Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-25757 In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO… Apisix 2.13.0+ Fix from $2,3002022-03-28 CRITICAL 9.8 CVE-2022-22720EPSS 28% Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server … HTTP Server 10.15.7 / 11.6.6+ Fix from $2,3002022-03-14 CRITICAL 9.8 CVE-2022-23943EPSS 50% Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. … HTTP Server 2.4.53+ Fix from $2,3002022-03-14 CRITICAL 9.1 CVE-2022-22721EPSS 42% If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later ca… HTTP Server 10.15.7 / 11.6.6+ Fix from $2,3002022-03-14 CRITICAL 9.1 CVE-2022-25312 An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions … Any23 2.7+ Fix from $2,3002022-03-05 CRITICAL 9.8 CVE-2022-24112 KEVEPSS 96% An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX … Apisix 2.10.4 / 2.12.1+ Fix from $2,3002022-02-11 CRITICAL 9.1 CVE-2021-44521EPSS 55% When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab… Cassandra 3.0.26 / 3.11.12+ Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2021-36152 Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to ver… Gobblin after 0.15.0 Fix from $2,3002022-02-04 CRITICAL 9.1 CVE-2022-23944EPSS 79% User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Patch available Fix from $2,3002022-01-25 CRITICAL 9.8 CVE-2021-45029EPSS 6% Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Mitigation only Fix from $2,3002022-01-25 CRITICAL 9.8 CVE-2022-23305EPSS 67% By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from … Log4j 1.2.18.2+ Fix from $2,3002022-01-18 CRITICAL 9.8 CVE-2021-43297EPSS 17% A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub… Dubbo 2.6.12 / 2.7.15+ Fix from $2,3002022-01-10 CRITICAL 9.8 CVE-2021-31522 Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach… Kylin 3.1.3+ Fix from $2,3002022-01-06 CRITICAL 9.8 CVE-2021-45456EPSS 89% Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet… Kylin Mitigation only Fix from $2,3002022-01-06 CRITICAL 9.1 CVE-2021-40525 Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writ… James 3.6.2+ Fix from $2,3002022-01-04 CRITICAL 9.8 CVE-2021-45232EPSS 86% In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all… Apisix Dashboard 2.10.1+ Fix from $2,3002021-12-27 CRITICAL 9.8 CVE-2021-44548EPSS 5% An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n… Solr 8.11.1+ Fix from $2,3002021-12-23 CRITICAL 9.8 CVE-2021-44790EPSS 97% A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache http… HTTP Server 2.4.52 / 5.20.0+ Fix from $2,3002021-12-20 CRITICAL 9.0 CVE-2021-45046 KEVEPSS 100% It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at… Log4j 2.12.2 / 2.16.0+ Fix from $2,3002021-12-14 CRITICAL 10.0 CVE-2021-44228 KEVEPSS 100% Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… Log4j 2.1.0 / 2.3.1+ Fix from $2,3002021-12-10 CRITICAL 9.1 CVE-2021-44140EPSS 6% Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques… Jspwiki 2.11.0+ Fix from $2,3002021-11-24 CRITICAL 9.1 CVE-2021-39231 In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att… Ozone 1.2.0+ Fix from $2,3002021-11-19 CRITICAL 9.1 CVE-2021-39233 In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any … Ozone 1.2.0+ Fix from $2,3002021-11-19 CRITICAL 9.8 CVE-2021-36372 In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authentica… Ozone 1.2.0+ Fix from $2,3002021-11-19 CRITICAL 9.8 CVE-2021-37580EPSS 40% A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff… Shenyu Mitigation only Fix from $2,3002021-11-16 CRITICAL 9.8 CVE-2021-43350 An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP… Traffic Control 5.1.4 / 6.0.1+ Fix from $2,3002021-11-11 CRITICAL 9.8 CVE-2021-43082 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an… Traffic Server after 9.1.0 Fix from $2,3002021-11-03 CRITICAL 9.8 CVE-2021-40865EPSS 66% An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 CRITICAL 9.8 CVE-2021-38294EPSS 84% A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 CRITICAL 9.8 CVE-2021-42013 KEVEPSS 100% It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… HTTP Server 9.2.6.0 / 18.1.0.1.0+ Fix from $2,3002021-10-07