Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-13925EPSS 20% Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi… Kylin 3.1.0+ Fix from $2,3002020-07-14 CRITICAL 9.8 CVE-2020-13926 Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh… Kylin 3.1.0+ Fix from $2,3002020-07-14 CRITICAL 9.8 CVE-2020-9480EPSS 29% In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar… Spark after 2.4.5 Fix from $2,3002020-06-23 CRITICAL 9.8 CVE-2020-11989EPSS 24% Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. Shiro 1.5.3+ Fix from $2,3002020-06-22 CRITICAL 9.8 CVE-2020-11969 If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP… Tomee after 8.0.1 Fix from $2,3002020-06-15 CRITICAL 9.8 CVE-2020-11975EPSS 30% Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code wi… Unomi 1.5.1+ Fix from $2,3002020-06-05 CRITICAL 9.1 CVE-2020-1963 Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fi… Ignite after 2.8.0 Fix from $2,3002020-06-03 CRITICAL 9.8 CVE-2018-21234EPSS 8% Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. Hive 5.0.4+ Fix from $2,3002020-05-21 CRITICAL 9.8 CVE-2020-1955 CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e… Couchdb Mitigation only Fix from $2,3002020-05-20 CRITICAL 9.8 CVE-2020-11972EPSS 6% Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users… Camel after 8.2.2 Fix from $2,3002020-05-14 CRITICAL 9.8 CVE-2020-11973EPSS 7% Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh… Camel after 8.5.0 Fix from $2,3002020-05-14 CRITICAL 9.8 CVE-2019-17562 A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vul… Cloudstack 4.13.1.0+ Fix from $2,3002020-05-14 CRITICAL 9.8 CVE-2020-1939 The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs… Nuttx after 8.2 Fix from $2,3002020-05-12 CRITICAL 9.8 CVE-2018-1285EPSS 17% Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack… Log4net 2.0.10+ Fix from $2,3002020-05-11 CRITICAL 9.8 CVE-2020-1961 Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e… Syncope 2.0.15 / 2.1.6+ Fix from $2,3002020-05-04 CRITICAL 9.8 CVE-2020-1959 A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading … Syncope 2.1.6+ Fix from $2,3002020-05-04 CRITICAL 9.8 CVE-2020-1952 An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, c… Iotdb after 0.9.1 Fix from $2,3002020-04-27 CRITICAL 9.8 CVE-2020-1964 It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to … Heron Mitigation only Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2019-17564EPSS 37% Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in… Dubbo after 2.7.4 Fix from $2,3002020-04-01 CRITICAL 9.1 CVE-2019-17560 The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to interc… Netbeans after 11.2 Fix from $2,3002020-03-30 CRITICAL 9.8 CVE-2020-1957EPSS 23% Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. Shiro 1.5.2+ Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2019-17559 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgr… Traffic Server after 8.0.5 Fix from $2,3002020-03-23 CRITICAL 9.8 CVE-2019-17565 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Up… Traffic Server after 8.0.5 Fix from $2,3002020-03-23 CRITICAL 9.8 CVE-2020-1944 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding an… Traffic Server after 8.0.5 Fix from $2,3002020-03-23 CRITICAL 10.0 CVE-2020-1953EPSS 7% Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes… Commons Configuration Mitigation only Fix from $2,3002020-03-13 CRITICAL 9.8 CVE-2020-1947EPSS 34% In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load … Shardingsphere Mitigation only Fix from $2,3002020-03-11 CRITICAL 9.8 CVE-2020-1938 KEVEPSS 99% When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as … Geode 7.0.100 / 8.5.51+ Fix from $2,3002020-02-24 CRITICAL 9.8 CVE-2014-4651 It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc… Jclouds 1.8.0+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2019-17570EPSS 49% An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar… Xml Rpc Patch available Fix from $2,3002020-01-23 CRITICAL 9.8 CVE-2019-0219EPSS 8% A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially craft… Cordova Inappbrowser after 3.0.0 Fix from $2,3002020-01-14