4.8

CVSS3.1

CVE-2024-45478 - Apache Ranger: Stored XSS in Edit Service page - Add logic to validate user input

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

📅 Published: Jan. 21, 2025, 9:25 p.m. 🔄 Last Modified: June 10, 2025, 9:15 a.m.

8.8

CVSS3.1

CVE-2024-51941 - Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. A…

📅 Published: Jan. 21, 2025, 9:24 p.m. 🔄 Last Modified: Oct. 2, 2025, 1:40 a.m.

8.8

CVSS3.1

CVE-2025-23196 - Apache Ambari: Code Injection Vulnerability in Ambari Alert Definition

A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed using `sh -c`. An attacker with authentica…

📅 Published: Jan. 21, 2025, 9:23 p.m. 🔄 Last Modified: June 9, 2025, 7:42 p.m.

7.5

CVSS3.1

CVE-2025-23195 - Apache Ambari: XML External Entity (XXE) Vulnerability in Ambari/Oozie

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` class without disabling external entity resolution. An attacker…

📅 Published: Jan. 21, 2025, 9:22 p.m. 🔄 Last Modified: June 9, 2025, 7:36 p.m.

7.3

CVSS3.1

CVE-2025-21571 -

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox e…

📅 Published: Jan. 21, 2025, 8:53 p.m. 🔄 Last Modified: April 29, 2025, 8:02 p.m.

6.1

CVSS3.1

CVE-2025-21570 -

Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login). The supported version that is affected is 8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Scienc…

📅 Published: Jan. 21, 2025, 8:53 p.m. 🔄 Last Modified: April 29, 2025, 8:01 p.m.

6.6

CVSS3.1

CVE-2025-21569 -

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that is affected is 11.2.19.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyp…

📅 Published: Jan. 21, 2025, 8:53 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

4.5

CVSS3.1

CVE-2025-21568 -

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security). The supported version that is affected is 11.2.19.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracl…

📅 Published: Jan. 21, 2025, 8:53 p.m. 🔄 Last Modified: June 23, 2025, 6:01 p.m.

7.5

CVSS3.1

CVE-2025-21565 -

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful…

📅 Published: Jan. 21, 2025, 8:53 p.m. 🔄 Last Modified: April 29, 2025, 8:01 p.m.

4.3

CVSS3.1

CVE-2025-21567 - mysql: Privilege Handling Flaw in MySQL Server

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Suc…

📅 Published: Jan. 21, 2025, 8:53 p.m. 🔄 Last Modified: Nov. 3, 2025, 9:18 p.m.
Total resulsts: 346661
Page 6763 of 34,667
« previous page » next page
Filters