Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HTTP Server CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…

Patch available
Fix from $2,300 2021-10-05
Ddlutils CRITICAL 9.8
CVE-2021-41616

Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…

Mitigation only
Fix from $2,300 2021-09-30
Shiro CRITICAL 9.8
CVE-2021-41303EPSS 77%

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…

Fix: 1.8.0+
Fix from $2,300 2021-09-17
HTTP Server CRITICAL 9.8
CVE-2021-39275EPSS 39%

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but t…

Fix: 2.4.49+
Fix from $2,300 2021-09-16
Any23 CRITICAL 9.8
CVE-2021-40146EPSS 6%

A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vuln…

Fix: 2.5+
Fix from $2,300 2021-09-11
Any23 CRITICAL 9.1
CVE-2021-38555

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…

Fix: 2.5+
Fix from $2,300 2021-09-11
Airflow CRITICAL 9.8
CVE-2021-38540EPSS 81%

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …

Fix: 2.1.3+
Fix from $2,300 2021-09-09
Dubbo CRITICAL 9.8
CVE-2021-37579EPSS 7%

The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…

Fix: 2.7.13 / 3.0.2+
Fix from $2,300 2021-09-09
Dubbo CRITICAL 9.8
CVE-2021-36161

Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean…

Fix: 2.7.13+
Fix from $2,300 2021-09-09
Dubbo CRITICAL 9.8
CVE-2021-36163

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…

Fix: after 3.0.1
Fix from $2,300 2021-09-07
Zeppelin CRITICAL 9.8
CVE-2019-10095EPSS 6%

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe…

Fix: after 0.9.0
Fix from $2,300 2021-09-02
Nifi Minifi C\+\+ CRITICAL 9.8
CVE-2021-33191

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th…

Fix: 0.10.0+
Fix from $2,300 2021-08-24
Ofbiz CRITICAL 9.8
CVE-2021-37608EPSS 6%

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach…

Fix: 17.12.08+
Fix from $2,300 2021-08-18
Juddi CRITICAL 9.8
CVE-2021-37578

Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo…

Fix: 3.3.10+
Fix from $2,300 2021-07-29
Traffic Server CRITICAL 9.8
CVE-2021-35474

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.…

Fix: after 9.0.1
Fix from $2,300 2021-06-30
Nuttx CRITICAL 9.8
CVE-2021-26461EPSS 5%

Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignmen…

Fix: 10.1.0+
Fix from $2,300 2021-06-21
Chainsaw CRITICAL 9.8
CVE-2020-9493

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

Fix: 1.2.18.1 / 2.0+
Fix from $2,300 2021-06-16
HTTP Server CRITICAL 9.8
CVE-2021-26691EPSS 68%

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Fix: 18.1.0.1.0+
Fix from $2,300 2021-06-10
Dubbo CRITICAL 9.8
CVE-2021-25641EPSS 21%

Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before…

Fix: 2.6.9 / 2.7.8+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30179

Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha…

Fix: 2.6.9 / 2.7.10+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30180EPSS 60%

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the cu…

Fix: 2.7.10+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30181EPSS 61%

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are …

Fix: 2.6.10 / 2.7.10+
Fix from $2,300 2021-06-01
Pulsar CRITICAL 9.8
CVE-2021-22160EPSS 53%

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if th…

Fix: 2.7.1+
Fix from $2,300 2021-05-26
Ofbiz CRITICAL 9.8
CVE-2021-29200EPSS 55%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Ofbiz CRITICAL 9.8
CVE-2021-30128EPSS 81%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Maven CRITICAL 9.1
CVE-2021-26291EPSS 9%

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting …

Fix: 1.13.5 / 3.8.1+
Fix from $2,300 2021-04-23
Tapestry CRITICAL 9.8
CVE-2021-27850EPSS 94%

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…

Fix: 5.6.2 / 5.7.1+
Fix from $2,300 2021-04-15
Solr CRITICAL 9.8
CVE-2021-27905EPSS 93%

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Solr CRITICAL 9.1
CVE-2021-29943EPSS 5%

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usi…

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Spamassassin CRITICAL 9.8
CVE-2020-1946EPSS 6%

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …

Fix: 3.4.5+
Fix from $2,300 2021-03-25