Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-5499 Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same. Rust Sgx Sdk after 1.0.8 Fix from $2,3002020-01-04 CRITICAL 9.8 CVE-2019-17571EPSS 69% Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi… Log4j 4.14.3+ Fix from $2,3002019-12-20 CRITICAL 9.8 CVE-2019-17556 Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being … Olingo after 4.6.0 Fix from $2,3002019-12-04 CRITICAL 9.8 CVE-2019-12409EPSS 22% The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh… Solr No fix yet Fix from $2,3002019-11-18 CRITICAL 9.8 CVE-2019-12419EPSS 14% Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne… Cxf 3.2.11 / 3.3.4+ Fix from $2,3002019-11-06 CRITICAL 9.8 CVE-2011-3923EPSS 89% Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. Struts 2.3.1.2+ Fix from $2,3002019-11-01 CRITICAL 9.8 CVE-2019-17195EPSS 11% Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potenti… Hadoop 7.9+ Fix from $2,3002019-10-15 CRITICAL 9.1 CVE-2019-10082EPSS 17% In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during c… HTTP Server after 17.3 Fix from $2,3002019-09-26 CRITICAL 9.8 CVE-2019-10071EPSS 9% The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the… Tapestry after 5.4.3 Fix from $2,3002019-09-16 CRITICAL 9.8 CVE-2019-0195EPSS 15% Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou… Tapestry after 5.4.3 Fix from $2,3002019-09-16 CRITICAL 9.8 CVE-2019-10074 An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This … Ofbiz after 16.11.05 Fix from $2,3002019-09-11 CRITICAL 9.8 CVE-2018-17200EPSS 5% The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpServi… Ofbiz after 16.11.05 Fix from $2,3002019-09-11 CRITICAL 9.8 CVE-2019-0189EPSS 24% The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and … Ofbiz 16.11.06+ Fix from $2,3002019-09-11 CRITICAL 9.8 CVE-2019-12405 Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.… Traffic Control Mitigation only Fix from $2,3002019-09-09 CRITICAL 9.8 CVE-2018-11773 Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as a… Virtual Computing Lab after 2.5 Fix from $2,3002019-07-29 CRITICAL 9.8 CVE-2019-13990EPSS 16% initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. Tomee 2.3.2+ Fix from $2,3002019-07-26 CRITICAL 9.8 CVE-2018-11779 In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d… Storm after 1.2.2 Fix from $2,3002019-07-26 CRITICAL 9.8 CVE-2018-11800 SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts … Fineract 1.3.0+ Fix from $2,3002019-06-11 CRITICAL 9.8 CVE-2018-11801 SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related… Fineract 1.3.0+ Fix from $2,3002019-06-11 CRITICAL 9.8 CVE-2018-17198 Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S… Roller after 5.1.2 Fix from $2,3002019-05-28 CRITICAL 9.8 CVE-2013-7285EPSS 84% Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary… Activemq after 1.4.6 Fix from $2,3002019-05-15 CRITICAL 9.8 CVE-2019-0228EPSS 9% Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac… Pdfbox Mitigation only Fix from $2,3002019-04-17 CRITICAL 9.8 CVE-2019-0192EPSS 57% In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it… Solr after 6.6.5 Fix from $2,3002019-03-07 CRITICAL 9.8 CVE-2019-0187 Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a… Jmeter Mitigation only Fix from $2,3002019-03-06 CRITICAL 9.8 CVE-2017-17836 In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airfl… Airflow after 1.8.2 Fix from $2,3002019-01-23 CRITICAL 9.8 CVE-2018-11788EPSS 6% Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The … Karaf 4.1.7+ Fix from $2,3002019-01-07 CRITICAL 9.8 CVE-2018-17191EPSS 7% Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the n… Netbeans Mitigation only Fix from $2,3002018-12-31 CRITICAL 9.8 CVE-2018-17190EPSS 7% In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos… Spark Mitigation only Fix from $2,3002018-11-19 CRITICAL 9.8 CVE-2018-8021EPSS 44% Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. … Superset 0.23+ Fix from $2,3002018-11-07 CRITICAL 9.8 CVE-2018-11792 In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER… Impala 3.0.1+ Fix from $2,3002018-10-24