Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server HIGH 7.5
CVE-2021-26690EPSS 65%

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, …

Fix: after 2.4.46
Fix from $1,950 2021-06-10
HTTP Server HIGH 7.3
CVE-2020-35452EPSS 53%

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of thi…

Fix: after 2.4.46
Fix from $1,950 2021-06-10
HTTP Server MEDIUM 5.5
CVE-2020-13938EPSS 12%

Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

Fix: 5.10.0+
Fix from $1,600 2021-06-10
HTTP Server MEDIUM 5.3
CVE-2019-17567EPSS 60%

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneli…

Fix: after 2.4.46
Fix from $1,600 2021-06-10
HTTP Server MEDIUM 5.3
CVE-2021-30641EPSS 53%

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

Fix: after 2.4.46
Fix from $1,600 2021-06-10
Apisix Dashboard MEDIUM 5.3
CVE-2021-33190

In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external net…

Mitigation only
Fix from $1,600 2021-06-08
Airflow MEDIUM 5.3
CVE-2021-29621

Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows …

Fix: after 3.2.3
Fix from $1,600 2021-06-07
Dubbo CRITICAL 9.8
CVE-2021-25641EPSS 21%

Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before…

Fix: 2.6.9 / 2.7.8+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30179

Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha…

Fix: 2.6.9 / 2.7.10+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30180EPSS 60%

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the cu…

Fix: 2.7.10+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30181EPSS 61%

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are …

Fix: 2.6.10 / 2.7.10+
Fix from $2,300 2021-06-01
Dubbo MEDIUM 6.1
CVE-2021-25640

In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…

Fix: 2.6.9 / 2.7.9+
Fix from $1,600 2021-06-01
Fineract HIGH 7.4
CVE-2020-17514

Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a ma…

Fix: 1.5.0+
Fix from $1,950 2021-05-27
Pulsar CRITICAL 9.8
CVE-2021-22160EPSS 53%

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if th…

Fix: 2.7.1+
Fix from $2,300 2021-05-26
Wicket HIGH 7.5
CVE-2021-23937

A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups fro…

Fix: after 9.2.0
Fix from $1,950 2021-05-25
Traffic Server HIGH 7.5
CVE-2021-27737

Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

No fix yet
Fix from $1,950 2021-05-14
Unomi HIGH 7.5
CVE-2021-31164

Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

Fix: 1.5.5+
Fix from $1,950 2021-05-04
Airflow MEDIUM 6.1
CVE-2021-28359EPSS 14%

The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.1…

Fix: 1.10.15 / 2.0.2+
Fix from $1,600 2021-05-02
Ofbiz CRITICAL 9.8
CVE-2021-29200EPSS 55%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Ofbiz CRITICAL 9.8
CVE-2021-30128EPSS 81%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Tapestry HIGH 7.5
CVE-2021-30638EPSS 7%

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia…

Fix: 5.6.4 / 5.7.2+
Fix from $1,950 2021-04-27
Superset MEDIUM 6.1
CVE-2021-28125EPSS 64%

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open re…

Fix: after 1.0.1
Fix from $1,600 2021-04-27
Ozone HIGH 7.5
CVE-2020-17517

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allo…

Fix: 1.1.0+
Fix from $1,950 2021-04-27
Maven CRITICAL 9.1
CVE-2021-26291EPSS 9%

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting …

Fix: 1.13.5 / 3.8.1+
Fix from $2,300 2021-04-23
Bookkeeper HIGH 7.1
CVE-2020-23922

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

Fix: after 5.1.4
Fix from $1,950 2021-04-21
Openoffice HIGH 8.8
CVE-2021-30245

The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since abo…

Fix: after 4.1.8
Fix from $1,950 2021-04-15
Tapestry CRITICAL 9.8
CVE-2021-27850EPSS 94%

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…

Fix: 5.6.2 / 5.7.1+
Fix from $2,300 2021-04-15
Solr CRITICAL 9.8
CVE-2021-27905EPSS 93%

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Solr CRITICAL 9.1
CVE-2021-29943EPSS 5%

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usi…

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Solr HIGH 7.5
CVE-2021-29262EPSS 8%

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing…

Fix: 8.8.2+
Fix from $1,950 2021-04-13