Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Kylin CRITICAL 9.8
CVE-2020-13925EPSS 20%

Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…

Fix: 3.1.0+
Fix from $2,300 2020-07-14
Kylin CRITICAL 9.8
CVE-2020-13926

Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…

Fix: 3.1.0+
Fix from $2,300 2020-07-14
Spark CRITICAL 9.8
CVE-2020-9480EPSS 29%

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…

Fix: after 2.4.5
Fix from $2,300 2020-06-23
Shiro CRITICAL 9.8
CVE-2020-11989EPSS 24%

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

Fix: 1.5.3+
Fix from $2,300 2020-06-22
Tomee CRITICAL 9.8
CVE-2020-11969

If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP…

Fix: after 8.0.1
Fix from $2,300 2020-06-15
Unomi CRITICAL 9.8
CVE-2020-11975EPSS 30%

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code wi…

Fix: 1.5.1+
Fix from $2,300 2020-06-05
Ignite CRITICAL 9.1
CVE-2020-1963

Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fi…

Fix: after 2.8.0
Fix from $2,300 2020-06-03
Hive CRITICAL 9.8
CVE-2018-21234EPSS 8%

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

Fix: 5.0.4+
Fix from $2,300 2020-05-21
Couchdb CRITICAL 9.8
CVE-2020-1955

CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…

Mitigation only
Fix from $2,300 2020-05-20
Camel CRITICAL 9.8
CVE-2020-11972EPSS 6%

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users…

Fix: after 8.2.2
Fix from $2,300 2020-05-14
Camel CRITICAL 9.8
CVE-2020-11973EPSS 7%

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh…

Fix: after 8.5.0
Fix from $2,300 2020-05-14
Cloudstack CRITICAL 9.8
CVE-2019-17562

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vul…

Fix: 4.13.1.0+
Fix from $2,300 2020-05-14
Nuttx CRITICAL 9.8
CVE-2020-1939

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs…

Fix: after 8.2
Fix from $2,300 2020-05-12
Log4net CRITICAL 9.8
CVE-2018-1285EPSS 17%

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…

Fix: 2.0.10+
Fix from $2,300 2020-05-11
Syncope CRITICAL 9.8
CVE-2020-1961

Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e…

Fix: 2.0.15 / 2.1.6+
Fix from $2,300 2020-05-04
Syncope CRITICAL 9.8
CVE-2020-1959

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading …

Fix: 2.1.6+
Fix from $2,300 2020-05-04
Iotdb CRITICAL 9.8
CVE-2020-1952

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, c…

Fix: after 0.9.1
Fix from $2,300 2020-04-27
Heron CRITICAL 9.8
CVE-2020-1964

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …

Mitigation only
Fix from $2,300 2020-04-16
Dubbo CRITICAL 9.8
CVE-2019-17564EPSS 37%

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in…

Fix: after 2.7.4
Fix from $2,300 2020-04-01
Netbeans CRITICAL 9.1
CVE-2019-17560

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to interc…

Fix: after 11.2
Fix from $2,300 2020-03-30
Shiro CRITICAL 9.8
CVE-2020-1957EPSS 23%

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

Fix: 1.5.2+
Fix from $2,300 2020-03-25
Traffic Server CRITICAL 9.8
CVE-2019-17559

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgr…

Fix: after 8.0.5
Fix from $2,300 2020-03-23
Traffic Server CRITICAL 9.8
CVE-2019-17565

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Up…

Fix: after 8.0.5
Fix from $2,300 2020-03-23
Traffic Server CRITICAL 9.8
CVE-2020-1944

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding an…

Fix: after 8.0.5
Fix from $2,300 2020-03-23
Commons Configuration CRITICAL 10.0
CVE-2020-1953EPSS 7%

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…

Mitigation only
Fix from $2,300 2020-03-13
Shardingsphere CRITICAL 9.8
CVE-2020-1947EPSS 34%

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …

Mitigation only
Fix from $2,300 2020-03-11
Geode CRITICAL 9.8
CVE-2020-1938 KEVEPSS 99%

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as …

Fix: 7.0.100 / 8.5.51+
Fix from $2,300 2020-02-24
Jclouds CRITICAL 9.8
CVE-2014-4651

It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc…

Fix: 1.8.0+
Fix from $2,300 2020-02-18
Xml Rpc CRITICAL 9.8
CVE-2019-17570EPSS 49%

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar…

Patch available
Fix from $2,300 2020-01-23
Cordova Inappbrowser CRITICAL 9.8
CVE-2019-0219EPSS 8%

A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially craft…

Fix: after 3.0.0
Fix from $2,300 2020-01-14