Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Traffic Server HIGH 7.5
CVE-2021-32566

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se…

Fix: after 9.0.1
Fix from $1,950 2021-06-30
Traffic Server HIGH 7.5
CVE-2021-32567

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se…

Fix: after 9.0.1
Fix from $1,950 2021-06-30
Batik HIGH 8.2
CVE-2020-11987EPSS 14%

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf…

Fix: after 1.13
Fix from $1,950 2021-02-24
Xmlgraphics Commons HIGH 8.2
CVE-2020-11988EPSS 7%

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi…

Fix: after 2.4
Fix from $1,950 2021-02-24
Java Chassis HIGH 8.8
CVE-2020-17532

When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The…

Fix: 2.1.5+
Fix from $1,950 2021-01-25
Unomi CRITICAL 9.8
CVE-2020-13942EPSS 68%

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…

Fix: 1.5.2+
Fix from $2,300 2020-11-24
Solr HIGH 8.8
CVE-2020-13941

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org…

Fix: 8.6.0+
Fix from $1,950 2020-08-17
Jclouds CRITICAL 9.8
CVE-2014-4651

It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc…

Fix: 1.8.0+
Fix from $2,300 2020-02-18
Olingo HIGH 7.5
CVE-2019-17555

The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w…

Fix: after 4.6.0
Fix from $1,950 2019-12-04
Mod Fcgid HIGH 8.8
CVE-2016-1000104

A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.

Fix: after 2016-07-07
Fix from $1,950 2019-12-03
Qpid Cpp MEDIUM 6.5
CVE-2009-5004

qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

Mitigation only
Fix from $1,600 2019-11-09
Subversion MEDIUM 6.5
CVE-2018-11782

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only …

Fix: after 1.11.1
Fix from $1,600 2019-09-26
Santuario Xml Security For Java MEDIUM 5.5
CVE-2019-12400

In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static poo…

Fix: 2.1.4+
Fix from $1,600 2019-08-23
Virtual Computing Lab CRITICAL 9.8
CVE-2018-11773

Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as a…

Fix: after 2.5
Fix from $2,300 2019-07-29
Airflow HIGH 8.8
CVE-2017-15720

In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.

Fix: after 1.8.2
Fix from $1,950 2019-01-23
Oozie MEDIUM 6.5
CVE-2018-11799

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that result…

Fix: 5.1.0+
Fix from $1,600 2018-12-19
Nifi HIGH 7.5
CVE-2018-17194

When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE …

Fix: after 1.7.1
Fix from $1,950 2018-12-19
Couchdb HIGH 7.8
CVE-2018-14889

CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.

Mitigation only
Fix from $1,950 2018-09-21
Spamassassin MEDIUM 5.3
CVE-2017-15705EPSS 8%

A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags…

Fix: 3.4.2+
Fix from $1,600 2018-09-17
Mesos HIGH 7.5
CVE-2018-1330

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked H…

Fix: 1.4.2 / 1.5.1+
Fix from $1,950 2018-09-13
Traffic Server HIGH 7.5
CVE-2018-8022EPSS 7%

A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users …

Fix: after 6.2.2
Fix from $1,950 2018-08-29
Traffic Server HIGH 7.5
CVE-2018-1318EPSS 8%

Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server …

Fix: after 7.1.3
Fix from $1,950 2018-08-29
Couchdb HIGH 7.2
CVE-2018-8007EPSS 12%

Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configura…

Fix: after 2.1.1
Fix from $1,950 2018-07-11
Cxf Fediz HIGH 7.5
CVE-2018-8038EPSS 11%

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response…

Fix: 1.4.4+
Fix from $1,950 2018-07-05
Qpid Broker J HIGH 7.5
CVE-2018-8030

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish mes…

Fix: after 7.0.4
Fix from $1,950 2018-06-20
HTTP Server HIGH 8.1
CVE-2017-15715EPSS 86%

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than…

Fix: after 2.4.29
Fix from $1,950 2018-03-26
Commons Email HIGH 7.5
CVE-2018-1294

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input co…

Fix: after 1.4
Fix from $1,950 2018-03-20
Syncope HIGH 7.2
CVE-2018-1321EPSS 18%

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and …

Fix: 1.2.11 / 2.0.8+
Fix from $1,950 2018-03-20
Traffic Server HIGH 8.6
CVE-2017-5660

There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issu…

Fix: after 6.2.0
Fix from $1,950 2018-02-27
Traffic Server HIGH 7.5
CVE-2017-7671

There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can c…

Fix: after 6.2.0
Fix from $1,950 2018-02-27