Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openoffice HIGH 7.8
CVE-2021-28129

While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi…

Mitigation only
Fix from $1,950 2021-10-07
HTTP Server CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…

Patch available
Fix from $2,300 2021-10-05
HTTP Server HIGH 7.5
CVE-2021-41524EPSS 25%

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the …

Patch available
Fix from $1,950 2021-10-05
Ddlutils CRITICAL 9.8
CVE-2021-41616

Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…

Mitigation only
Fix from $2,300 2021-09-30
Druid MEDIUM 6.5
CVE-2021-36749EPSS 81%

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…

Fix: 0.22.0+
Fix from $1,600 2021-09-24
Openoffice HIGH 7.8
CVE-2021-33035EPSS 51%

Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When readin…

Fix: after 4.1.10
Fix from $1,950 2021-09-23
Kafka MEDIUM 5.9
CVE-2021-38153EPSS 6%

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attack…

Fix: 2.2.4 / 2.6.3+
Fix from $1,600 2021-09-22
Santuario Xml Security For Java HIGH 7.5
CVE-2021-40690EPSS 7%

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is…

Fix: 2.1.7 / 2.2.3+
Fix from $1,950 2021-09-19
Shiro CRITICAL 9.8
CVE-2021-41303EPSS 77%

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…

Fix: 1.8.0+
Fix from $2,300 2021-09-17
HTTP Server CRITICAL 9.8
CVE-2021-39275EPSS 39%

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but t…

Fix: 2.4.49+
Fix from $2,300 2021-09-16
HTTP Server HIGH 7.5
CVE-2021-34798EPSS 65%

Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.

Fix: after 5.19.1
Fix from $1,950 2021-09-16
HTTP Server HIGH 7.5
CVE-2021-36160EPSS 63%

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Ser…

Fix: 2.4.49+
Fix from $1,950 2021-09-16
Jena HIGH 7.5
CVE-2021-39239

A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex…

Fix: after 4.1.0
Fix from $1,950 2021-09-16
Tomcat HIGH 7.5
CVE-2021-41079EPSS 7%

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured …

Fix: 8.5.64 / 9.0.44+
Fix from $1,950 2021-09-16
Any23 CRITICAL 9.8
CVE-2021-40146EPSS 6%

A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vuln…

Fix: 2.5+
Fix from $2,300 2021-09-11
Any23 CRITICAL 9.1
CVE-2021-38555

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…

Fix: 2.5+
Fix from $2,300 2021-09-11
Airflow CRITICAL 9.8
CVE-2021-38540EPSS 81%

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …

Fix: 2.1.3+
Fix from $2,300 2021-09-09
Dubbo CRITICAL 9.8
CVE-2021-37579EPSS 7%

The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…

Fix: 2.7.13 / 3.0.2+
Fix from $2,300 2021-09-09
Dubbo CRITICAL 9.8
CVE-2021-36161

Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean…

Fix: 2.7.13+
Fix from $2,300 2021-09-09
Dubbo CRITICAL 9.8
CVE-2021-36163

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…

Fix: after 3.0.1
Fix from $2,300 2021-09-07
Dubbo HIGH 8.8
CVE-2021-36162

Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the c…

Fix: after 3.0.1
Fix from $1,950 2021-09-07
Zeppelin MEDIUM 6.1
CVE-2021-27578

Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apac…

Fix: 0.9.0+
Fix from $1,600 2021-09-02
Zeppelin CRITICAL 9.8
CVE-2019-10095EPSS 6%

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe…

Fix: after 0.9.0
Fix from $2,300 2021-09-02
Zeppelin HIGH 7.5
CVE-2020-13929

Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This is…

Fix: after 0.9.0
Fix from $1,950 2021-09-02
Ofbiz HIGH 7.5
CVE-2021-25958

In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table…

Fix: 17.12.08+
Fix from $1,950 2021-08-30
Nifi Minifi C\+\+ CRITICAL 9.8
CVE-2021-33191

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th…

Fix: 0.10.0+
Fix from $2,300 2021-08-24
Portable Runtime HIGH 7.1
CVE-2021-35940

An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for thi…

Patch available
Fix from $1,950 2021-08-23
Ofbiz CRITICAL 9.8
CVE-2021-37608EPSS 6%

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach…

Fix: 17.12.08+
Fix from $2,300 2021-08-18
Roller HIGH 7.5
CVE-2021-33580

User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression…

Fix: 6.0.2+
Fix from $1,950 2021-08-18
Airflow MEDIUM 5.3
CVE-2021-35936

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…

Fix: 2.1.2+
Fix from $1,600 2021-08-16