1
Total CVEs
0
Critical
0
High
1
Medium
0
Low

Recent CVEs

Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metad...

Affected versions: 2.0.0 2.1.0 2.1.1 2.2.0 2.2.1 +1 more

Published: Apr 13, 2026

5.4

CVSS

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deseri...

Affected versions: 2.0.0 2.1.0 2.1.1 2.2.0 2.2.1 +1 more

Published: Apr 13, 2026

8.8

CVSS

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files of...

Affected versions: 0.9.1 0.9.2

Published: Jul 26, 2019

5.0

CVSS

In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code a...

Affected versions: 0.10.1 0.10.2 1.0 1.0.0 1.0.1 +9 more

Published: Jul 10, 2018

6.5

CVSS

Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log....

Affected versions: 0.9.0.1

Published: Oct 30, 2017

7.8

CVSS

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to ...

Affected versions: 1.0 1.0.1 1.0.2 1.0.3 1.1

Published: Aug 9, 2017

4.3

CVSS

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors....

Affected versions: 0.10.0

Published: Jan 13, 2017

10.0

CVSS

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web...

Affected versions: 5.x-1.1 5.x-1.10 5.x-1.11 5.x-1.12 5.x-1.13 +44 more

Published: Jun 7, 2010

2.1

CVSS

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web...

Affected versions: 5.x-1.1 5.x-1.10 5.x-1.11 5.x-1.12 5.x-1.13 +44 more

Published: Jun 1, 2010

2.1

CVSS

The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors....

Affected versions: 6.x-1.0 6.x-1.1 6.x-1.10 6.x-1.11 6.x-1.12 +21 more

Published: Dec 31, 2009

5.0

CVSS

Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist...

Affected versions: 3.9.62

Published: Jul 27, 2009

9.3

CVSS

Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild i...

Affected versions: 2.7.9_10 2.7.9_8 2.8 2.9

Published: May 28, 2009

9.3

CVSS

Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDown...

Affected versions: 2.7.9_10 2.7.9_8 2.8 2.9 3.9.3_25 +3 more

Published: May 11, 2009

9.3

CVSS

SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm projec...

Affected versions: 5.x-1.1 5.x-1.10 5.x-1.11 5.x-1.12 5.x-1.13 +28 more

Published: Mar 2, 2009

6.0

CVSS