Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2019-10091 When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c… Geode Mitigation only Fix from $1,9502020-03-16 CRITICAL 10.0 CVE-2020-1953EPSS 7% Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes… Commons Configuration Mitigation only Fix from $2,3002020-03-13 CRITICAL 9.8 CVE-2020-1947EPSS 34% In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load … Shardingsphere Mitigation only Fix from $2,3002020-03-11 MEDIUM 6.5 CVE-2020-1932 An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retr… Superset Mitigation only Fix from $1,6002020-01-28 MEDIUM 5.3 CVE-2020-1928 An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose… Nifi Mitigation only Fix from $1,6002020-01-28 HIGH 7.5 CVE-2014-0212 qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors Qpid Cpp Mitigation only Fix from $1,9502019-12-13 HIGH 8.8 CVE-2012-1592EPSS 29% A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit… Struts Mitigation only Fix from $1,9502019-12-05 HIGH 7.8 CVE-2011-2177 OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools. Openoffice Mitigation only Fix from $1,9502019-11-27 CRITICAL 9.8 CVE-2019-12409EPSS 22% The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh… Solr No fix yet Fix from $2,3002019-11-18 MEDIUM 6.1 CVE-2019-10070 Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality Atlas Mitigation only Fix from $1,6002019-11-18 MEDIUM 6.5 CVE-2009-5004 qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use . Qpid Cpp Mitigation only Fix from $1,6002019-11-09 HIGH 7.5 CVE-2012-2945 Hadoop 1.0.3 contains a symlink vulnerability. Hadoop No fix yet Fix from $1,9502019-10-29 HIGH 7.5 CVE-2019-0231 Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the cl… Mina Mitigation only Fix from $1,9502019-10-01 CRITICAL 9.8 CVE-2019-12405 Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.… Traffic Control Mitigation only Fix from $2,3002019-09-09 MEDIUM 6.1 CVE-2019-0234 A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu… Roller Mitigation only Fix from $1,6002019-07-15 HIGH 7.5 CVE-2018-17201 Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note th… Commons Imaging Mitigation only Fix from $1,9502019-05-06 HIGH 7.5 CVE-2018-17202 Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be use… Commons Imaging Mitigation only Fix from $1,9502019-05-06 MEDIUM 6.1 CVE-2019-0186EPSS 21% The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uni… Pluto No fix yet Fix from $1,6002019-04-26 CRITICAL 9.8 CVE-2019-0228EPSS 9% Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac… Pdfbox Mitigation only Fix from $2,3002019-04-17 HIGH 7.5 CVE-2019-0215EPSS 11% In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a… HTTP Server Mitigation only Fix from $1,9502019-04-08 CRITICAL 9.8 CVE-2019-0187 Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a… Jmeter Mitigation only Fix from $2,3002019-03-06 HIGH 7.5 CVE-2019-0190EPSS 59% A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to e… HTTP Server Mitigation only Fix from $1,9502019-01-30 MEDIUM 5.3 CVE-2018-17189EPSS 20% In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unn… HTTP Server Mitigation only Fix from $1,6002019-01-30 CRITICAL 9.8 CVE-2018-17191EPSS 8% Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the n… Netbeans Mitigation only Fix from $2,3002018-12-31 CRITICAL 9.8 CVE-2018-17190EPSS 9% In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos… Spark Mitigation only Fix from $2,3002018-11-19 HIGH 7.8 CVE-2018-14889 CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. Couchdb Mitigation only Fix from $1,9502018-09-21 MEDIUM 6.1 CVE-2016-4975EPSS 20% Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 … HTTP Server Mitigation only Fix from $1,6002018-08-14 HIGH 7.5 CVE-2018-8011EPSS 56% By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This coul… HTTP Server Mitigation only Fix from $1,9502018-07-18 HIGH 7.5 CVE-2018-1306EPSS 44% The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive i… Pluto No fix yet Fix from $1,9502018-06-27 HIGH 7.5 CVE-2018-10583EPSS 79% An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co… Openoffice No fix yet Fix from $1,9502018-05-01