Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kylin HIGH 7.5
CVE-2021-45458

Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by thi…

Fix: 3.1.3+
Fix from $1,950 2022-01-06
Kylin MEDIUM 6.5
CVE-2021-36774

Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmi…

Fix: after 3.1.2
Fix from $1,600 2022-01-06
Kylin HIGH 7.5
CVE-2021-27738

All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se…

Fix: 3.1.2+
Fix from $1,950 2022-01-06
Pluto MEDIUM 6.1
CVE-2021-36737

The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of th…

Fix: 3.1.1+
Fix from $1,600 2022-01-06
Pluto MEDIUM 6.1
CVE-2021-36738

The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users sho…

Fix: 3.1.1+
Fix from $1,600 2022-01-06
Pluto MEDIUM 6.1
CVE-2021-36739

The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) at…

Mitigation only
Fix from $1,600 2022-01-06
James CRITICAL 9.1
CVE-2021-40525

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writ…

Fix: 3.6.2+
Fix from $2,300 2022-01-04
Geode HIGH 7.5
CVE-2021-34797

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with …

Fix: after 1.13.4
Fix from $1,950 2022-01-04
James HIGH 7.5
CVE-2021-40110

In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnera…

Fix: 3.6.1+
Fix from $1,950 2022-01-04
James MEDIUM 6.5
CVE-2021-40111

In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger i…

Fix: 3.6.1+
Fix from $1,600 2022-01-04
James MEDIUM 5.9
CVE-2021-38542

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-mi…

Fix: 3.6.1+
Fix from $1,600 2022-01-04
Log4j MEDIUM 6.6
CVE-2021-44832EPSS 98%

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…

Fix: 2.3.2 / 2.12.4+
Fix from $1,600 2021-12-28
Apisix Dashboard CRITICAL 9.8
CVE-2021-45232EPSS 86%

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all…

Fix: 2.10.1+
Fix from $2,300 2021-12-27
Solr CRITICAL 9.8
CVE-2021-44548EPSS 5%

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…

Fix: 8.11.1+
Fix from $2,300 2021-12-23
HTTP Server CRITICAL 9.8
CVE-2021-44790EPSS 97%

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache http…

Fix: 2.4.52 / 5.20.0+
Fix from $2,300 2021-12-20
HTTP Server HIGH 8.2
CVE-2021-44224EPSS 82%

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixi…

Fix: 2.4.52 / 5.20.0+
Fix from $1,950 2021-12-20
Parquet Java HIGH 7.5
CVE-2021-41561

Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apac…

Fix: 1.11.2 / 1.12.2+
Fix from $1,950 2021-12-20
Plc4x HIGH 8.8
CVE-2021-43083

Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport.…

Fix: 0.9.1+
Fix from $1,950 2021-12-19
Log4j MEDIUM 5.9
CVE-2021-45105EPSS 100%

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential looku…

Fix: 2.3.1 / 2.7.0+
Fix from $1,600 2021-12-18
Nifi MEDIUM 6.5
CVE-2021-44145

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious externa…

Fix: 1.15.1+
Fix from $1,600 2021-12-17
Log4j CRITICAL 9.0
CVE-2021-45046 KEVEPSS 100%

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at…

Fix: 2.12.2 / 2.16.0+
Fix from $2,300 2021-12-14
Sling Commons Messaging Mail HIGH 7.4
CVE-2021-44549

Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "…

Mitigation only
Fix from $1,950 2021-12-14
Log4j HIGH 7.5
CVE-2021-4104EPSS 81%

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack…

Patch available
Fix from $1,950 2021-12-14
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Airavata Django Portal MEDIUM 5.3
CVE-2021-43410

Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are l…

Fix: 2021-12-06+
Fix from $1,600 2021-12-09
Jspwiki CRITICAL 9.1
CVE-2021-44140EPSS 6%

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…

Fix: 2.11.0+
Fix from $2,300 2021-11-24
Jspwiki MEDIUM 6.1
CVE-2021-40369

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow th…

Fix: 2.11.0+
Fix from $1,600 2021-11-24
Apisix HIGH 7.5
CVE-2021-43557EPSS 15%

The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without…

Fix: 2.10.2+
Fix from $1,950 2021-11-22
Ozone CRITICAL 9.1
CVE-2021-39231

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Ozone CRITICAL 9.1
CVE-2021-39233

In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any …

Fix: 1.2.0+
Fix from $2,300 2021-11-19