Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Spamassassin CRITICAL 9.8
CVE-2018-11780EPSS 11%

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

Fix: 3.4.2+
Fix from $2,300 2018-09-17
Mod Perl CRITICAL 9.8
CVE-2011-2767EPSS 8%

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do…

Fix: after 2.0.10
Fix from $2,300 2018-08-26
Camel CRITICAL 9.8
CVE-2018-8027EPSS 5%

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

Fix: after 2.20.3
Fix from $2,300 2018-07-31
Openwhisk CRITICAL 9.8
CVE-2018-11756EPSS 7%

In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 or openwhisk/action-php-v7.1:1…

Fix: 1.0.1 / 1.0.2+
Fix from $2,300 2018-07-23
Openwhisk CRITICAL 9.8
CVE-2018-11757EPSS 6%

In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an a…

Fix: after 1.3.0
Fix from $2,300 2018-07-23
Ignite CRITICAL 9.8
CVE-2018-8018EPSS 6%

In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deseriali…

Fix: 2.4.8 / 2.5.3+
Fix from $2,300 2018-07-20
Directory Ldap Api CRITICAL 9.8
CVE-2018-1337

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before…

Fix: 1.0.2+
Fix from $2,300 2018-07-10
Cassandra CRITICAL 9.8
CVE-2018-8016

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows r…

Fix: after 3.11.1
Fix from $2,300 2018-06-28
Batik CRITICAL 9.8
CVE-2018-8013EPSS 18%

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…

Fix: 1.10 / 7.2+
Fix from $2,300 2018-05-24
Nifi CRITICAL 9.8
CVE-2018-1309

Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The f…

Fix: 1.6.0+
Fix from $2,300 2018-05-23
Tomcat CRITICAL 9.8
CVE-2018-8014EPSS 19%

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are ins…

Fix: after 9.0.8
Fix from $2,300 2018-05-16
Fineract CRITICAL 9.8
CVE-2018-1290

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para…

Mitigation only
Fix from $2,300 2018-04-20
Hive CRITICAL 9.1
CVE-2018-1282EPSS 6%

This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup th…

Fix: after 2.3.2
Fix from $2,300 2018-04-05
Ignite CRITICAL 9.8
CVE-2018-1295EPSS 6%

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i…

Fix: after 2.3.0
Fix from $2,300 2018-04-02
HTTP Server CRITICAL 9.8
CVE-2018-1312EPSS 16%

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…

Mitigation only
Fix from $2,300 2018-03-26
Xerces C\+\+ CRITICAL 9.8
CVE-2017-12627EPSS 7%

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…

Fix: 3.2.1+
Fix from $2,300 2018-03-01
Geode CRITICAL 9.8
CVE-2017-15692

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce…

Fix: 1.4.0+
Fix from $2,300 2018-02-27
Jmeter CRITICAL 9.8
CVE-2018-1287

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an at…

Mitigation only
Fix from $2,300 2018-02-14
Jmeter CRITICAL 9.8
CVE-2018-1297EPSS 11%

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …

Mitigation only
Fix from $2,300 2018-02-13
Cloudstack CRITICAL 9.8
CVE-2016-6813EPSS 6%

Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is a…

Fix: after 4.8.1.0
Fix from $2,300 2018-02-06
Hadoop CRITICAL 9.8
CVE-2017-15718

The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Application…

Mitigation only
Fix from $2,300 2018-01-24
Nifi CRITICAL 9.8
CVE-2017-15697

A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fi…

Fix: after 1.4.0
Fix from $2,300 2018-01-23
Groovy CRITICAL 9.8
CVE-2016-6814EPSS 16%

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se…

Fix: after 2.4.7
Fix from $2,300 2018-01-18
Ofbiz CRITICAL 9.8
CVE-2017-15714

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code …

No fix yet
Fix from $2,300 2018-01-04
Flex Blazeds CRITICAL 9.8
CVE-2017-5641EPSS 21%

Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. …

Fix: 8.5.3-00+
Fix from $2,300 2017-12-28
Synapse CRITICAL 9.8
CVE-2017-15708EPSS 18%

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases…

Mitigation only
Fix from $2,300 2017-12-11
Qpid Broker J CRITICAL 9.8
CVE-2017-15702EPSS 6%

In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an …

Fix: after 0.32
Fix from $2,300 2017-12-01
Solr CRITICAL 9.1
CVE-2017-1000190

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

Fix: after 2.7.1
Fix from $2,300 2017-11-17
Camel CRITICAL 9.8
CVE-2017-12633EPSS 7%

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D…

Fix: 2.19.4 / 2.20.1+
Fix from $2,300 2017-11-15
Camel CRITICAL 9.8
CVE-2017-12634EPSS 7%

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De…

Fix: 2.19.4+
Fix from $2,300 2017-11-15