Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2022-41131 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airf… Airflow 2.3.0 / 4.1.0+ Fix from $1,9502022-11-22 MEDIUM 5.5 CVE-2022-40954 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Air… Airflow 2.3.0 / 4.0.0+ Fix from $1,6002022-11-22 CRITICAL 9.8 CVE-2022-38649 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air… Airflow 2.3.0 / 4.0.0+ Fix from $2,3002022-11-22 HIGH 7.5 CVE-2022-45470 missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect t… Hama after 1.7.1 Fix from $1,9502022-11-21 CRITICAL 9.8 CVE-2022-45047 Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j… Sshd after 2.9.1 Fix from $2,3002022-11-16 HIGH 7.5 CVE-2022-40308 If anonymous read enabled, it's possible to read the database file directly without logging in. Archiva 2.2.9+ Fix from $1,9502022-11-15 MEDIUM 6.1 CVE-2022-45402EPSS 82% In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. Airflow 2.4.3+ Fix from $1,6002022-11-15 CRITICAL 9.8 CVE-2022-45136 Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u… Jena Sdb after 3.17.0 Fix from $2,3002022-11-14 CRITICAL 9.8 CVE-2022-45378 In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invok… Soap after 2.3 Fix from $2,3002022-11-14 HIGH 8.8 CVE-2022-40127EPSS 86% A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually … Airflow 2.4.0+ Fix from $1,9502022-11-14 HIGH 7.5 CVE-2022-27949 A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (fo… Airflow 2.3.1+ Fix from $1,9502022-11-14 HIGH 7.5 CVE-2022-37866 When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include pla… Ivy 2.5.1+ Fix from $1,9502022-11-07 CRITICAL 9.8 CVE-2022-42920 Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds wri… Commons Bcel 6.6.0+ Fix from $2,3002022-11-07 CRITICAL 9.1 CVE-2022-37865 With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip… Ivy 2.5.1+ Fix from $2,3002022-11-07 HIGH 8.1 CVE-2022-33684 The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllo… Pulsar 2.7.5 / 2.8.4+ Fix from $1,9502022-11-04 HIGH 7.5 CVE-2022-32287 A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files o… Uimaj after 3.3.0 Fix from $1,9502022-11-03 MEDIUM 5.4 CVE-2022-43670 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and pri… Sling Cms after 1.1.0 Fix from $1,6002022-11-02 MEDIUM 6.1 CVE-2022-43982 In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. Airflow 2.4.2+ Fix from $1,6002022-11-02 MEDIUM 6.1 CVE-2022-43985 In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint. Airflow 2.4.2+ Fix from $1,6002022-11-02 MEDIUM 6.5 CVE-2022-34662 When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade… Dolphinscheduler 3.0.0+ Fix from $1,6002022-11-01 MEDIUM 5.4 CVE-2022-31777 A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScri… Spark 3.2.2+ Fix from $1,6002022-11-01 HIGH 7.5 CVE-2022-42252 If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via s… Tomcat 8.5.83 / 9.0.68+ Fix from $1,9502022-11-01 MEDIUM 6.5 CVE-2022-26884 Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher. Dolphinscheduler 2.0.6+ Fix from $1,6002022-10-28 CRITICAL 9.8 CVE-2022-42468 Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa… Flume after 1.10.1 Fix from $2,3002022-10-26 HIGH 8.8 CVE-2022-39944 In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when… Linkis after 1.2.0 Fix from $1,9502022-10-26 HIGH 7.5 CVE-2022-43766 Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP que… Iotdb after 0.13.2 Fix from $1,9502022-10-26 HIGH 7.5 CVE-2022-41704 A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri… Batik 1.16+ Fix from $1,9502022-10-25 HIGH 7.5 CVE-2022-42890 A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML … Batik 1.16+ Fix from $1,9502022-10-25 MEDIUM 5.4 CVE-2022-34870 Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region … Geode after 1.15.0 Fix from $1,6002022-10-25 CRITICAL 9.8 CVE-2021-42010 Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-… Heron 0.20.5-incubating+ Fix from $2,3002022-10-24