Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Rust Sgx Sdk CRITICAL 9.8
CVE-2020-5499

Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.

Fix: after 1.0.8
Fix from $2,300 2020-01-04
Log4j CRITICAL 9.8
CVE-2019-17571EPSS 69%

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi…

Fix: 4.14.3+
Fix from $2,300 2019-12-20
Olingo CRITICAL 9.8
CVE-2019-17556

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being …

Fix: after 4.6.0
Fix from $2,300 2019-12-04
Solr CRITICAL 9.8
CVE-2019-12409EPSS 22%

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…

No fix yet
Fix from $2,300 2019-11-18
Cxf CRITICAL 9.8
CVE-2019-12419EPSS 14%

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne…

Fix: 3.2.11 / 3.3.4+
Fix from $2,300 2019-11-06
Struts CRITICAL 9.8
CVE-2011-3923EPSS 89%

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

Fix: 2.3.1.2+
Fix from $2,300 2019-11-01
Hadoop CRITICAL 9.8
CVE-2019-17195EPSS 11%

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potenti…

Fix: 7.9+
Fix from $2,300 2019-10-15
HTTP Server CRITICAL 9.1
CVE-2019-10082EPSS 17%

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during c…

Fix: after 17.3
Fix from $2,300 2019-09-26
Tapestry CRITICAL 9.8
CVE-2019-10071EPSS 9%

The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the…

Fix: after 5.4.3
Fix from $2,300 2019-09-16
Tapestry CRITICAL 9.8
CVE-2019-0195EPSS 15%

Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou…

Fix: after 5.4.3
Fix from $2,300 2019-09-16
Ofbiz CRITICAL 9.8
CVE-2019-10074

An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This …

Fix: after 16.11.05
Fix from $2,300 2019-09-11
Ofbiz CRITICAL 9.8
CVE-2018-17200EPSS 5%

The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpServi…

Fix: after 16.11.05
Fix from $2,300 2019-09-11
Ofbiz CRITICAL 9.8
CVE-2019-0189EPSS 24%

The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and …

Fix: 16.11.06+
Fix from $2,300 2019-09-11
Traffic Control CRITICAL 9.8
CVE-2019-12405

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…

Mitigation only
Fix from $2,300 2019-09-09
Virtual Computing Lab CRITICAL 9.8
CVE-2018-11773

Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as a…

Fix: after 2.5
Fix from $2,300 2019-07-29
Tomee CRITICAL 9.8
CVE-2019-13990EPSS 16%

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Fix: 2.3.2+
Fix from $2,300 2019-07-26
Storm CRITICAL 9.8
CVE-2018-11779

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…

Fix: after 1.2.2
Fix from $2,300 2019-07-26
Fineract CRITICAL 9.8
CVE-2018-11800

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts …

Fix: 1.3.0+
Fix from $2,300 2019-06-11
Fineract CRITICAL 9.8
CVE-2018-11801

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related…

Fix: 1.3.0+
Fix from $2,300 2019-06-11
Roller CRITICAL 9.8
CVE-2018-17198

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S…

Fix: after 5.1.2
Fix from $2,300 2019-05-28
Activemq CRITICAL 9.8
CVE-2013-7285EPSS 84%

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary…

Fix: after 1.4.6
Fix from $2,300 2019-05-15
Pdfbox CRITICAL 9.8
CVE-2019-0228EPSS 9%

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…

Mitigation only
Fix from $2,300 2019-04-17
Solr CRITICAL 9.8
CVE-2019-0192EPSS 57%

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it…

Fix: after 6.6.5
Fix from $2,300 2019-03-07
Jmeter CRITICAL 9.8
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a…

Mitigation only
Fix from $2,300 2019-03-06
Airflow CRITICAL 9.8
CVE-2017-17836

In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airfl…

Fix: after 1.8.2
Fix from $2,300 2019-01-23
Karaf CRITICAL 9.8
CVE-2018-11788EPSS 6%

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …

Fix: 4.1.7+
Fix from $2,300 2019-01-07
Netbeans CRITICAL 9.8
CVE-2018-17191EPSS 7%

Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the n…

Mitigation only
Fix from $2,300 2018-12-31
Spark CRITICAL 9.8
CVE-2018-17190EPSS 7%

In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos…

Mitigation only
Fix from $2,300 2018-11-19
Superset CRITICAL 9.8
CVE-2018-8021EPSS 44%

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. …

Fix: 0.23+
Fix from $2,300 2018-11-07
Impala CRITICAL 9.8
CVE-2018-11792

In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER…

Fix: 3.0.1+
Fix from $2,300 2018-10-24