Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-24112 KEVEPSS 96% An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX … Apisix 2.10.4 / 2.12.1+ Fix from $2,3002022-02-11 HIGH 8.8 CVE-2022-24289 Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur… Cayenne 4.2+ Fix from $1,9502022-02-11 CRITICAL 9.1 CVE-2021-44521EPSS 55% When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab… Cassandra 3.0.26 / 3.11.12+ Fix from $2,3002022-02-11 HIGH 7.5 CVE-2022-23206 In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted… Traffic Control 5.1.6 / 6.1.0+ Fix from $1,9502022-02-06 HIGH 7.5 CVE-2022-23913 In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumptio… Artemis 2.19.1+ Fix from $1,9502022-02-04 CRITICAL 9.8 CVE-2021-36152 Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to ver… Gobblin after 0.15.0 Fix from $2,3002022-02-04 MEDIUM 5.5 CVE-2021-36151 In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.… Gobblin after 0.15.0 Fix from $1,6002022-02-04 MEDIUM 6.5 CVE-2021-44451EPSS 8% Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could b… Superset after 1.3.2 Fix from $1,6002022-02-01 MEDIUM 6.5 CVE-2021-41571 In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API… Pulsar 2.6.4 / 2.7.3+ Fix from $1,6002022-02-01 HIGH 7.0 CVE-2022-23181 The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, … Tomcat after 10.0.14 Fix from $1,9502022-01-27 MEDIUM 5.3 CVE-2022-22932 Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk… Karaf 4.2.15 / 4.3.6+ Fix from $1,6002022-01-26 HIGH 8.1 CVE-2021-41766 Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology… Karaf 4.3.6+ Fix from $1,9502022-01-26 CRITICAL 9.1 CVE-2022-23944EPSS 79% User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Patch available Fix from $2,3002022-01-25 HIGH 7.5 CVE-2022-23223 On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to versio… Shenyu Patch available Fix from $1,9502022-01-25 HIGH 7.5 CVE-2022-23945 Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Patch available Fix from $1,9502022-01-25 CRITICAL 9.8 CVE-2021-45029EPSS 6% Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Mitigation only Fix from $2,3002022-01-25 MEDIUM 6.5 CVE-2022-23437 There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the Xe… Xerces J 9.0+ Fix from $1,6002022-01-24 MEDIUM 6.5 CVE-2022-22733EPSS 38% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco… Shardingsphere Elasticjob Ui Mitigation only Fix from $1,6002022-01-20 MEDIUM 6.5 CVE-2021-45230 In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs f… Airflow 2.2.0+ Fix from $1,6002022-01-20 CRITICAL 9.8 CVE-2022-23305EPSS 67% By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from … Log4j 1.2.18.2+ Fix from $2,3002022-01-18 HIGH 8.8 CVE-2022-23302EPSS 64% JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration… Log4j 1.2.18.1+ Fix from $1,9502022-01-18 HIGH 8.8 CVE-2022-23307EPSS 54% CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j… Chainsaw 1.2.18.1 / 2.0+ Fix from $1,9502022-01-18 MEDIUM 6.1 CVE-2021-42357 When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request t… Knox 1.6.1+ Fix from $1,6002022-01-17 HIGH 8.8 CVE-2021-43999 Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo… Guacamole Mitigation only Fix from $1,9502022-01-11 MEDIUM 6.5 CVE-2021-41767 Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allo… Guacamole after 1.3.0 Fix from $1,6002022-01-11 CRITICAL 9.8 CVE-2021-43297EPSS 17% A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub… Dubbo 2.6.12 / 2.7.15+ Fix from $2,3002022-01-10 HIGH 7.5 CVE-2021-43045 A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. Th… Avro 1.11.0+ Fix from $1,9502022-01-06 CRITICAL 9.8 CVE-2021-31522 Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach… Kylin 3.1.3+ Fix from $2,3002022-01-06 CRITICAL 9.8 CVE-2021-45456EPSS 89% Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet… Kylin Mitigation only Fix from $2,3002022-01-06 HIGH 7.5 CVE-2021-45457 In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and p… Kylin 3.1.3+ Fix from $1,9502022-01-06