Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Karaf CRITICAL 9.8
CVE-2022-40145

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function …

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-12-21
Zeppelin MEDIUM 6.5
CVE-2021-28655

The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. …

Fix: after 0.9.0
Fix from $1,600 2022-12-16
Cxf HIGH 7.5
CVE-2022-46363

A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vul…

Fix: 3.4.10 / 3.5.5+
Fix from $1,950 2022-12-13
Commons Net MEDIUM 6.5
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net co…

Fix: 3.9.0+
Fix from $1,600 2022-12-03
Hama HIGH 7.5
CVE-2022-45470

missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect t…

Fix: after 1.7.1
Fix from $1,950 2022-11-21
Flume CRITICAL 9.8
CVE-2022-42468

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…

Fix: after 1.10.1
Fix from $2,300 2022-10-26
Pulsar MEDIUM 6.5
CVE-2022-24280

Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from…

Fix: 2.7.5 / 2.8.3+
Fix from $1,600 2022-09-23
Flume CRITICAL 9.8
CVE-2022-34916

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI …

Fix: 1.10.1+
Fix from $2,300 2022-08-21
Traffic Server HIGH 7.5
CVE-2021-37150

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-28129

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue af…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31778

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. Thi…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31779

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects …

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31780

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects …

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Avro HIGH 7.5
CVE-2022-35724

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Avro HIGH 7.5
CVE-2022-36125

It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust …

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Flume CRITICAL 9.8
CVE-2022-25167

Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…

Fix: 1.10.0+
Fix from $2,300 2022-06-14
Apisix CRITICAL 9.8
CVE-2022-25757

In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…

Fix: 2.13.0+
Fix from $2,300 2022-03-28
Traffic Server HIGH 7.5
CVE-2021-44040

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affe…

Fix: after 9.1.1
Fix from $1,950 2022-03-23
Poi MEDIUM 5.5
CVE-2022-26336

A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read…

Fix: 5.2.1+
Fix from $1,600 2022-03-04
Log4j MEDIUM 6.6
CVE-2021-44832EPSS 98%

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…

Fix: 2.3.2 / 2.12.4+
Fix from $1,600 2021-12-28
Solr CRITICAL 9.8
CVE-2021-44548EPSS 5%

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…

Fix: 8.11.1+
Fix from $2,300 2021-12-23
Parquet Java HIGH 7.5
CVE-2021-41561

Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apac…

Fix: 1.11.2 / 1.12.2+
Fix from $1,950 2021-12-20
Log4j MEDIUM 5.9
CVE-2021-45105EPSS 100%

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential looku…

Fix: 2.3.1 / 2.7.0+
Fix from $1,600 2021-12-18
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Ozone MEDIUM 6.8
CVE-2021-39234

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Traffic Server HIGH 7.5
CVE-2021-37148

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.0.1
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-37149

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-41585

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting…

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-37147

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Tomcat HIGH 7.5
CVE-2021-41079EPSS 7%

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured …

Fix: 8.5.64 / 9.0.44+
Fix from $1,950 2021-09-16