Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Batik HIGH 8.2
CVE-2020-11987EPSS 14%

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf…

Fix: after 1.13
Fix from $1,950 2021-02-24
Xmlgraphics Commons HIGH 8.2
CVE-2020-11988EPSS 7%

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi…

Fix: after 2.4
Fix from $1,950 2021-02-24
Livy MEDIUM 5.4
CVE-2021-26544

Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw t…

Patch available
Fix from $1,600 2021-02-20
Myfaces HIGH 7.5
CVE-2021-26296

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptograph…

Fix: after 2.3.7
Fix from $1,950 2021-02-19
Airflow MEDIUM 6.5
CVE-2021-26559

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur…

Mitigation only
Fix from $1,600 2021-02-17
Airflow MEDIUM 5.3
CVE-2021-26697

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…

Mitigation only
Fix from $1,600 2021-02-17
Cordova HIGH 7.8
CVE-2021-21315 KEVEPSS 91%

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,…

Fix: 5.3.1+
Fix from $1,950 2021-02-16
Hive HIGH 7.5
CVE-2020-13949EPSS 7%

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leadin…

Fix: 4.0.0+
Fix from $1,950 2021-02-12
Activemq MEDIUM 6.1
CVE-2020-13947EPSS 79%

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of A…

Fix: 5.15.14 / 5.16.1+
Fix from $1,600 2021-02-08
Shiro CRITICAL 9.8
CVE-2020-17523EPSS 86%

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.1+
Fix from $2,300 2021-02-03
Cassandra HIGH 7.5
CVE-2020-17516

Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption set…

Fix: after 3.11.9
Fix from $1,950 2021-02-03
Druid HIGH 8.8
CVE-2021-25646EPSS 99%

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for …

Fix: after 0.20.0
Fix from $1,950 2021-01-29
Activemq HIGH 7.5
CVE-2021-26117EPSS 11%

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior…

Fix: 2.16.0 / 5.15.14+
Fix from $1,950 2021-01-27
Artemis HIGH 7.5
CVE-2021-26118

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 …

Mitigation only
Fix from $1,950 2021-01-27
Hadoop HIGH 8.8
CVE-2020-9492

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote UR…

Fix: after 3.2.1
Fix from $1,950 2021-01-26
Traffic Control MEDIUM 5.8
CVE-2020-17522

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi…

Fix: after 4.1.0
Fix from $1,600 2021-01-26
Nutch CRITICAL 9.1
CVE-2021-23901

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa…

Fix: 1.18+
Fix from $2,300 2021-01-25
Java Chassis HIGH 8.8
CVE-2020-17532

When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The…

Fix: 2.1.5+
Fix from $1,950 2021-01-25
Xmlbeans CRITICAL 9.1
CVE-2021-23926EPSS 6%

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities …

Fix: after 2.6.0
Fix from $2,300 2021-01-14
Tomcat MEDIUM 5.9
CVE-2021-24122EPSS 23%

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 t…

Fix: after 9.0.39
Fix from $1,600 2021-01-14
Html\/java Api HIGH 7.0
CVE-2020-17534

There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/J…

Mitigation only
Fix from $1,950 2021-01-11
Dubbo CRITICAL 9.8
CVE-2020-11995EPSS 6%

A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H…

Fix: after 2.7.7
Fix from $2,300 2021-01-11
Traffic Server HIGH 7.5
CVE-2020-17508

The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.1…

Fix: after 8.1.0
Fix from $1,950 2021-01-11
Traffic Server HIGH 7.5
CVE-2020-17509

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache …

Fix: after 8.0.7
Fix from $1,950 2021-01-11
Dolphinscheduler MEDIUM 6.5
CVE-2020-13922

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter…

Mitigation only
Fix from $1,600 2021-01-11
Flink HIGH 7.5
CVE-2020-17518EPSS 50%

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a m…

Fix: 1.11.3+
Fix from $1,950 2021-01-05
Flink HIGH 7.5
CVE-2020-17519 KEVEPSS 98%

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t…

Fix: 1.11.3+
Fix from $1,950 2021-01-05
Accumulo HIGH 8.1
CVE-2020-17533

Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before pe…

Fix: after 1.10.0
Fix from $1,950 2020-12-29
Airflow HIGH 7.7
CVE-2020-17526EPSS 23%

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A wher…

Fix: 1.10.14+
Fix from $1,950 2020-12-21
Dolphinscheduler CRITICAL 9.8
CVE-2020-11974EPSS 8%

In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.

Mitigation only
Fix from $2,300 2020-12-18