Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-34486 KEVEPSS 83% Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. … Tomcat Mitigation only Fix from $1,9502026-04-09 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2025-24813 KEVEPSS 100% Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade… Tomcat 9.0.99 / 10.1.35+ Fix from $2,3002025-03-10 HIGH 7.5 CVE-2024-45195 KEVEPSS 100% Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrad… Ofbiz 18.12.16+ Fix from $1,9502024-09-04 CRITICAL 9.8 CVE-2024-38856 KEVEPSS 99% Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi… Ofbiz 18.12.15+ Fix from $2,3002024-08-05 CRITICAL 9.1 CVE-2024-38475 KEVEPSS 100% Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p… HTTP Server 2.4.60 / 10.2.1.14-75sv+ Fix from $2,3002024-07-01 CRITICAL 9.8 CVE-2024-32113 KEVEPSS 99% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before … Ofbiz 18.12.13+ Fix from $2,3002024-05-08 CRITICAL 9.8 CVE-2024-27348 KEVEPSS 99% RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & … Hugegraph 1.3.0+ Fix from $2,3002024-04-22 CRITICAL 9.8 CVE-2023-46604 KEVEPSS 100% The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to… Activemq 5.15.16 / 5.16.7+ Fix from $2,3002023-10-27 CRITICAL 9.8 CVE-2023-33246 KEVEPSS 97% For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu… Rocketmq 4.9.6 / 5.1.1+ Fix from $2,3002023-05-24 CRITICAL 9.8 CVE-2023-27524 KEVEPSS 97% Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K… Superset after 2.0.1 Fix from $2,3002023-04-24 HIGH 8.8 CVE-2022-33891 KEVEPSS 93% The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks … Spark after 3.2.1 Fix from $1,9502022-07-18 CRITICAL 9.8 CVE-2022-24706 KEVEPSS 92% In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.… Couchdb 3.2.2+ Fix from $2,3002022-04-26 CRITICAL 9.8 CVE-2022-24112 KEVEPSS 96% An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX … Apisix 2.10.4 / 2.12.1+ Fix from $2,3002022-02-11 CRITICAL 9.0 CVE-2021-45046 KEVEPSS 100% It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at… Log4j 2.12.2 / 2.16.0+ Fix from $2,3002021-12-14 CRITICAL 10.0 CVE-2021-44228 KEVEPSS 100% Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… Log4j 2.1.0 / 2.3.1+ Fix from $2,3002021-12-10 CRITICAL 9.8 CVE-2021-42013 KEVEPSS 100% It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… HTTP Server 9.2.6.0 / 18.1.0.1.0+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-41773 KEVEPSS 100% A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi… HTTP Server Patch available Fix from $2,3002021-10-05 HIGH 7.8 CVE-2021-21315 KEVEPSS 91% The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… Cordova 5.3.1+ Fix from $1,9502021-02-16 HIGH 7.5 CVE-2020-17519 KEVEPSS 98% A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t… Flink 1.11.3+ Fix from $1,9502021-01-05 CRITICAL 9.8 CVE-2020-17530 KEVEPSS 96% Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.… Struts 2.5.30+ Fix from $2,3002020-12-11 CRITICAL 9.8 CVE-2020-13927 KEVEPSS 100% The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us… Airflow 1.10.11+ Fix from $2,3002020-11-10 HIGH 8.8 CVE-2020-11978 KEVEPSS 99% An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D… Airflow 1.10.11+ Fix from $1,9502020-07-17 HIGH 8.8 CVE-2020-1956 KEVEPSS 97% Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is … Kylin after 2.6.5 Fix from $1,9502020-05-22 CRITICAL 9.8 CVE-2020-1938 KEVEPSS 99% When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as … Geode 7.0.100 / 8.5.51+ Fix from $2,3002020-02-24 HIGH 7.5 CVE-2019-17558 KEVEPSS 99% Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi… Solr 7.7.3 / 8.4.0+ Fix from $1,9502019-12-30 HIGH 7.2 CVE-2019-0193 KEVEPSS 84% In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh… Solr 7.7.3 / 8.1.2+ Fix from $1,9502019-08-01 HIGH 7.8 CVE-2019-0211 KEVEPSS 65% In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads … HTTP Server after 2.4.38 Fix from $1,9502019-04-08 HIGH 8.1 CVE-2018-11776 KEVEPSS 100% Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by u… Struts 2.3.35 / 2.5.17+ Fix from $1,9502018-08-22 HIGH 8.1 CVE-2017-12617 KEVEPSS 100% When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett… Tomcat 7.0.82 / 8.0.47+ Fix from $1,9502017-10-04