Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Commons Bcel CRITICAL 9.8
CVE-2022-42920

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds wri…

Fix: 6.6.0+
Fix from $2,300 2022-11-07
Ivy CRITICAL 9.1
CVE-2022-37865

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip…

Fix: 2.5.1+
Fix from $2,300 2022-11-07
Flume CRITICAL 9.8
CVE-2022-42468

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…

Fix: after 1.10.1
Fix from $2,300 2022-10-26
Heron CRITICAL 9.8
CVE-2021-42010

Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-…

Fix: 0.20.5-incubating+
Fix from $2,300 2022-10-24
Dubbo CRITICAL 9.8
CVE-2022-39198

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…

Fix: after 3.0.11
Fix from $2,300 2022-10-18
Commons Text CRITICAL 9.8
CVE-2022-42889EPSS 100%

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…

Fix: 1.10.0 / 7.5.0+
Fix from $2,300 2022-10-13
Kylin CRITICAL 9.8
CVE-2022-24697EPSS 85%

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can…

Fix: 2.6.6+
Fix from $2,300 2022-10-13
Shiro CRITICAL 9.8
CVE-2022-40664

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

Fix: 1.10.0+
Fix from $2,300 2022-10-12
Pinot CRITICAL 9.8
CVE-2022-26112

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…

Fix: 0.11.0+
Fix from $2,300 2022-09-23
Calcite CRITICAL 9.8
CVE-2022-39135

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe…

Fix: 1.32.0+
Fix from $2,300 2022-09-11
Ofbiz CRITICAL 9.8
CVE-2022-25371

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Ofbiz CRITICAL 9.8
CVE-2022-29063

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Airflow CRITICAL 9.8
CVE-2022-38054

In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

Fix: after 2.3.3
Fix from $2,300 2022-09-02
Geode CRITICAL 9.8
CVE-2022-37021

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A…

Fix: after 1.13.4
Fix from $2,300 2022-08-31
Flume CRITICAL 9.8
CVE-2022-34916

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI …

Fix: 1.10.1+
Fix from $2,300 2022-08-21
Hadoop CRITICAL 9.8
CVE-2022-25168

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary…

Fix: after 3.3.2
Fix from $2,300 2022-08-04
Cloudstack CRITICAL 9.8
CVE-2022-35741EPSS 8%

Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entit…

Fix: 4.16.1.1+
Fix from $2,300 2022-07-18
Commons Configuration CRITICAL 9.8
CVE-2022-33980EPSS 43%

Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for i…

Fix: 2.8+
Fix from $2,300 2022-07-06
Jetspeed CRITICAL 9.8
CVE-2022-32533

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…

Mitigation only
Fix from $2,300 2022-07-06
Shiro CRITICAL 9.8
CVE-2022-32532EPSS 27%

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…

Fix: 1.9.1+
Fix from $2,300 2022-06-29
Flume CRITICAL 9.8
CVE-2022-25167

Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…

Fix: 1.10.0+
Fix from $2,300 2022-06-14
Hadoop CRITICAL 9.8
CVE-2021-37404

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in…

Fix: 2.10.2 / 3.2.3+
Fix from $2,300 2022-06-13
HTTP Server CRITICAL 9.8
CVE-2022-31813

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop m…

Fix: 2.4.54+
Fix from $2,300 2022-06-09
HTTP Server CRITICAL 9.1
CVE-2022-28615EPSS 6%

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extrem…

Fix: 2.4.54+
Fix from $2,300 2022-06-09
Maven Shared Utils CRITICAL 9.8
CVE-2022-29599

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing she…

Fix: 3.3.3+
Fix from $2,300 2022-05-23
Jena CRITICAL 9.8
CVE-2022-28890

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…

Mitigation only
Fix from $2,300 2022-05-05
Couchdb CRITICAL 9.8
CVE-2022-24706 KEVEPSS 92%

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.…

Fix: 3.2.2+
Fix from $2,300 2022-04-26
Superset CRITICAL 9.8
CVE-2022-27479

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

Fix: 1.4.2+
Fix from $2,300 2022-04-13
Struts CRITICAL 9.8
CVE-2021-31805EPSS 85%

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double ev…

Fix: after 2.5.29
Fix from $2,300 2022-04-12
Hadoop CRITICAL 9.8
CVE-2022-26612

In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR …

Fix: 3.2.3+
Fix from $2,300 2022-04-07