Commons Json after 2.0.20 Fix from $2,3002023-05-15 HIGH 8.1 CVE-2023-29032 An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Version… Openmeetings 7.1.0+ Fix from $1,9502023-05-12 HIGH 7.2 CVE-2023-29246 An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affec… Openmeetings 7.1.0+ Fix from $1,9502023-05-12 MEDIUM 5.3 CVE-2023-28936 Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 Openmeetings 7.1.0+ Fix from $1,6002023-05-12 CRITICAL 9.8 CVE-2023-25754 Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0. Airflow 2.6.0+ Fix from $2,3002023-05-08 MEDIUM 5.4 CVE-2023-29247 Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. Airflow 2.6.0+ Fix from $1,6002023-05-08 CRITICAL 9.8 CVE-2023-31039 Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker tha… Brpc 1.5.0+ Fix from $2,3002023-05-08 HIGH 8.8 CVE-2023-31038 SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the database were properly escaped for S… Log4cxx 1.1.0+ Fix from $1,9502023-05-08 HIGH 8.8 CVE-2022-45048 Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe… Ranger Mitigation only Fix from $1,9502023-05-05 HIGH 8.1 CVE-2021-40331 An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on … Ranger after 2.3.0 Fix from $1,9502023-05-05 MEDIUM 5.3 CVE-2023-26268 Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design d… Couchdb 3.2.3 / 3.3.2+ Fix from $1,6002023-05-02 HIGH 8.8 CVE-2023-32007EPSS 76% ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut… Spark after 3.2.1 Fix from $1,9502023-05-02 CRITICAL 9.1 CVE-2022-46365 Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a … Streampark 2.0.0+ Fix from $2,3002023-05-01 CRITICAL 9.8 CVE-2022-45802 Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload… Streampark 2.0.0+ Fix from $2,3002023-05-01 MEDIUM 5.4 CVE-2022-45801 Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that constru… Streampark 2.0.0+ Fix from $1,6002023-05-01 MEDIUM 5.4 CVE-2023-22665 There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to ex… Jena after 4.8.0 Fix from $1,6002023-04-25 MEDIUM 6.5 CVE-2023-30776 An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue… Superset after 2.0.1 Fix from $1,6002023-04-24 CRITICAL 9.8 CVE-2023-27524 KEVEPSS 97% Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K… Superset after 2.0.1 Fix from $2,3002023-04-24 MEDIUM 6.5 CVE-2023-25504 A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu… Superset after 2.0.1 Fix from $1,6002023-04-17 CRITICAL 9.9 CVE-2023-22946 In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c… Spark 3.4.0+ Fix from $2,3002023-04-17 CRITICAL 9.8 CVE-2023-30771 Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd… Iotdb Web Workbench Mitigation only Fix from $2,3002023-04-17