Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2022-40145 This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function … Karaf 4.3.8 / 4.4.2+ Fix from $2,3002022-12-21 MEDIUM 6.5 CVE-2021-28655 The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. … Zeppelin after 0.9.0 Fix from $1,6002022-12-16 HIGH 7.5 CVE-2022-46363 A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vul… Cxf 3.4.10 / 3.5.5+ Fix from $1,9502022-12-13 MEDIUM 6.5 CVE-2021-37533 Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net co… Commons Net 3.9.0+ Fix from $1,6002022-12-03 HIGH 7.5 CVE-2022-45470 missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect t… Hama after 1.7.1 Fix from $1,9502022-11-21 CRITICAL 9.8 CVE-2022-42468 Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa… Flume after 1.10.1 Fix from $2,3002022-10-26 MEDIUM 6.5 CVE-2022-24280 Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from… Pulsar 2.7.5 / 2.8.3+ Fix from $1,6002022-09-23 CRITICAL 9.8 CVE-2022-34916 Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI … Flume 1.10.1+ Fix from $2,3002022-08-21 HIGH 7.5 CVE-2021-37150 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-28129 Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue af… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31778 Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. Thi… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31779 Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects … Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31780 Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects … Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-35724 It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin… Avro 0.14.0+ Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-36125 It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust … Avro 0.14.0+ Fix from $1,9502022-08-09 CRITICAL 9.8 CVE-2022-25167 Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L… Flume 1.10.0+ Fix from $2,3002022-06-14 CRITICAL 9.8 CVE-2022-25757 In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO… Apisix 2.13.0+ Fix from $2,3002022-03-28 HIGH 7.5 CVE-2021-44040 Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affe… Traffic Server after 9.1.1 Fix from $1,9502022-03-23 MEDIUM 5.5 CVE-2022-26336 A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read… Poi 5.2.1+ Fix from $1,6002022-03-04 MEDIUM 6.6 CVE-2021-44832EPSS 98% Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at… Log4j 2.3.2 / 2.12.4+ Fix from $1,6002021-12-28 CRITICAL 9.8 CVE-2021-44548EPSS 5% An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n… Solr 8.11.1+ Fix from $2,3002021-12-23 HIGH 7.5 CVE-2021-41561 Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apac… Parquet Java 1.11.2 / 1.12.2+ Fix from $1,9502021-12-20 MEDIUM 5.9 CVE-2021-45105EPSS 100% Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential looku… Log4j 2.3.1 / 2.7.0+ Fix from $1,6002021-12-18 CRITICAL 10.0 CVE-2021-44228 KEVEPSS 100% Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… Log4j 2.1.0 / 2.3.1+ Fix from $2,3002021-12-10 MEDIUM 6.8 CVE-2021-39234 In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo… Ozone 1.2.0+ Fix from $1,6002021-11-19 HIGH 7.5 CVE-2021-37148 Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache … Traffic Server after 9.0.1 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-37149 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache … Traffic Server after 9.1.0 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-41585 Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting… Traffic Server after 9.1.0 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-37147 Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache … Traffic Server after 9.1.0 Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-41079EPSS 7% Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured … Tomcat 8.5.64 / 9.0.44+ Fix from $1,9502021-09-16