VYPR

Vendor CVEs

Apache

All CVEs

3,418 total · sorted by risk
  • CVE-2026-33227MedApr 7, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web…

  • CVE-2026-32642MedMar 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the…

  • CVE-2026-23907MedMar 10, 2026
    risk 0.28cvss 5.3epss 0.01

    This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from …

  • CVE-2026-25604MedMar 9, 2026
    risk 0.28cvss 5.4epss 0.00

    In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access controls by reusing SAML response from…

  • CVE-2025-66200MedDec 5, 2025
    risk 0.28cvss 5.4epss 0.01

    mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through…

  • CVE-2025-59790MedNov 28, 2025
    risk 0.28cvss 5.4epss 0.00

    Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

  • CVE-2025-62728MedNov 26, 2025
    risk 0.28cvss 5.4epss 0.00

    SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized users/applications that are allowed to call directly the Thrift APIs. In most real-world…

  • CVE-2025-64406MedNov 12, 2025
    risk 0.28cvss 4.3epss 0.01

    An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory areas. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version…

  • CVE-2025-58337MedNov 5, 2025
    risk 0.28cvss 5.4epss 0.00

    An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions. Impact: Bypasses read-only mode; attackers with read-only access may…

  • CVE-2025-62402MedOct 30, 2025
    risk 0.28cvss 5.4epss 0.00

    API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.

  • CVE-2025-61795MedOct 27, 2025
    risk 0.28cvss 5.3epss 0.01

    Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage…

  • CVE-2025-55673MedAug 14, 2025
    risk 0.28cvss 4.3epss 0.01

    When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the…

  • CVE-2024-52279MedAug 3, 2025
    risk 0.28cvss 5.3epss 0.01

    Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes…

  • CVE-2025-48924MedJul 11, 2025
    risk 0.28cvss 5.3epss 0.02

    Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can…

  • CVE-2025-22829MedJun 10, 2025
    risk 0.28cvss 4.3epss 0.01

    The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable reception of…

  • CVE-2025-31672MedApr 9, 2025
    risk 0.28cvss 5.3epss 0.01

    Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in…

  • CVE-2025-27888MedMar 20, 2025
    risk 0.28cvss 5.4epss 0.02

    Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous…

  • CVE-2024-54016MedMar 20, 2025
    risk 0.28cvss 4.3epss 0.01

    Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through <=2.2.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

  • CVE-2025-22828MedJan 13, 2025
    risk 0.28cvss 4.3epss 0.02

    CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add…

  • CVE-2024-56512MedDec 28, 2024
    risk 0.28cvss 5.4epss 0.03

    Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter…

  • CVE-2024-56128MedDec 18, 2024
    risk 0.28cvss 5.3epss 0.01

    Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of RFC 5802 [1]. Specifically, as…

  • CVE-2024-54677MedDec 17, 2024
    risk 0.28cvss 5.3epss 0.02

    Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following…

  • CVE-2024-53948MedDec 9, 2024
    risk 0.28cvss 5.3epss 0.01

    Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.

  • CVE-2024-40761MedSep 25, 2024
    risk 0.28cvss 5.3epss 0.01

    Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead.…

  • CVE-2024-45384MedSep 17, 2024
    risk 0.28cvss 5.3epss 0.01

    Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid…

  • CVE-2024-41890MedAug 12, 2024
    risk 0.28cvss 5.3epss 0.01

    Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the…

  • CVE-2024-41888MedAug 12, 2024
    risk 0.28cvss 5.3epss 0.01

    Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being…

  • CVE-2024-42222MedAug 7, 2024
    risk 0.28cvss 4.3epss 0.01

    In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details,…

  • CVE-2024-25090MedJul 26, 2024
    risk 0.28cvss 5.4epss 0.01

    Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller…

  • CVE-2024-38503MedJul 22, 2024
    risk 0.28cvss 5.4epss 0.01

    When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are…

  • CVE-2024-39863MedJul 17, 2024
    risk 0.28cvss 5.4epss 0.01

    Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.

  • CVE-2024-32077MedMay 14, 2024
    risk 0.28cvss 5.4epss 0.02

    Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.

  • CVE-2024-28148MedMay 7, 2024
    risk 0.28cvss 4.3epss 0.01

    An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the…

  • CVE-2024-31863MedApr 9, 2024
    risk 0.28cvss 5.3epss 0.01

    Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

  • CVE-2024-31862MedApr 9, 2024
    risk 0.28cvss 5.3epss 0.01

    Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

  • CVE-2022-47894MedApr 9, 2024
    risk 0.28cvss 5.3epss 0.01

    Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict…

  • CVE-2024-29735MedMar 26, 2024
    risk 0.28cvss 5.3epss 0.01

    Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set permissions for all parent folders of log folder, in default configuration adding write…

  • CVE-2024-29133MedMar 21, 2024
    risk 0.28cvss 5.4epss 0.02

    Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

  • CVE-2023-50740MedMar 6, 2024
    risk 0.28cvss 5.3epss 0.01

    In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users upgrade the version of Linkis to version 1.5.0

  • CVE-2024-26016MedFeb 28, 2024
    risk 0.28cvss 4.3epss 0.01

    A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these charts and dashboards…

  • CVE-2024-24772MedFeb 28, 2024
    risk 0.28cvss 4.3epss 0.01

    A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version…

  • CVE-2024-27315MedFeb 28, 2024
    risk 0.28cvss 4.3epss 0.01

    An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surface in the error…

  • CVE-2024-21742MedFeb 27, 2024
    risk 0.28cvss 5.3epss 0.01

    Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.

  • CVE-2023-47265MedDec 21, 2023
    risk 0.28cvss 5.4epss 0.01

    Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks…

  • CVE-2023-42505MedNov 28, 2023
    risk 0.28cvss 4.3epss 0.01

    An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.

  • CVE-2023-43701MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue…

  • CVE-2023-42501MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma…

  • CVE-2023-45648MedOct 10, 2023
    risk 0.28cvss 5.3epss 0.06

    Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer…

  • CVE-2023-42795MedOct 10, 2023
    risk 0.28cvss 5.3epss 0.02

    Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some…

  • CVE-2023-32672MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.01

    An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL…

Page 49 of 69