Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Activemq CRITICAL 9.8
CVE-2021-21347EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21350EPSS 15%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21351EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21344EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21346EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21342EPSS 50%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Ofbiz CRITICAL 9.8
CVE-2021-26295EPSS 98%

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF…

Fix: 17.12.06+
Fix from $2,300 2021-03-22
Shiro CRITICAL 9.8
CVE-2020-17523EPSS 86%

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.1+
Fix from $2,300 2021-02-03
Nutch CRITICAL 9.1
CVE-2021-23901

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa…

Fix: 1.18+
Fix from $2,300 2021-01-25
Xmlbeans CRITICAL 9.1
CVE-2021-23926EPSS 6%

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities …

Fix: after 2.6.0
Fix from $2,300 2021-01-14
Dubbo CRITICAL 9.8
CVE-2020-11995EPSS 6%

A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H…

Fix: after 2.7.7
Fix from $2,300 2021-01-11
Dolphinscheduler CRITICAL 9.8
CVE-2020-11974EPSS 8%

In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.

Mitigation only
Fix from $2,300 2020-12-18
Tomee CRITICAL 9.8
CVE-2020-13931

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker co…

Fix: after 8.0.3
Fix from $2,300 2020-12-18
Struts CRITICAL 9.8
CVE-2020-17530 KEVEPSS 96%

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.…

Fix: 2.5.30+
Fix from $2,300 2020-12-11
Nuttx CRITICAL 9.8
CVE-2020-17529

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …

Fix: after 9.1.0
Fix from $2,300 2020-12-09
Nuttx CRITICAL 9.1
CVE-2020-17528

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …

Fix: after 9.1.0
Fix from $2,300 2020-12-09
Tapestry CRITICAL 9.8
CVE-2020-17531EPSS 10%

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok…

Fix: 5.0.1+
Fix from $2,300 2020-12-08
Unomi CRITICAL 9.8
CVE-2020-13942EPSS 68%

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…

Fix: 1.5.2+
Fix from $2,300 2020-11-24
Airflow CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…

Fix: 1.10.11+
Fix from $2,300 2020-11-10
Shiro CRITICAL 9.8
CVE-2020-17510EPSS 9%

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.0+
Fix from $2,300 2020-11-05
Solr CRITICAL 9.8
CVE-2020-13957EPSS 79%

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co…

Fix: after 8.6.2
Fix from $2,300 2020-10-13
Struts CRITICAL 9.8
CVE-2019-0230EPSS 97%

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Fix: after 8.0.23
Fix from $2,300 2020-09-14
Activemq CRITICAL 9.8
CVE-2020-11998EPSS 51%

A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map …

Fix: after 8.5.0
Fix from $2,300 2020-09-10
Netbeans CRITICAL 9.8
CVE-2020-11986EPSS 10%

To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build…

Fix: after 12.0
Fix from $2,300 2020-09-09
HTTP Server CRITICAL 9.8
CVE-2020-11984EPSS 90%

Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

Fix: after 8.2.2
Fix from $2,300 2020-08-07
Skywalking CRITICAL 9.8
CVE-2020-13921EPSS 33%

**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

Patch available
Fix from $2,300 2020-08-05
Airflow CRITICAL 9.8
CVE-2020-11981EPSS 37%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ…

Fix: after 1.10.10
Fix from $2,300 2020-07-17
Airflow CRITICAL 9.8
CVE-2020-11982EPSS 7%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) …

Fix: after 1.10.10
Fix from $2,300 2020-07-17
Dubbo CRITICAL 9.8
CVE-2020-1948EPSS 16%

This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met…

Fix: after 2.7.6
Fix from $2,300 2020-07-14