Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2021-32566 Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se… Traffic Server after 9.0.1 Fix from $1,9502021-06-30 HIGH 7.5 CVE-2021-32567 Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se… Traffic Server after 9.0.1 Fix from $1,9502021-06-30 HIGH 8.2 CVE-2020-11987EPSS 14% Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf… Batik after 1.13 Fix from $1,9502021-02-24 HIGH 8.2 CVE-2020-11988EPSS 7% Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi… Xmlgraphics Commons after 2.4 Fix from $1,9502021-02-24 HIGH 8.8 CVE-2020-17532 When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The… Java Chassis 2.1.5+ Fix from $1,9502021-01-25 CRITICAL 9.8 CVE-2020-13942EPSS 68% It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve… Unomi 1.5.2+ Fix from $2,3002020-11-24 HIGH 8.8 CVE-2020-13941 Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org… Solr 8.6.0+ Fix from $1,9502020-08-17 CRITICAL 9.8 CVE-2014-4651 It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc… Jclouds 1.8.0+ Fix from $2,3002020-02-18 HIGH 7.5 CVE-2019-17555 The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w… Olingo after 4.6.0 Fix from $1,9502019-12-04 HIGH 8.8 CVE-2016-1000104 A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. Mod Fcgid after 2016-07-07 Fix from $1,9502019-12-03 MEDIUM 6.5 CVE-2009-5004 qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use . Qpid Cpp Mitigation only Fix from $1,6002019-11-09 MEDIUM 6.5 CVE-2018-11782 In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only … Subversion after 1.11.1 Fix from $1,6002019-09-26 MEDIUM 5.5 CVE-2019-12400 In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static poo… Santuario Xml Security For Java 2.1.4+ Fix from $1,6002019-08-23 CRITICAL 9.8 CVE-2018-11773 Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as a… Virtual Computing Lab after 2.5 Fix from $2,3002019-07-29 HIGH 8.8 CVE-2017-15720 In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object. Airflow after 1.8.2 Fix from $1,9502019-01-23 MEDIUM 6.5 CVE-2018-11799 Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that result… Oozie 5.1.0+ Fix from $1,6002018-12-19 HIGH 7.5 CVE-2018-17194 When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE … Nifi after 1.7.1 Fix from $1,9502018-12-19 HIGH 7.8 CVE-2018-14889 CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. Couchdb Mitigation only Fix from $1,9502018-09-21 MEDIUM 5.3 CVE-2017-15705EPSS 8% A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags… Spamassassin 3.4.2+ Fix from $1,6002018-09-17 HIGH 7.5 CVE-2018-1330 When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked H… Mesos 1.4.2 / 1.5.1+ Fix from $1,9502018-09-13 HIGH 7.5 CVE-2018-8022EPSS 7% A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users … Traffic Server after 6.2.2 Fix from $1,9502018-08-29 HIGH 7.5 CVE-2018-1318EPSS 8% Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server … Traffic Server after 7.1.3 Fix from $1,9502018-08-29 HIGH 7.2 CVE-2018-8007EPSS 12% Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configura… Couchdb after 2.1.1 Fix from $1,9502018-07-11 HIGH 7.5 CVE-2018-8038EPSS 11% Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response… Cxf Fediz 1.4.4+ Fix from $1,9502018-07-05 HIGH 7.5 CVE-2018-8030 A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish mes… Qpid Broker J after 7.0.4 Fix from $1,9502018-06-20 HIGH 8.1 CVE-2017-15715EPSS 86% In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than… HTTP Server after 2.4.29 Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-1294 If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input co… Commons Email after 1.4 Fix from $1,9502018-03-20 HIGH 7.2 CVE-2018-1321EPSS 18% An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and … Syncope 1.2.11 / 2.0.8+ Fix from $1,9502018-03-20 HIGH 8.6 CVE-2017-5660 There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issu… Traffic Server after 6.2.0 Fix from $1,9502018-02-27 HIGH 7.5 CVE-2017-7671 There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can c… Traffic Server after 6.2.0 Fix from $1,9502018-02-27