Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-1290 In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para… Fineract Mitigation only Fix from $2,3002018-04-20 HIGH 8.8 CVE-2018-1289 In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain… Fineract Mitigation only Fix from $1,9502018-04-20 HIGH 8.1 CVE-2018-1291 Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with … Fineract Mitigation only Fix from $1,9502018-04-20 HIGH 8.1 CVE-2018-1292 Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u… Fineract Mitigation only Fix from $1,9502018-04-20 CRITICAL 9.8 CVE-2018-1312EPSS 16% In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g… HTTP Server Mitigation only Fix from $2,3002018-03-26 HIGH 7.5 CVE-2017-15710EPSS 18% In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La… HTTP Server No fix yet Fix from $1,9502018-03-26 MEDIUM 6.5 CVE-2009-4267 The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows p… Juddi Mitigation only Fix from $1,6002018-02-19 MEDIUM 6.5 CVE-2017-15712 Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici… Oozie Mitigation only Fix from $1,6002018-02-19 CRITICAL 9.8 CVE-2018-1287 In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an at… Jmeter Mitigation only Fix from $2,3002018-02-14 CRITICAL 9.8 CVE-2018-1297EPSS 10% When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access … Jmeter Mitigation only Fix from $2,3002018-02-13 HIGH 7.8 CVE-2016-8742 The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p… Couchdb No fix yet Fix from $1,9502018-02-12 MEDIUM 5.9 CVE-2018-1298 A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, … Qpid Broker J Mitigation only Fix from $1,6002018-02-09 CRITICAL 9.8 CVE-2017-15718 The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Application… Hadoop Mitigation only Fix from $2,3002018-01-24 HIGH 7.5 CVE-2012-3353 The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con… Sling Jcr Contentloader Mitigation only Fix from $1,9502018-01-09 CRITICAL 9.8 CVE-2017-15714 The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code … Ofbiz No fix yet Fix from $2,3002018-01-04 HIGH 8.8 CVE-2017-15700 A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the… Sling Authentication Service Mitigation only Fix from $1,9502017-12-18 HIGH 8.8 CVE-2017-5663 In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissio… Fineract Mitigation only Fix from $1,9502017-12-14 CRITICAL 9.8 CVE-2017-15708EPSS 18% In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases… Synapse Mitigation only Fix from $2,3002017-12-11 HIGH 7.8 CVE-2017-3166 In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl… Hadoop Mitigation only Fix from $1,9502017-11-13 MEDIUM 5.3 CVE-2009-1197 Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp. Juddi Mitigation only Fix from $1,6002017-10-30 CRITICAL 9.8 CVE-2015-3249EPSS 5% The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces… Traffic Server Mitigation only Fix from $2,3002017-10-30 HIGH 8.8 CVE-2016-3090EPSS 6% The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL e… Struts Mitigation only Fix from $1,9502017-10-30 CRITICAL 9.8 CVE-2014-3579 XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv… Activemq Apollo Mitigation only Fix from $2,3002017-10-27 CRITICAL 9.8 CVE-2014-3600EPSS 10% XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving… Activemq Mitigation only Fix from $2,3002017-10-27 CRITICAL 9.8 CVE-2016-5003EPSS 15% The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ… Ws Xmlrpc No fix yet Fix from $2,3002017-10-27 HIGH 7.8 CVE-2016-5002EPSS 8% XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co… Xml Rpc Mitigation only Fix from $1,9502017-10-27 CRITICAL 9.8 CVE-2012-1622EPSS 5% Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors. Ofbiz Mitigation only Fix from $2,3002017-10-26 CRITICAL 9.8 CVE-2017-5636 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio… Nifi Mitigation only Fix from $2,3002017-10-19 HIGH 7.5 CVE-2017-5635 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin… Nifi Mitigation only Fix from $1,9502017-10-19 MEDIUM 6.5 CVE-2016-8734EPSS 6% Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack… Subversion Mitigation only Fix from $1,6002017-10-16