Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Ofbiz HIGH 7.5
CVE-2019-12425

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

Mitigation only
Fix from $1,950 2020-04-30
Druid MEDIUM 6.5
CVE-2020-1958

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…

Mitigation only
Fix from $1,600 2020-04-01
Deltaspike MEDIUM 6.1
CVE-2019-12416

we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrat…

Fix: after 1.9.2
Fix from $1,600 2020-03-19
Solr HIGH 7.5
CVE-2019-17558 KEVEPSS 99%

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…

Fix: 7.7.3 / 8.4.0+
Fix from $1,950 2019-12-30
Ofbiz CRITICAL 9.8
CVE-2019-10074

An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This …

Fix: after 16.11.05
Fix from $2,300 2019-09-11
Allura MEDIUM 6.1
CVE-2018-1319

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted…

Fix: after 1.8.0
Fix from $1,600 2018-03-15
Ofbiz CRITICAL 9.8
CVE-2017-15714

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code …

No fix yet
Fix from $2,300 2018-01-04
Synapse CRITICAL 9.8
CVE-2017-15708EPSS 18%

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases…

Mitigation only
Fix from $2,300 2017-12-11
Nifi CRITICAL 9.8
CVE-2017-5636

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…

Mitigation only
Fix from $2,300 2017-10-19
Groovy CRITICAL 9.8
CVE-2015-3253EPSS 41%

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause…

Patch available
Fix from $2,300 2015-08-13
Archiva CRITICAL 9.8
CVE-2013-2251 KEVEPSS 100%

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi…

Fix: 1.3.8+
Fix from $2,300 2013-07-20