Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Geode HIGH 7.4
CVE-2019-10091

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c…

Mitigation only
Fix from $1,950 2020-03-16
Commons Configuration CRITICAL 10.0
CVE-2020-1953EPSS 7%

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…

Mitigation only
Fix from $2,300 2020-03-13
Shardingsphere CRITICAL 9.8
CVE-2020-1947EPSS 34%

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …

Mitigation only
Fix from $2,300 2020-03-11
Superset MEDIUM 6.5
CVE-2020-1932

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retr…

Mitigation only
Fix from $1,600 2020-01-28
Nifi MEDIUM 5.3
CVE-2020-1928

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose…

Mitigation only
Fix from $1,600 2020-01-28
Qpid Cpp HIGH 7.5
CVE-2014-0212

qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors

Mitigation only
Fix from $1,950 2019-12-13
Struts HIGH 8.8
CVE-2012-1592EPSS 29%

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit…

Mitigation only
Fix from $1,950 2019-12-05
Openoffice HIGH 7.8
CVE-2011-2177

OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.

Mitigation only
Fix from $1,950 2019-11-27
Solr CRITICAL 9.8
CVE-2019-12409EPSS 22%

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…

No fix yet
Fix from $2,300 2019-11-18
Atlas MEDIUM 6.1
CVE-2019-10070

Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

Mitigation only
Fix from $1,600 2019-11-18
Qpid Cpp MEDIUM 6.5
CVE-2009-5004

qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

Mitigation only
Fix from $1,600 2019-11-09
Hadoop HIGH 7.5
CVE-2012-2945

Hadoop 1.0.3 contains a symlink vulnerability.

No fix yet
Fix from $1,950 2019-10-29
Mina HIGH 7.5
CVE-2019-0231

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the cl…

Mitigation only
Fix from $1,950 2019-10-01
Traffic Control CRITICAL 9.8
CVE-2019-12405

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…

Mitigation only
Fix from $2,300 2019-09-09
Roller MEDIUM 6.1
CVE-2019-0234

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu…

Mitigation only
Fix from $1,600 2019-07-15
Commons Imaging HIGH 7.5
CVE-2018-17201

Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note th…

Mitigation only
Fix from $1,950 2019-05-06
Commons Imaging HIGH 7.5
CVE-2018-17202

Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be use…

Mitigation only
Fix from $1,950 2019-05-06
Pluto MEDIUM 6.1
CVE-2019-0186EPSS 21%

The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uni…

No fix yet
Fix from $1,600 2019-04-26
Pdfbox CRITICAL 9.8
CVE-2019-0228EPSS 9%

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…

Mitigation only
Fix from $2,300 2019-04-17
HTTP Server HIGH 7.5
CVE-2019-0215EPSS 11%

In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a…

Mitigation only
Fix from $1,950 2019-04-08
Jmeter CRITICAL 9.8
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a…

Mitigation only
Fix from $2,300 2019-03-06
HTTP Server HIGH 7.5
CVE-2019-0190EPSS 59%

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to e…

Mitigation only
Fix from $1,950 2019-01-30
HTTP Server MEDIUM 5.3
CVE-2018-17189EPSS 20%

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unn…

Mitigation only
Fix from $1,600 2019-01-30
Netbeans CRITICAL 9.8
CVE-2018-17191EPSS 8%

Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the n…

Mitigation only
Fix from $2,300 2018-12-31
Spark CRITICAL 9.8
CVE-2018-17190EPSS 9%

In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos…

Mitigation only
Fix from $2,300 2018-11-19
Couchdb HIGH 7.8
CVE-2018-14889

CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.

Mitigation only
Fix from $1,950 2018-09-21
HTTP Server MEDIUM 6.1
CVE-2016-4975EPSS 20%

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 …

Mitigation only
Fix from $1,600 2018-08-14
HTTP Server HIGH 7.5
CVE-2018-8011EPSS 56%

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This coul…

Mitigation only
Fix from $1,950 2018-07-18
Pluto HIGH 7.5
CVE-2018-1306EPSS 44%

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive i…

No fix yet
Fix from $1,950 2018-06-27
Openoffice HIGH 7.5
CVE-2018-10583EPSS 79%

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co…

No fix yet
Fix from $1,950 2018-05-01