Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2021-39232 In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins. Ozone 1.2.0+ Fix from $1,9502021-11-19 HIGH 8.8 CVE-2021-39236 In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. Ozone 1.2.0+ Fix from $1,9502021-11-19 MEDIUM 6.8 CVE-2021-39234 In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo… Ozone 1.2.0+ Fix from $1,6002021-11-19 MEDIUM 6.5 CVE-2021-39235 In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block to… Ozone 1.2.0+ Fix from $1,6002021-11-19 MEDIUM 5.3 CVE-2021-41532 In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access… Ozone 1.2.0+ Fix from $1,6002021-11-19 CRITICAL 9.8 CVE-2021-36372 In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authentica… Ozone 1.2.0+ Fix from $2,3002021-11-19 MEDIUM 6.5 CVE-2021-42250 Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject ma… Superset 1.3.2+ Fix from $1,6002021-11-17 CRITICAL 9.8 CVE-2021-37580EPSS 40% A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff… Shenyu Mitigation only Fix from $2,3002021-11-16 MEDIUM 6.5 CVE-2021-41972 Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed … Superset after 1.3.1 Fix from $1,6002021-11-12 CRITICAL 9.8 CVE-2021-43350 An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP… Traffic Control 5.1.4 / 6.0.1+ Fix from $2,3002021-11-11 HIGH 7.5 CVE-2021-26558 Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa… Shardingsphere Ui 5.0.0+ Fix from $1,9502021-11-11 CRITICAL 9.8 CVE-2021-43082 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an… Traffic Server after 9.1.0 Fix from $2,3002021-11-03 HIGH 8.1 CVE-2021-38161 Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Ap… Traffic Server after 8.0.8 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-37148 Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache … Traffic Server after 9.0.1 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-37149 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache … Traffic Server after 9.1.0 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-41585 Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting… Traffic Server after 9.1.0 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-37147 Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache … Traffic Server after 9.1.0 Fix from $1,9502021-11-03 HIGH 8.8 CVE-2021-27644 In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so… Dolphinscheduler 1.3.6+ Fix from $1,9502021-11-01 MEDIUM 6.5 CVE-2021-41973 In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the H… Mina 2.0.22 / 2.1.5+ Fix from $1,6002021-11-01 CRITICAL 9.8 CVE-2021-40865EPSS 66% An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 CRITICAL 9.8 CVE-2021-38294EPSS 84% A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 HIGH 8.8 CVE-2021-41971 Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic… Superset after 1.3.0 Fix from $1,9502021-10-18 MEDIUM 5.4 CVE-2021-32609 Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a… Superset after 1.1 Fix from $1,6002021-10-18 HIGH 7.5 CVE-2021-42340EPSS 12% The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memor… Tomcat 8.5.72 / 9.0.54+ Fix from $1,9502021-10-14 HIGH 7.3 CVE-2021-38295 In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB… Couchdb 3.1.2+ Fix from $1,9502021-10-14 HIGH 7.5 CVE-2021-41832 It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are… Openoffice 4.1.11+ Fix from $1,9502021-10-11 HIGH 7.5 CVE-2021-41830 It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice u… Openoffice 4.1.11+ Fix from $1,9502021-10-11 MEDIUM 5.3 CVE-2021-41831 It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users ar… Openoffice 4.1.11+ Fix from $1,6002021-10-11 CRITICAL 9.8 CVE-2021-42013 KEVEPSS 100% It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… HTTP Server 9.2.6.0 / 18.1.0.1.0+ Fix from $2,3002021-10-07 MEDIUM 6.5 CVE-2021-40439 Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia… Openoffice after 4.1.10 Fix from $1,6002021-10-07