Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Jspwiki MEDIUM 6.1
CVE-2022-28732EPSS 82%

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascrip…

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Druid MEDIUM 6.1
CVE-2021-44791

In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes …

Fix: after 0.22.1
Fix from $1,600 2022-07-07
Jetspeed CRITICAL 9.8
CVE-2022-32533

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…

Mitigation only
Fix from $2,300 2022-07-06
Tomcat MEDIUM 6.1
CVE-2022-34305EPSS 7%

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples…

Fix: after 10.0.22
Fix from $1,600 2022-06-23
Jspwiki MEDIUM 6.1
CVE-2022-24948

A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, whi…

Fix: 2.11.2+
Fix from $1,600 2022-02-25
Airflow MEDIUM 6.1
CVE-2021-45229

It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache…

Fix: after 2.2.3
Fix from $1,600 2022-02-25
Knox MEDIUM 6.1
CVE-2021-42357

When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request t…

Fix: 1.6.1+
Fix from $1,600 2022-01-17
Pluto MEDIUM 6.1
CVE-2021-36737

The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of th…

Fix: 3.1.1+
Fix from $1,600 2022-01-06
Pluto MEDIUM 6.1
CVE-2021-36738

The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users sho…

Fix: 3.1.1+
Fix from $1,600 2022-01-06
Pluto MEDIUM 6.1
CVE-2021-36739

The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) at…

Mitigation only
Fix from $1,600 2022-01-06
Jspwiki MEDIUM 6.1
CVE-2021-40369

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow th…

Fix: 2.11.0+
Fix from $1,600 2021-11-24
Superset MEDIUM 5.4
CVE-2021-32609

Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a…

Fix: after 1.1
Fix from $1,600 2021-10-18
Couchdb HIGH 7.3
CVE-2021-38295

In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB…

Fix: 3.1.2+
Fix from $1,950 2021-10-14
Zeppelin MEDIUM 6.1
CVE-2021-27578

Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apac…

Fix: 0.9.0+
Fix from $1,600 2021-09-02
Jena Fuseki MEDIUM 6.1
CVE-2021-33192

A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects …

Fix: 4.1.0+
Fix from $1,600 2021-07-05
Airflow MEDIUM 6.1
CVE-2021-28359EPSS 14%

The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.1…

Fix: 1.10.15 / 2.0.2+
Fix from $1,600 2021-05-02
Velocity Tools MEDIUM 6.1
CVE-2020-13959EPSS 6%

The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attac…

Fix: 3.1+
Fix from $1,600 2021-03-10
Superset MEDIUM 5.4
CVE-2021-27907EPSS 86%

Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related informatio…

Fix: after 0.38.0
Fix from $1,600 2021-03-05
Ambari MEDIUM 6.1
CVE-2020-1936

A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.

Fix: 2.7.4+
Fix from $1,600 2021-03-02
Livy MEDIUM 5.4
CVE-2021-26544

Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw t…

Patch available
Fix from $1,600 2021-02-20
Activemq MEDIUM 6.1
CVE-2020-13947EPSS 79%

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of A…

Fix: 5.15.14 / 5.16.1+
Fix from $1,600 2021-02-08
Airflow MEDIUM 6.1
CVE-2020-17515EPSS 16%

The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prio…

Fix: 1.10.15 / 2.0.2+
Fix from $1,600 2020-12-11
Cxf MEDIUM 6.1
CVE-2020-13954EPSS 43%

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a r…

Fix: 3.3.8 / 3.4.1+
Fix from $1,600 2020-11-12
Airflow MEDIUM 6.1
CVE-2020-13944EPSS 25%

In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.

Fix: 1.10.15 / 2.0.2+
Fix from $1,600 2020-09-17
Atlas MEDIUM 6.1
CVE-2020-13928

Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of th…

Fix: 2.1.0+
Fix from $1,600 2020-09-16
Artemis MEDIUM 6.1
CVE-2020-13932

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vuln…

Fix: after 2.13.0
Fix from $1,600 2020-07-20
Airflow MEDIUM 6.1
CVE-2020-9485

An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.

Fix: after 1.10.10
Fix from $1,600 2020-07-17
Airflow MEDIUM 5.4
CVE-2020-11983

An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handl…

Fix: after 1.10.10
Fix from $1,600 2020-07-17
Ofbiz MEDIUM 6.1
CVE-2020-9496EPSS 99%

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

No fix yet
Fix from $1,600 2020-07-15
Activemq MEDIUM 6.1
CVE-2020-1941EPSS 6%

In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.

Fix: after 8.2.2
Fix from $1,600 2020-05-14