Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-24831 Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu… Iotdb after 0.13.3 Fix from $2,3002023-04-17 HIGH 7.5 CVE-2022-47501EPSS 10% Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. Thi… Ofbiz 18.12.07+ Fix from $1,9502023-04-14 CRITICAL 9.0 CVE-2022-45064 The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting is… Apache Sling Engine 2.14.0+ Fix from $2,3002023-04-13 MEDIUM 5.3 CVE-2023-30465 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i… Inlong Mitigation only Fix from $1,6002023-04-11 CRITICAL 9.8 CVE-2023-27603 In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-29215 In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-29216 In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.1 CVE-2023-27987 In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the de… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-27602 In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-28706 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects… Airflow Hive Provider 6.0.0+ Fix from $2,3002023-04-07 HIGH 7.5 CVE-2023-28707 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider:… Apache Airflow Providers Apache Drill 2.3.2+ Fix from $1,9502023-04-07 HIGH 7.5 CVE-2023-28710 Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider:… Apache Airflow Providers Apache Spark 4.0.1+ Fix from $1,9502023-04-07 HIGH 7.8 CVE-2023-26269 Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation b… James 3.7.4+ Fix from $1,9502023-04-03 HIGH 8.8 CVE-2023-28935 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software … Unstructured Information Management Architecture Mitigation only Fix from $1,9502023-03-30 MEDIUM 5.4 CVE-2023-28158 Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users… Archiva 2.2.10+ Fix from $1,6002023-03-29 CRITICAL 9.8 CVE-2023-28326 Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privi… Openmeetings 7.0.0+ Fix from $2,3002023-03-28 HIGH 8.1 CVE-2023-25195 Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain ac… Fineract after 1.8.3 Fix from $1,9502023-03-28 MEDIUM 6.3 CVE-2023-25197 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Aut… Fineract after 1.8.2 Fix from $1,6002023-03-28 HIGH 8.8 CVE-2023-27296 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong,… Inlong after 1.5.0 Fix from $1,9502023-03-27 HIGH 7.8 CVE-2022-38745 Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro… Openoffice 4.1.14+ Fix from $1,9502023-03-24 HIGH 7.8 CVE-2022-47502 Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. … Openoffice after 4.1.13 Fix from $1,9502023-03-24 HIGH 7.5 CVE-2023-26513 Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.… Sling Resource Merger 1.4.2+ Fix from $1,9502023-03-20 MEDIUM 5.3 CVE-2023-25695 Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Air… Airflow 2.5.2+ Fix from $1,6002023-03-15 HIGH 7.5 CVE-2023-26464 ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t… Log4j 2.0+ Fix from $1,9502023-03-10 CRITICAL 9.8 CVE-2023-23638 A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.… Dubbo after 3.1.5 Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-25690EPSS 85% Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affec… HTTP Server after 2.4.55 Fix from $2,3002023-03-07 HIGH 7.5 CVE-2023-27522 HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. … HTTP Server 2.0.22 / 2.4.56+ Fix from $1,9502023-03-07 CRITICAL 9.8 CVE-2023-25691 Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1… Apache Airflow Providers Google 8.10.0+ Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-25693 Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. Apache Airflow Providers Apache Sqoop 3.1.1+ Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-25696 Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. Apache Airflow Providers Apache Hive 5.1.3+ Fix from $2,3002023-02-24