Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-21347EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21350EPSS 15% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21351EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.9 CVE-2021-21345EPSS 72% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21344EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21346EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21342EPSS 50% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed … Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-26295EPSS 98% Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF… Ofbiz 17.12.06+ Fix from $2,3002021-03-22 CRITICAL 9.8 CVE-2020-17523EPSS 86% Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Shiro 1.7.1+ Fix from $2,3002021-02-03 CRITICAL 9.1 CVE-2021-23901 An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa… Nutch 1.18+ Fix from $2,3002021-01-25 CRITICAL 9.1 CVE-2021-23926EPSS 6% The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities … Xmlbeans after 2.6.0 Fix from $2,3002021-01-14 CRITICAL 9.8 CVE-2020-11995EPSS 6% A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H… Dubbo after 2.7.7 Fix from $2,3002021-01-11 CRITICAL 9.8 CVE-2020-11974EPSS 8% In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database. Dolphinscheduler Mitigation only Fix from $2,3002020-12-18 CRITICAL 9.8 CVE-2020-13931 If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker co… Tomee after 8.0.3 Fix from $2,3002020-12-18 CRITICAL 9.8 CVE-2020-17530 KEVEPSS 96% Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.… Struts 2.5.30+ Fix from $2,3002020-12-11 CRITICAL 9.8 CVE-2020-17529 Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt … Nuttx after 9.1.0 Fix from $2,3002020-12-09 CRITICAL 9.1 CVE-2020-17528 Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt … Nuttx after 9.1.0 Fix from $2,3002020-12-09 CRITICAL 9.8 CVE-2020-17531EPSS 10% A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok… Tapestry 5.0.1+ Fix from $2,3002020-12-08 CRITICAL 9.8 CVE-2020-13942EPSS 68% It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve… Unomi 1.5.2+ Fix from $2,3002020-11-24 CRITICAL 9.8 CVE-2020-13927 KEVEPSS 100% The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us… Airflow 1.10.11+ Fix from $2,3002020-11-10 CRITICAL 9.8 CVE-2020-17510EPSS 9% Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Shiro 1.7.0+ Fix from $2,3002020-11-05 CRITICAL 9.8 CVE-2020-13957EPSS 79% Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co… Solr after 8.6.2 Fix from $2,3002020-10-13 CRITICAL 9.8 CVE-2019-0230EPSS 97% Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Struts after 8.0.23 Fix from $2,3002020-09-14 CRITICAL 9.8 CVE-2020-11998EPSS 51% A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map … Activemq after 8.5.0 Fix from $2,3002020-09-10 CRITICAL 9.8 CVE-2020-11986EPSS 10% To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build… Netbeans after 12.0 Fix from $2,3002020-09-09 CRITICAL 9.8 CVE-2020-11984EPSS 90% Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE HTTP Server after 8.2.2 Fix from $2,3002020-08-07 CRITICAL 9.8 CVE-2020-13921EPSS 33% **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases. Skywalking Patch available Fix from $2,3002020-08-05 CRITICAL 9.8 CVE-2020-11981EPSS 37% An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ… Airflow after 1.10.10 Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-11982EPSS 7% An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) … Airflow after 1.10.10 Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-1948EPSS 16% This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met… Dubbo after 2.7.6 Fix from $2,3002020-07-14