Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-41773 KEVEPSS 100% A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi… HTTP Server Patch available Fix from $2,3002021-10-05 CRITICAL 9.8 CVE-2021-41616 Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR… Ddlutils Mitigation only Fix from $2,3002021-09-30 CRITICAL 9.8 CVE-2021-41303EPSS 77% Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul… Shiro 1.8.0+ Fix from $2,3002021-09-17 CRITICAL 9.8 CVE-2021-39275EPSS 39% ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but t… HTTP Server 2.4.49+ Fix from $2,3002021-09-16 CRITICAL 9.8 CVE-2021-40146EPSS 6% A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vuln… Any23 2.5+ Fix from $2,3002021-09-11 CRITICAL 9.1 CVE-2021-38555 An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X… Any23 2.5+ Fix from $2,3002021-09-11 CRITICAL 9.8 CVE-2021-38540EPSS 81% The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint … Airflow 2.1.3+ Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-37579EPSS 7% The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.… Dubbo 2.7.13 / 3.0.2+ Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-36161 Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean… Dubbo 2.7.13+ Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-36163 In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque… Dubbo after 3.0.1 Fix from $2,3002021-09-07 CRITICAL 9.8 CVE-2019-10095EPSS 6% bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe… Zeppelin after 0.9.0 Fix from $2,3002021-09-02 CRITICAL 9.8 CVE-2021-33191 From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th… Nifi Minifi C\+\+ 0.10.0+ Fix from $2,3002021-08-24 CRITICAL 9.8 CVE-2021-37608EPSS 6% Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach… Ofbiz 17.12.08+ Fix from $2,3002021-08-18 CRITICAL 9.8 CVE-2021-37578 Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo… Juddi 3.3.10+ Fix from $2,3002021-07-29 CRITICAL 9.8 CVE-2021-35474 Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.… Traffic Server after 9.0.1 Fix from $2,3002021-06-30 CRITICAL 9.8 CVE-2021-26461EPSS 5% Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignmen… Nuttx 10.1.0+ Fix from $2,3002021-06-21 CRITICAL 9.8 CVE-2020-9493 A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. Chainsaw 1.2.18.1 / 2.0+ Fix from $2,3002021-06-16 CRITICAL 9.8 CVE-2021-26691EPSS 68% In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow HTTP Server 18.1.0.1.0+ Fix from $2,3002021-06-10 CRITICAL 9.8 CVE-2021-25641EPSS 21% Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before… Dubbo 2.6.9 / 2.7.8+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-30179 Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha… Dubbo 2.6.9 / 2.7.10+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-30180EPSS 60% Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the cu… Dubbo 2.7.10+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-30181EPSS 61% Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are … Dubbo 2.6.10 / 2.7.10+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-22160EPSS 53% If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if th… Pulsar 2.7.1+ Fix from $2,3002021-05-26 CRITICAL 9.8 CVE-2021-29200EPSS 55% Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack Ofbiz 17.12.07+ Fix from $2,3002021-04-27 CRITICAL 9.8 CVE-2021-30128EPSS 81% Apache OFBiz has unsafe deserialization prior to 17.12.07 version Ofbiz 17.12.07+ Fix from $2,3002021-04-27 CRITICAL 9.1 CVE-2021-26291EPSS 9% Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting … Maven 1.13.5 / 3.8.1+ Fix from $2,3002021-04-23 CRITICAL 9.8 CVE-2021-27850EPSS 94% A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,… Tapestry 5.6.2 / 5.7.1+ Fix from $2,3002021-04-15 CRITICAL 9.8 CVE-2021-27905EPSS 93% The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter … Solr 8.8.2+ Fix from $2,3002021-04-13 CRITICAL 9.1 CVE-2021-29943EPSS 5% When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usi… Solr 8.8.2+ Fix from $2,3002021-04-13 CRITICAL 9.8 CVE-2020-1946EPSS 6% In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. … Spamassassin 3.4.5+ Fix from $2,3002021-03-25