Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xalan Java HIGH 7.5
CVE-2022-34169EPSS 81%

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corru…

Fix: after 17.0.3
Fix from $1,950 2022-07-19
Cloudstack CRITICAL 9.8
CVE-2022-35741EPSS 8%

Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entit…

Fix: 4.16.1.1+
Fix from $2,300 2022-07-18
Skywalking Nodejs Agent HIGH 7.5
CVE-2022-36127

A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be un…

Fix: 0.5.1+
Fix from $1,950 2022-07-18
Spark HIGH 8.8
CVE-2022-33891 KEVEPSS 93%

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks …

Fix: after 3.2.1
Fix from $1,950 2022-07-18
Hive HIGH 7.5
CVE-2021-34538

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was…

Fix: 3.1.3+
Fix from $1,950 2022-07-16
Tapestry HIGH 7.5
CVE-2022-31781

Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially craf…

Fix: 5.8.2+
Fix from $1,950 2022-07-13
Druid MEDIUM 6.1
CVE-2021-44791

In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes …

Fix: after 0.22.1
Fix from $1,600 2022-07-07
Commons Configuration CRITICAL 9.8
CVE-2022-33980EPSS 43%

Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for i…

Fix: 2.8+
Fix from $2,300 2022-07-06
Jetspeed CRITICAL 9.8
CVE-2022-32533

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…

Mitigation only
Fix from $2,300 2022-07-06
Shiro CRITICAL 9.8
CVE-2022-32532EPSS 26%

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…

Fix: 1.9.1+
Fix from $2,300 2022-06-29
Systemds HIGH 7.5
CVE-2022-26477

The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered wi…

Fix: after 2.2.1
Fix from $1,950 2022-06-27
Tomcat MEDIUM 6.1
CVE-2022-34305EPSS 7%

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples…

Fix: after 10.0.22
Fix from $1,600 2022-06-23
Sling Api MEDIUM 5.3
CVE-2022-32549

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to …

Fix: after 5.4.0
Fix from $1,600 2022-06-22
Nifi HIGH 8.8
CVE-2022-33140

The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group …

Fix: after 1.16.2
Fix from $1,950 2022-06-15
Hadoop HIGH 8.8
CVE-2021-33036

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar…

Fix: 2.10.2 / 3.2.3+
Fix from $1,950 2022-06-15
Flume CRITICAL 9.8
CVE-2022-25167

Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…

Fix: 1.10.0+
Fix from $2,300 2022-06-14
Hadoop CRITICAL 9.8
CVE-2021-37404

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in…

Fix: 2.10.2 / 3.2.3+
Fix from $2,300 2022-06-13
HTTP Server CRITICAL 9.8
CVE-2022-31813

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop m…

Fix: 2.4.54+
Fix from $2,300 2022-06-09
HTTP Server CRITICAL 9.1
CVE-2022-28615EPSS 6%

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extrem…

Fix: 2.4.54+
Fix from $2,300 2022-06-09
HTTP Server HIGH 7.5
CVE-2022-26377EPSS 20%

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to sm…

Fix: 2.4.54+
Fix from $1,950 2022-06-09
HTTP Server HIGH 7.5
CVE-2022-29404EPSS 6%

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no defau…

Fix: after 2.4.53
Fix from $1,950 2022-06-09
HTTP Server HIGH 7.5
CVE-2022-30522EPSS 90%

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m…

Mitigation only
Fix from $1,950 2022-06-09
HTTP Server HIGH 7.5
CVE-2022-30556

Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the …

Fix: 2.4.54+
Fix from $1,950 2022-06-09
HTTP Server MEDIUM 5.3
CVE-2022-28330

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

Fix: after 2.4.53
Fix from $1,600 2022-06-09
HTTP Server MEDIUM 5.3
CVE-2022-28614

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very larg…

Fix: after 2.4.53
Fix from $1,600 2022-06-09
Dubbo MEDIUM 6.1
CVE-2022-24969

bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…

Fix: 2.6.12 / 2.7.15+
Fix from $1,600 2022-06-09
Tika MEDIUM 5.5
CVE-2022-30973

We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText clas…

Fix: 1.28.3+
Fix from $1,600 2022-05-31
Archiva MEDIUM 6.5
CVE-2022-29405

In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8

Fix: 2.2.8+
Fix from $1,600 2022-05-25
Maven Shared Utils CRITICAL 9.8
CVE-2022-29599

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing she…

Fix: 3.3.3+
Fix from $2,300 2022-05-23
Shenyu HIGH 7.5
CVE-2022-26650

In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where …

Patch available
Fix from $1,950 2022-05-17