Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-42466 Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be render… Isis 2.0.0+ Fix from $1,6002022-10-19 MEDIUM 5.3 CVE-2022-42467 When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to dir… Isis 2.0.0+ Fix from $1,6002022-10-19 CRITICAL 9.8 CVE-2022-39198 A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss… Dubbo after 3.0.11 Fix from $2,3002022-10-18 CRITICAL 9.8 CVE-2022-42889EPSS 100% Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat… Commons Text 1.10.0 / 7.5.0+ Fix from $2,3002022-10-13 CRITICAL 9.8 CVE-2022-24697EPSS 85% Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can… Kylin 2.6.6+ Fix from $2,3002022-10-13 CRITICAL 9.8 CVE-2022-40664 Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. Shiro 1.10.0+ Fix from $2,3002022-10-12 HIGH 8.1 CVE-2022-41672 In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the U… Airflow after 2.4.1 Fix from $1,9502022-10-07 MEDIUM 6.5 CVE-2022-40160 ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to… Commons Jxpath after 1.3 Fix from $1,6002022-10-06 MEDIUM 6.5 CVE-2022-40159 ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to… Commons Jxpath after 1.3 Fix from $1,6002022-10-06 MEDIUM 6.5 CVE-2022-24280 Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from… Pulsar 2.7.5 / 2.8.3+ Fix from $1,6002022-09-23 MEDIUM 5.9 CVE-2022-33681 Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connectio… Pulsar 2.7.5 / 2.8.4+ Fix from $1,6002022-09-23 MEDIUM 5.9 CVE-2022-33682 TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's J… Pulsar 2.7.5 / 2.8.4+ Fix from $1,6002022-09-23 MEDIUM 5.9 CVE-2022-33683 Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnec… Pulsar 2.7.5 / 2.8.4+ Fix from $1,6002022-09-23 CRITICAL 9.8 CVE-2022-26112 In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to… Pinot 0.11.0+ Fix from $2,3002022-09-23 HIGH 7.5 CVE-2022-40146EPSS 6% Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec… Batik Mitigation only Fix from $1,9502022-09-22 MEDIUM 5.3 CVE-2022-38398 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a… Batik Mitigation only Fix from $1,6002022-09-22 MEDIUM 5.3 CVE-2022-38648 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A… Batik Mitigation only Fix from $1,6002022-09-22 HIGH 7.5 CVE-2022-40705 An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files … Soap Mitigation only Fix from $1,9502022-09-22 HIGH 7.5 CVE-2022-40604 In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction. Airflow after 2.3.4 Fix from $1,9502022-09-21 MEDIUM 6.1 CVE-2022-40754 In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint. Airflow after 2.3.4 Fix from $1,6002022-09-21 HIGH 8.8 CVE-2022-40955 In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi… Inlong 1.3.0+ Fix from $1,9502022-09-20 HIGH 7.5 CVE-2022-34917 A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated… Kafka 2.8.2 / 3.0.2+ Fix from $1,9502022-09-20 CRITICAL 9.8 CVE-2022-39135 Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe… Calcite 1.32.0+ Fix from $2,3002022-09-11 HIGH 7.5 CVE-2022-28220 Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, … James after 3.6.2 Fix from $1,9502022-09-08 HIGH 8.8 CVE-2022-38369 Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue. Iotdb No fix yet Fix from $1,9502022-09-05 HIGH 7.5 CVE-2022-38370 Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users… Iotdb Mitigation only Fix from $1,9502022-09-05 CRITICAL 9.8 CVE-2022-25371 Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in… Ofbiz 18.12.06+ Fix from $2,3002022-09-02 CRITICAL 9.8 CVE-2022-29063 The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier… Ofbiz 18.12.06+ Fix from $2,3002022-09-02 CRITICAL 9.8 CVE-2022-38054 In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. Airflow after 2.3.3 Fix from $2,3002022-09-02 HIGH 7.5 CVE-2022-25813EPSS 67% In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a … Ofbiz 18.12.06+ Fix from $1,9502022-09-02