Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Fineract CRITICAL 9.8
CVE-2018-1290

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para…

Mitigation only
Fix from $2,300 2018-04-20
Fineract HIGH 8.8
CVE-2018-1289

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain…

Mitigation only
Fix from $1,950 2018-04-20
Fineract HIGH 8.1
CVE-2018-1291

Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with …

Mitigation only
Fix from $1,950 2018-04-20
Fineract HIGH 8.1
CVE-2018-1292

Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u…

Mitigation only
Fix from $1,950 2018-04-20
HTTP Server CRITICAL 9.8
CVE-2018-1312EPSS 16%

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…

Mitigation only
Fix from $2,300 2018-03-26
HTTP Server HIGH 7.5
CVE-2017-15710EPSS 18%

In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La…

No fix yet
Fix from $1,950 2018-03-26
Juddi MEDIUM 6.5
CVE-2009-4267

The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows p…

Mitigation only
Fix from $1,600 2018-02-19
Oozie MEDIUM 6.5
CVE-2017-15712

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici…

Mitigation only
Fix from $1,600 2018-02-19
Jmeter CRITICAL 9.8
CVE-2018-1287

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an at…

Mitigation only
Fix from $2,300 2018-02-14
Jmeter CRITICAL 9.8
CVE-2018-1297EPSS 10%

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …

Mitigation only
Fix from $2,300 2018-02-13
Couchdb HIGH 7.8
CVE-2016-8742

The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…

No fix yet
Fix from $1,950 2018-02-12
Qpid Broker J MEDIUM 5.9
CVE-2018-1298

A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, …

Mitigation only
Fix from $1,600 2018-02-09
Hadoop CRITICAL 9.8
CVE-2017-15718

The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Application…

Mitigation only
Fix from $2,300 2018-01-24
Sling Jcr Contentloader HIGH 7.5
CVE-2012-3353

The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con…

Mitigation only
Fix from $1,950 2018-01-09
Ofbiz CRITICAL 9.8
CVE-2017-15714

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code …

No fix yet
Fix from $2,300 2018-01-04
Sling Authentication Service HIGH 8.8
CVE-2017-15700

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the…

Mitigation only
Fix from $1,950 2017-12-18
Fineract HIGH 8.8
CVE-2017-5663

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissio…

Mitigation only
Fix from $1,950 2017-12-14
Synapse CRITICAL 9.8
CVE-2017-15708EPSS 18%

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases…

Mitigation only
Fix from $2,300 2017-12-11
Hadoop HIGH 7.8
CVE-2017-3166

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl…

Mitigation only
Fix from $1,950 2017-11-13
Juddi MEDIUM 5.3
CVE-2009-1197

Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.

Mitigation only
Fix from $1,600 2017-10-30
Traffic Server CRITICAL 9.8
CVE-2015-3249EPSS 5%

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…

Mitigation only
Fix from $2,300 2017-10-30
Struts HIGH 8.8
CVE-2016-3090EPSS 6%

The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL e…

Mitigation only
Fix from $1,950 2017-10-30
Activemq Apollo CRITICAL 9.8
CVE-2014-3579

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…

Mitigation only
Fix from $2,300 2017-10-27
Activemq CRITICAL 9.8
CVE-2014-3600EPSS 10%

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…

Mitigation only
Fix from $2,300 2017-10-27
Ws Xmlrpc CRITICAL 9.8
CVE-2016-5003EPSS 15%

The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…

No fix yet
Fix from $2,300 2017-10-27
Xml Rpc HIGH 7.8
CVE-2016-5002EPSS 8%

XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co…

Mitigation only
Fix from $1,950 2017-10-27
Ofbiz CRITICAL 9.8
CVE-2012-1622EPSS 5%

Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $2,300 2017-10-26
Nifi CRITICAL 9.8
CVE-2017-5636

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…

Mitigation only
Fix from $2,300 2017-10-19
Nifi HIGH 7.5
CVE-2017-5635

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin…

Mitigation only
Fix from $1,950 2017-10-19
Subversion MEDIUM 6.5
CVE-2016-8734EPSS 6%

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack…

Mitigation only
Fix from $1,600 2017-10-16