Vulnerability index

Browse CVEs

22 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici… Iotdb 2.0.8+ Fix from $2,3002026-07-06 MEDIUM 6.5 CVE-2026-33582 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF ima… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-34031 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not… Answer 2.0.1+ Fix from $1,6002026-06-09 HIGH 7.3 CVE-2025-59118 Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommen… Ofbiz 24.09.03+ Fix from $1,9502025-11-12 CRITICAL 9.8 CVE-2024-53677EPSS 78% File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th… Struts 6.4.0+ Fix from $2,3002024-12-11 HIGH 8.8 CVE-2024-31411 Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead … Streampipes 0.95.0+ Fix from $1,9502024-07-17 MEDIUM 5.3 CVE-2024-23946 Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Ofbiz 18.12.12+ Fix from $1,6002024-02-29 CRITICAL 9.1 CVE-2024-22393 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack b… Answer 1.2.5+ Fix from $2,3002024-02-22 HIGH 8.8 CVE-2023-50386EPSS 84% Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 CRITICAL 9.8 CVE-2022-45802 Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload… Streampark 2.0.0+ Fix from $2,3002023-05-01 CRITICAL 9.8 CVE-2023-27602 In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2021-37608EPSS 6% Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach… Ofbiz 17.12.08+ Fix from $2,3002021-08-18 CRITICAL 9.8 CVE-2021-21347EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21350EPSS 15% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21351EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21344EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21346EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 8.8 CVE-2012-1592EPSS 29% A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit… Struts Mitigation only Fix from $1,9502019-12-05 CRITICAL 9.8 CVE-2019-12409EPSS 22% The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh… Solr No fix yet Fix from $2,3002019-11-18 HIGH 8.1 CVE-2017-12617 KEVEPSS 100% When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett… Tomcat 7.0.82 / 8.0.47+ Fix from $1,9502017-10-04 HIGH 8.1 CVE-2017-12615 KEVEPSS 100% When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t… Tomcat after 7.0.79 Fix from $1,9502017-09-19 CRITICAL 9.8 CVE-2016-3088 KEVEPSS 99% The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol… Activemq 5.14.0+ Fix from $2,3002016-06-01