Vulnerability index

Browse CVEs

74 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Tomcat MEDIUM 6.8
CVE-2013-4444EPSS 14%

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JM…

Fix: after 7.0.39
Fix from $1,600 2014-09-12
Couchdb MEDIUM 6.8
CVE-2012-5649EPSS 7%

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, relat…

Fix: after 1.0.3
Fix from $1,600 2014-05-23
Syncope MEDIUM 6.5
CVE-2014-0111

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Co…

Fix: 1.0.9 / 1.1.7+
Fix from $1,600 2014-04-17
Roller MEDIUM 6.8
CVE-2013-4212EPSS 81%

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions vi…

Fix: after 5.0.1
Fix from $1,600 2013-12-07
Camel MEDIUM 6.8
CVE-2013-4330EPSS 9%

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expres…

Fix: after 2.9.6
Fix from $1,600 2013-10-04
Struts HIGH 9.3
CVE-2013-2134EPSS 70%

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly …

Fix: 2.3.14.3+
Fix from $1,950 2013-07-16
Struts HIGH 9.3
CVE-2013-2135EPSS 14%

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" an…

Fix: 2.3.14.3+
Fix from $1,950 2013-07-16
Geronimo HIGH 10.0
CVE-2013-1777EPSS 10%

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o…

Patch available
Fix from $1,950 2013-07-11
Struts HIGH 9.3
CVE-2013-1965EPSS 93%

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a cr…

Fix: 2.3.14.1+
Fix from $1,950 2013-07-10
Struts HIGH 9.3
CVE-2013-1966EPSS 72%

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …

Fix: 2.3.14.1+
Fix from $1,950 2013-07-10
Struts HIGH 8.1
CVE-2013-2115EPSS 73%

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …

Fix: after 2.3.14.1
Fix from $1,950 2013-07-10
Struts CRITICAL 9.8
CVE-2012-0391 KEVEPSS 75%

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo…

Fix: 2.2.3.1+
Fix from $2,300 2012-01-08
Struts MEDIUM 6.8
CVE-2012-0394EPSS 74%

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary command…

Fix: after 2.3.17
Fix from $1,600 2012-01-08
Openoffice HIGH 9.3
CVE-2009-3302EPSS 12%

filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execut…

Fix: 3.2.0+
Fix from $1,950 2010-02-16