Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 7.5 CVE-2019-12425 Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host Ofbiz Mitigation only Fix from $1,9502020-04-30 MEDIUM 6.5 CVE-2020-1958 When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali… Druid Mitigation only Fix from $1,6002020-04-01 MEDIUM 6.1 CVE-2019-12416 we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrat… Deltaspike after 1.9.2 Fix from $1,6002020-03-19 HIGH 7.5 CVE-2019-17558 KEVEPSS 99% Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi… Solr 7.7.3 / 8.4.0+ Fix from $1,9502019-12-30 CRITICAL 9.8 CVE-2019-10074 An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This … Ofbiz after 16.11.05 Fix from $2,3002019-09-11 MEDIUM 6.1 CVE-2018-1319 In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted… Allura after 1.8.0 Fix from $1,6002018-03-15 CRITICAL 9.8 CVE-2017-15714 The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code … Ofbiz No fix yet Fix from $2,3002018-01-04 CRITICAL 9.8 CVE-2017-15708EPSS 18% In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases… Synapse Mitigation only Fix from $2,3002017-12-11 CRITICAL 9.8 CVE-2017-5636 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio… Nifi Mitigation only Fix from $2,3002017-10-19 CRITICAL 9.8 CVE-2015-3253EPSS 41% The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause… Groovy Patch available Fix from $2,3002015-08-13 CRITICAL 9.8 CVE-2013-2251 KEVEPSS 100% Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi… Archiva 1.3.8+ Fix from $2,3002013-07-20