Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tika MEDIUM 5.5
CVE-2022-25169

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

Fix: 1.28.2 / 2.4.0+
Fix from $1,600 2022-05-16
Tika MEDIUM 5.5
CVE-2022-30126

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caus…

Fix: 1.28.3 / 2.4.0+
Fix from $1,600 2022-05-16
Tomcat HIGH 8.6
CVE-2022-25762EPSS 8%

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Ap…

Fix: 8.5.76 / 9.0.21+
Fix from $1,950 2022-05-13
Tomcat HIGH 7.5
CVE-2022-29885EPSS 73%

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor in…

Fix: after 10.0.20
Fix from $1,950 2022-05-12
Jena CRITICAL 9.8
CVE-2022-28890

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…

Mitigation only
Fix from $2,300 2022-05-05
Nifi HIGH 7.5
CVE-2022-29265

Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content …

Fix: after 1.16.0
Fix from $1,950 2022-04-30
Doris HIGH 7.5
CVE-2022-23942

Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

Fix: 1.0.0+
Fix from $1,950 2022-04-26
Couchdb CRITICAL 9.8
CVE-2022-24706 KEVEPSS 92%

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.…

Fix: 3.2.2+
Fix from $2,300 2022-04-26
Apisix HIGH 7.5
CVE-2022-29266EPSS 8%

In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the…

Fix: 2.13.1+
Fix from $1,950 2022-04-20
Superset CRITICAL 9.8
CVE-2022-27479

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

Fix: 1.4.2+
Fix from $2,300 2022-04-13
Subversion HIGH 7.5
CVE-2022-24070EPSS 9%

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use …

Fix: 1.10.8 / 1.14.2+
Fix from $1,950 2022-04-12
Struts CRITICAL 9.8
CVE-2021-31805EPSS 85%

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double ev…

Fix: after 2.5.29
Fix from $2,300 2022-04-12
Hadoop CRITICAL 9.8
CVE-2022-26612

In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR …

Fix: 3.2.3+
Fix from $2,300 2022-04-07
Pinot HIGH 7.5
CVE-2022-23974

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations t…

Fix: 0.10.0+
Fix from $1,950 2022-04-05
Dolphinscheduler HIGH 7.5
CVE-2022-25598

Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should up…

Fix: 2.0.5+
Fix from $1,950 2022-03-30
Apisix CRITICAL 9.8
CVE-2022-25757

In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…

Fix: 2.13.0+
Fix from $2,300 2022-03-28
Traffic Server HIGH 8.1
CVE-2021-44759

Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This…

Fix: after 8.1.0
Fix from $1,950 2022-03-23
Traffic Server HIGH 7.5
CVE-2021-44040

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affe…

Fix: after 9.1.1
Fix from $1,950 2022-03-23
Cloudstack HIGH 7.5
CVE-2022-26779

Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only o…

Fix: 4.16.1.0+
Fix from $1,950 2022-03-15
HTTP Server CRITICAL 9.8
CVE-2022-22720EPSS 28%

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server …

Fix: 10.15.7 / 11.6.6+
Fix from $2,300 2022-03-14
HTTP Server CRITICAL 9.8
CVE-2022-23943EPSS 50%

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. …

Fix: 2.4.53+
Fix from $2,300 2022-03-14
HTTP Server CRITICAL 9.1
CVE-2022-22721EPSS 42%

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later ca…

Fix: 10.15.7 / 11.6.6+
Fix from $2,300 2022-03-14
HTTP Server HIGH 7.5
CVE-2022-22719EPSS 70%

A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Serv…

Fix: 10.15.7 / 11.6.6+
Fix from $1,950 2022-03-14
Spark HIGH 7.5
CVE-2021-38296

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and ear…

Fix: 3.1.3+
Fix from $1,950 2022-03-10
Any23 CRITICAL 9.1
CVE-2022-25312

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions …

Fix: 2.7+
Fix from $2,300 2022-03-05
Poi MEDIUM 5.5
CVE-2022-26336

A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read…

Fix: 5.2.1+
Fix from $1,600 2022-03-04
Jspwiki HIGH 8.8
CVE-2022-24947

Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2…

Fix: 2.11.2+
Fix from $1,950 2022-02-25
Jspwiki MEDIUM 6.1
CVE-2022-24948

A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, whi…

Fix: 2.11.2+
Fix from $1,600 2022-02-25
Airflow HIGH 8.8
CVE-2022-24288EPSS 78%

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command In…

Fix: 2.2.4+
Fix from $1,950 2022-02-25
Airflow MEDIUM 6.1
CVE-2021-45229

It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache…

Fix: after 2.2.3
Fix from $1,600 2022-02-25