Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Apisix CRITICAL 9.8
CVE-2022-25757

In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…

Fix: 2.13.0+
Fix from $2,300 2022-03-28
HTTP Server CRITICAL 9.8
CVE-2022-22720EPSS 28%

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server …

Fix: 10.15.7 / 11.6.6+
Fix from $2,300 2022-03-14
HTTP Server CRITICAL 9.8
CVE-2022-23943EPSS 50%

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. …

Fix: 2.4.53+
Fix from $2,300 2022-03-14
HTTP Server CRITICAL 9.1
CVE-2022-22721EPSS 42%

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later ca…

Fix: 10.15.7 / 11.6.6+
Fix from $2,300 2022-03-14
Any23 CRITICAL 9.1
CVE-2022-25312

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions …

Fix: 2.7+
Fix from $2,300 2022-03-05
Apisix CRITICAL 9.8
CVE-2022-24112 KEVEPSS 96%

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX …

Fix: 2.10.4 / 2.12.1+
Fix from $2,300 2022-02-11
Cassandra CRITICAL 9.1
CVE-2021-44521EPSS 55%

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…

Fix: 3.0.26 / 3.11.12+
Fix from $2,300 2022-02-11
Gobblin CRITICAL 9.8
CVE-2021-36152

Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to ver…

Fix: after 0.15.0
Fix from $2,300 2022-02-04
Shenyu CRITICAL 9.1
CVE-2022-23944EPSS 79%

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $2,300 2022-01-25
Shenyu CRITICAL 9.8
CVE-2021-45029EPSS 6%

Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Mitigation only
Fix from $2,300 2022-01-25
Log4j CRITICAL 9.8
CVE-2022-23305EPSS 67%

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from …

Fix: 1.2.18.2+
Fix from $2,300 2022-01-18
Dubbo CRITICAL 9.8
CVE-2021-43297EPSS 17%

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…

Fix: 2.6.12 / 2.7.15+
Fix from $2,300 2022-01-10
Kylin CRITICAL 9.8
CVE-2021-31522

Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…

Fix: 3.1.3+
Fix from $2,300 2022-01-06
Kylin CRITICAL 9.8
CVE-2021-45456EPSS 89%

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…

Mitigation only
Fix from $2,300 2022-01-06
James CRITICAL 9.1
CVE-2021-40525

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writ…

Fix: 3.6.2+
Fix from $2,300 2022-01-04
Apisix Dashboard CRITICAL 9.8
CVE-2021-45232EPSS 86%

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all…

Fix: 2.10.1+
Fix from $2,300 2021-12-27
Solr CRITICAL 9.8
CVE-2021-44548EPSS 5%

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…

Fix: 8.11.1+
Fix from $2,300 2021-12-23
HTTP Server CRITICAL 9.8
CVE-2021-44790EPSS 97%

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache http…

Fix: 2.4.52 / 5.20.0+
Fix from $2,300 2021-12-20
Log4j CRITICAL 9.0
CVE-2021-45046 KEVEPSS 100%

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at…

Fix: 2.12.2 / 2.16.0+
Fix from $2,300 2021-12-14
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Jspwiki CRITICAL 9.1
CVE-2021-44140EPSS 6%

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…

Fix: 2.11.0+
Fix from $2,300 2021-11-24
Ozone CRITICAL 9.1
CVE-2021-39231

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Ozone CRITICAL 9.1
CVE-2021-39233

In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any …

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Ozone CRITICAL 9.8
CVE-2021-36372

In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authentica…

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Shenyu CRITICAL 9.8
CVE-2021-37580EPSS 40%

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…

Mitigation only
Fix from $2,300 2021-11-16
Traffic Control CRITICAL 9.8
CVE-2021-43350

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…

Fix: 5.1.4 / 6.0.1+
Fix from $2,300 2021-11-11
Traffic Server CRITICAL 9.8
CVE-2021-43082

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an…

Fix: after 9.1.0
Fix from $2,300 2021-11-03
Storm CRITICAL 9.8
CVE-2021-40865EPSS 66%

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Storm CRITICAL 9.8
CVE-2021-38294EPSS 84%

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
HTTP Server CRITICAL 9.8
CVE-2021-42013 KEVEPSS 100%

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs…

Fix: 9.2.6.0 / 18.1.0.1.0+
Fix from $2,300 2021-10-07