Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
HIGH 8.2 CVE-2020-11987EPSS 14% Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf… Batik after 1.13 Fix from $1,9502021-02-24 HIGH 8.2 CVE-2020-11988EPSS 7% Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi… Xmlgraphics Commons after 2.4 Fix from $1,9502021-02-24 HIGH 7.7 CVE-2020-26258EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability c… Struts 1.4.15 / 6.0.0+ Fix from $1,9502020-12-16 MEDIUM 5.3 CVE-2020-17513 In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack. Airflow 1.10.13+ Fix from $1,6002020-12-14 HIGH 7.5 CVE-2019-17566EPSS 11% Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-c… Batik 1.13+ Fix from $1,9502020-11-12 MEDIUM 6.3 CVE-2020-11980 In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on… Karaf 4.2.9+ Fix from $1,6002020-06-12 HIGH 7.5 CVE-2020-1925 Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or D… Olingo after 4.7.0 Fix from $1,9502020-01-09 CRITICAL 9.8 CVE-2018-17198 Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S… Roller after 5.1.2 Fix from $2,3002019-05-28 HIGH 7.5 CVE-2019-0227EPSS 92% A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits… Axis Patch available Fix from $1,9502019-05-01 HIGH 7.5 CVE-2017-3164EPSS 19% Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist … Solr after 7.6.0 Fix from $1,9502019-03-08 MEDIUM 6.5 CVE-2018-1000421 An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read … Mesos after 0.17.1 Fix from $1,6002019-01-09 HIGH 7.4 CVE-2017-5643EPSS 6% Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. Camel after 2.16.0 Fix from $1,9502017-03-16