Vulnerability index

Browse CVEs

22 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Iotdb CRITICAL 9.8
CVE-2026-24014

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Answer MEDIUM 6.5
CVE-2026-33582

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF ima…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Answer MEDIUM 6.5
CVE-2026-34031

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Ofbiz HIGH 7.3
CVE-2025-59118

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommen…

Fix: 24.09.03+
Fix from $1,950 2025-11-12
Struts CRITICAL 9.8
CVE-2024-53677EPSS 78%

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th…

Fix: 6.4.0+
Fix from $2,300 2024-12-11
Streampipes HIGH 8.8
CVE-2024-31411

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead …

Fix: 0.95.0+
Fix from $1,950 2024-07-17
Ofbiz MEDIUM 5.3
CVE-2024-23946

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $1,600 2024-02-29
Answer CRITICAL 9.1
CVE-2024-22393

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack b…

Fix: 1.2.5+
Fix from $2,300 2024-02-22
Solr HIGH 8.8
CVE-2023-50386EPSS 84%

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Streampark CRITICAL 9.8
CVE-2022-45802

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Linkis CRITICAL 9.8
CVE-2023-27602

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Ofbiz CRITICAL 9.8
CVE-2021-37608EPSS 6%

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach…

Fix: 17.12.08+
Fix from $2,300 2021-08-18
Activemq CRITICAL 9.8
CVE-2021-21347EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21350EPSS 15%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21351EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21344EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21346EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Struts HIGH 8.8
CVE-2012-1592EPSS 29%

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit…

Mitigation only
Fix from $1,950 2019-12-05
Solr CRITICAL 9.8
CVE-2019-12409EPSS 22%

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…

No fix yet
Fix from $2,300 2019-11-18
Tomcat HIGH 8.1
CVE-2017-12617 KEVEPSS 100%

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…

Fix: 7.0.82 / 8.0.47+
Fix from $1,950 2017-10-04
Tomcat HIGH 8.1
CVE-2017-12615 KEVEPSS 100%

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t…

Fix: after 7.0.79
Fix from $1,950 2017-09-19
Activemq CRITICAL 9.8
CVE-2016-3088 KEVEPSS 99%

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol…

Fix: 5.14.0+
Fix from $2,300 2016-06-01