Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ofbiz HIGH 7.5
CVE-2022-29158

Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, un…

Fix: 18.12.06+
Fix from $1,950 2022-09-02
Ofbiz MEDIUM 5.4
CVE-2022-25370

Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.…

Fix: 18.12.06+
Fix from $1,600 2022-09-02
Shenyu HIGH 8.8
CVE-2022-37435

Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This i…

Patch available
Fix from $1,950 2022-09-01
Geode CRITICAL 9.8
CVE-2022-37021

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A…

Fix: after 1.13.4
Fix from $2,300 2022-08-31
Geode HIGH 8.8
CVE-2022-37022

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user…

Fix: after 1.13.2
Fix from $1,950 2022-08-31
Geode MEDIUM 6.5
CVE-2022-37023

Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user w…

Fix: 1.15.0+
Fix from $1,600 2022-08-31
Libapreq2 HIGH 7.5
CVE-2022-22728

A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could s…

Fix: after 2.16
Fix from $1,950 2022-08-25
Hadoop HIGH 8.8
CVE-2021-25642

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation…

Fix: 2.10.2 / 3.2.4+
Fix from $1,950 2022-08-25
Artemis MEDIUM 6.1
CVE-2022-35278

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by u…

Fix: 2.24.0+
Fix from $1,600 2022-08-23
Flume CRITICAL 9.8
CVE-2022-34916

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI …

Fix: 1.10.1+
Fix from $2,300 2022-08-21
Apache Airflow Providers Docker HIGH 8.8
CVE-2022-38362

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the…

Fix: 3.0.0+
Fix from $1,950 2022-08-16
Openoffice HIGH 8.8
CVE-2022-37401

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with…

Fix: 4.1.13+
Fix from $1,950 2022-08-15
Openoffice HIGH 8.8
CVE-2022-37400

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with…

Fix: 4.1.13+
Fix from $1,950 2022-08-15
Traffic Server HIGH 7.5
CVE-2021-37150

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-25763

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison at…

Fix: 8.1.5 / 9.1.3+
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-28129

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue af…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31778

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. Thi…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31779

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects …

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31780

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects …

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Avro HIGH 7.5
CVE-2022-35724

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Avro HIGH 7.5
CVE-2022-36124

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust ap…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Avro HIGH 7.5
CVE-2022-36125

It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust …

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Hadoop CRITICAL 9.8
CVE-2022-25168

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary…

Fix: after 3.3.2
Fix from $2,300 2022-08-04
Jspwiki HIGH 8.8
CVE-2022-34158

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri…

Fix: 2.11.3+
Fix from $1,950 2022-08-04
Jspwiki MEDIUM 6.5
CVE-2022-28731EPSS 57%

A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacke…

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Jspwiki MEDIUM 6.1
CVE-2022-27166EPSS 85%

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow …

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Jspwiki MEDIUM 6.1
CVE-2022-28730EPSS 85%

A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javasc…

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Jspwiki MEDIUM 6.1
CVE-2022-28732EPSS 82%

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascrip…

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Apache Calcite Avatica HIGH 8.8
CVE-2022-36364

Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, th…

Fix: 1.22.0+
Fix from $1,950 2022-07-28
Mxnet HIGH 7.5
CVE-2022-24294

A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul…

Fix: 1.9.1+
Fix from $1,950 2022-07-24