apache
2,899 tracked vulnerabilities.
CVE-2023-42503
MEDIUM
Apache Commons Compress 1.22-1.23.0 - Denial of Service via Malformed TAR File Modification Time Headers
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-41267
HIGH
Apache Airflow HDFS Provider <4.1.1 - Info Disclosure
Sep 14, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-41081
HIGH
Apache Tomcat Connectors - Auth Bypass
Sep 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-40712
MEDIUM
Apache Airflow <2.7.1 - Info Disclosure
Sep 12, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-40611
MEDIUM
Apache Airflow <2.7.1 - Privilege Escalation
Sep 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-39265
LOW
Apache Superset <= 2.1.0 - SQLite Database Connection Manipulation via Alternative Driver Names
Sep 06, 2023
CVSS 3.8
EPSS 0.72
CVE-2023-37941
MEDIUM
Apache Superset 1.5.0-2.1.0 - Remote Code Execution via Metadata Database Deserialization
Sep 06, 2023
CVSS 6.6
EPSS 0.84
CVE-2023-32672
MEDIUM
Apache Superset <= 2.1.0 - Authenticated Incorrect Authorization in SQLLab
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-39264
MEDIUM
Apache Superset <= 2.1.0 - Sensitive Information Exposure via REST API Error Stack Traces
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-36388
MEDIUM
Apache Superset <= 2.1.0 - Authenticated Server-Side Request Forgery via Network Connection Test
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-36387
MEDIUM
Apache Superset <2.1.0 - Info Disclosure
Sep 06, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-27526
MEDIUM
Apache Superset <= 2.1.0 - Authenticated Incorrect Authorization via Import Charts Feature
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-27523
MEDIUM
Apache Superset <= 2.1.0 - Authenticated Improper Data Authorization in Jinja Templated Queries
Sep 06, 2023
CVSS 5.0
EPSS 0.00
CVE-2023-40743
CRITICAL
Apache Axis 1.x - Server-Side Request Forgery and Remote Code Execution via ServiceFactory.getService
Sep 05, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-41180
MEDIUM
Apache NiFi MiNiFi C++ <0.15 - Certificate Validation
Sep 03, 2023
CVSS 5.9
EPSS 0.00
CVE-2023-40195
HIGH
Apache Airflow Spark Provider < 4.1.3 - Authenticated Remote Code Execution via Malicious Spark Server
Aug 28, 2023
CVSS 8.8
EPSS 0.03
CVE-2023-27604
HIGH
Apache Airflow Sqoop Provider < 4.0.0 - Authenticated Remote Code Execution via Sqoop Import Connection Parameters
Aug 28, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-41080
MEDIUM
Apache Tomcat <11.0.0-M10 - Open Redirect
Aug 25, 2023
CVSS 6.1
EPSS 0.12
CVE-2023-40273
HIGH
Apache Airflow < 2.7.0 - Authenticated Session Fixation via Password Reset
Aug 23, 2023
CVSS 8.0
EPSS 0.00
CVE-2023-39441
MEDIUM
Apache Airflow < 2.7.0 - Improper Certificate Validation
Aug 23, 2023
CVSS 5.9
EPSS 0.00
CVE-2023-37379
HIGH
Apache Airflow < 2.7.0 - Authenticated Denial of Service via Connection Test Feature
Aug 23, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-40037
MEDIUM
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
Aug 18, 2023
CVSS 6.5
EPSS 0.01
CVE-2023-40272
HIGH
Apache Airflow Spark Provider < 4.1.3 - Arbitrary File Read via Connection Parameters
Aug 17, 2023
CVSS 7.5
EPSS 0.01
CVE-2023-39553
HIGH
Apache Airflow Drill Provider < 2.4.3 - Unauthenticated Arbitrary File Read via DrillHook Connection Parameters
Aug 11, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-33934
CRITICAL
Apache Traffic Server <9.2.1 - Info Disclosure
Aug 09, 2023
CVSS 9.1
EPSS 0.00
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
nifi 46
solr 46
cloudstack 45
cxf 43
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters