Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-25692 Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1… Apache Airflow Providers Google 8.10.0+ Fix from $1,9502023-02-24 HIGH 7.5 CVE-2023-25956 Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS… Apache Airflow Providers Amazon 7.2.1+ Fix from $1,9502023-02-24 MEDIUM 6.5 CVE-2023-25621 Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the reposito… Sling I18n 2.6.2+ Fix from $1,6002023-02-23 CRITICAL 9.8 CVE-2023-25613 An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.  Kerby Ldap Backend 2.0.3+ Fix from $2,3002023-02-20 HIGH 7.5 CVE-2023-24998EPSS 47% Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin… Commons Fileupload 1.5+ Fix from $1,9502023-02-20 HIGH 8.8 CVE-2022-42735 Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators… Shenyu Mitigation only Fix from $1,9502023-02-15 HIGH 7.5 CVE-2023-25141 Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct… Sling Jcr Base 3.1.12+ Fix from $1,9502023-02-14 HIGH 7.5 CVE-2023-22832 The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that i… Nifi after 1.19.1 Fix from $1,9502023-02-10 HIGH 8.8 CVE-2023-25194EPSS 96% A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to… Kafka Connect after 3.3.2 Fix from $1,9502023-02-07 HIGH 8.1 CVE-2022-45786 There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for Postgre… Age after 1.1.0 Fix from $1,9502023-02-04 MEDIUM 6.1 CVE-2023-22849 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and pri… Sling Cms 1.1.6+ Fix from $1,6002023-02-04 CRITICAL 9.8 CVE-2023-24997 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.… Inlong after 1.5.0 Fix from $2,3002023-02-01 HIGH 7.5 CVE-2023-24977 Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are ad… Inlong after 1.5.0 Fix from $1,9502023-02-01 CRITICAL 9.8 CVE-2022-24963 Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a … Portable Runtime Mitigation only Fix from $2,3002023-01-31 CRITICAL 9.8 CVE-2022-28331 On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int… Portable Runtime after 1.7.0 Fix from $2,3002023-01-31 MEDIUM 6.5 CVE-2022-25147 Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond… Portable Runtime Utility after 1.6.1 Fix from $1,6002023-01-31 HIGH 8.8 CVE-2022-44645 In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when… Linkis after 1.3.0 Fix from $1,9502023-01-31 HIGH 8.8 CVE-2023-24829 Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 bef… Iotdb 0.13.3+ Fix from $1,9502023-01-31 MEDIUM 6.5 CVE-2022-44644 In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files b… Linkis after 1.3.0 Fix from $1,6002023-01-31 HIGH 7.5 CVE-2023-24830 Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before… Iotdb 0.13.3+ Fix from $1,9502023-01-30 CRITICAL 9.8 CVE-2023-22884EPSS 11% Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach… Airflow 2.5.1 / 4.0.0+ Fix from $2,3002023-01-21 CRITICAL 9.0 CVE-2022-36760 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to sm… HTTP Server 2.4.55+ Fix from $2,3002023-01-17 HIGH 7.5 CVE-2006-20001 A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header va… HTTP Server 2.4.55+ Fix from $1,9502023-01-17 MEDIUM 5.3 CVE-2022-37436EPSS 58% Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorpo… HTTP Server 2.4.55+ Fix from $1,6002023-01-17 HIGH 8.8 CVE-2022-43719 Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio… Superset after 1.5.2 Fix from $1,9502023-01-16 MEDIUM 5.4 CVE-2022-41703 A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subquerie… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 5.4 CVE-2022-43717 Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 5.4 CVE-2022-43718 Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with databas… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 5.4 CVE-2022-43720 An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the t… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 5.4 CVE-2022-43721 An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh… Superset after 1.5.2 Fix from $1,6002023-01-16