Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cxf HIGH 7.5
CVE-2021-22696EPSS 7%

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…

Fix: 3.3.10 / 3.4.3+
Fix from $1,950 2021-04-02
Tika MEDIUM 5.5
CVE-2021-28657

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade …

Fix: after 17.12
Fix from $1,600 2021-03-31
Druid HIGH 8.8
CVE-2021-26919EPSS 23%

Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissio…

Fix: 0.20.2+
Fix from $1,950 2021-03-30
Spamassassin CRITICAL 9.8
CVE-2020-1946EPSS 6%

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …

Fix: 3.4.5+
Fix from $2,300 2021-03-25
Activemq CRITICAL 9.8
CVE-2021-21347EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21350EPSS 15%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21351EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq HIGH 8.6
CVE-2021-21349EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq HIGH 7.5
CVE-2021-21348EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21344EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21346EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21342EPSS 50%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq HIGH 7.5
CVE-2021-21341EPSS 78%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq HIGH 7.5
CVE-2021-21343EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Ofbiz CRITICAL 9.8
CVE-2021-26295EPSS 98%

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF…

Fix: 17.12.06+
Fix from $2,300 2021-03-22
Pdfbox MEDIUM 5.5
CVE-2021-27807

A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x ver…

Fix: after 14.3.0
Fix from $1,600 2021-03-19
Pdfbox MEDIUM 5.5
CVE-2021-27906

A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2…

Fix: after 2.0.22
Fix from $1,600 2021-03-19
Subversion HIGH 7.5
CVE-2020-17525EPSS 40%

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a c…

Fix: 1.10.7 / 1.14.1+
Fix from $1,950 2021-03-17
Ambari HIGH 7.5
CVE-2020-13924

In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to …

Fix: after 2.6.2.2
Fix from $1,950 2021-03-17
Hive MEDIUM 5.9
CVE-2020-1926

Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow rec…

Fix: 2.3.8+
Fix from $1,600 2021-03-16
Openmeetings HIGH 7.5
CVE-2021-27576

If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache O…

Fix: 6.0.0+
Fix from $1,950 2021-03-15
Velocity Engine HIGH 8.8
CVE-2020-13936EPSS 23%

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as th…

Fix: 2.3+
Fix from $1,950 2021-03-10
Velocity Tools MEDIUM 6.1
CVE-2020-13959EPSS 6%

The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attac…

Fix: 3.1+
Fix from $1,600 2021-03-10
Superset MEDIUM 5.4
CVE-2021-27907EPSS 86%

Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related informatio…

Fix: after 0.38.0
Fix from $1,600 2021-03-05
Ambari MEDIUM 6.1
CVE-2020-1936

A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.

Fix: 2.7.4+
Fix from $1,600 2021-03-02
Asterixdb MEDIUM 5.5
CVE-2020-9479

When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache A…

Fix: 0.9.5+
Fix from $1,600 2021-03-01
Tomcat HIGH 7.0
CVE-2021-25329EPSS 9%

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with…

Fix: 21.3.0+
Fix from $1,950 2021-03-01
Tomcat HIGH 7.5
CVE-2021-25122EPSS 18%

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate re…

Fix: 21.3.0+
Fix from $1,950 2021-03-01
Nifi MEDIUM 5.3
CVE-2020-27223EPSS 78%

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers …

Fix: 9.4.36+
Fix from $1,600 2021-02-26