Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pulsar Manager MEDIUM 6.5
CVE-2020-17520

In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing…

Mitigation only
Fix from $1,600 2020-12-18
Karaf HIGH 8.1
CVE-2020-28052EPSS 7%

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data …

Fix: 21.1.2+
Fix from $1,950 2020-12-18
Tomee CRITICAL 9.8
CVE-2020-13931

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker co…

Fix: after 8.0.3
Fix from $2,300 2020-12-18
Struts HIGH 7.7
CVE-2020-26258EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability c…

Fix: 1.4.15 / 6.0.0+
Fix from $1,950 2020-12-16
Struts MEDIUM 6.8
CVE-2020-26259EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion o…

Fix: 1.4.15 / 6.0.0+
Fix from $1,600 2020-12-16
Airflow MEDIUM 6.5
CVE-2020-17511

In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Meta…

Fix: 1.10.13+
Fix from $1,600 2020-12-14
Airflow MEDIUM 5.3
CVE-2020-17513

In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

Fix: 1.10.13+
Fix from $1,600 2020-12-14
Airflow MEDIUM 6.1
CVE-2020-17515EPSS 16%

The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prio…

Fix: 1.10.15 / 2.0.2+
Fix from $1,600 2020-12-11
Struts CRITICAL 9.8
CVE-2020-17530 KEVEPSS 96%

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.…

Fix: 2.5.30+
Fix from $2,300 2020-12-11
Nuttx CRITICAL 9.8
CVE-2020-17529

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …

Fix: after 9.1.0
Fix from $2,300 2020-12-09
Nuttx CRITICAL 9.1
CVE-2020-17528

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …

Fix: after 9.1.0
Fix from $2,300 2020-12-09
Tapestry CRITICAL 9.8
CVE-2020-17531EPSS 10%

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok…

Fix: 5.0.1+
Fix from $2,300 2020-12-08
Apisix MEDIUM 6.5
CVE-2020-13945EPSS 73%

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to a…

Fix: after 1.5
Fix from $1,600 2020-12-07
Groovy MEDIUM 5.5
CVE-2020-17521

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension me…

Fix: after 3.0.6
Fix from $1,600 2020-12-07
Tomcat HIGH 7.5
CVE-2020-17527EPSS 25%

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTT…

Fix: 21.1.2+
Fix from $1,950 2020-12-03
Httpclient MEDIUM 5.3
CVE-2020-13956EPSS 9%

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as …

Fix: 1.7.6 / 4.5.13+
Fix from $1,600 2020-12-02
Unomi CRITICAL 9.8
CVE-2020-13942EPSS 68%

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…

Fix: 1.5.2+
Fix from $2,300 2020-11-24
Libapreq2 HIGH 7.5
CVE-2019-12412

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a reque…

Fix: after 2.13
Fix from $1,950 2020-11-19
Openoffice HIGH 7.8
CVE-2020-13958

A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on th…

Fix: 4.1.8+
Fix from $1,950 2020-11-17
Batik HIGH 7.5
CVE-2019-17566EPSS 11%

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-c…

Fix: 1.13+
Fix from $1,950 2020-11-12
Cxf MEDIUM 6.1
CVE-2020-13954EPSS 43%

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a r…

Fix: 3.3.8 / 3.4.1+
Fix from $1,600 2020-11-12
Airflow CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…

Fix: 1.10.11+
Fix from $2,300 2020-11-10
Shiro CRITICAL 9.8
CVE-2020-17510EPSS 9%

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.0+
Fix from $2,300 2020-11-05
Beam HIGH 7.0
CVE-2020-27216

In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the…

Fix: 9.3.29+
Fix from $1,950 2020-10-23
Hadoop HIGH 8.8
CVE-2018-11764

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even …

Mitigation only
Fix from $1,950 2020-10-21
Kylin MEDIUM 5.3
CVE-2020-13937EPSS 78%

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alph…

Mitigation only
Fix from $1,600 2020-10-19
Solr CRITICAL 9.8
CVE-2020-13957EPSS 79%

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co…

Fix: after 8.6.2
Fix from $2,300 2020-10-13
Fineract HIGH 7.5
CVE-2018-20243

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract ji…

Fix: after 1.3.0
Fix from $1,950 2020-10-13
Calcite MEDIUM 5.9
CVE-2020-13955

HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle atta…

Fix: 1.26+
Fix from $1,600 2020-10-09
Nifi HIGH 7.5
CVE-2020-9486

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was tr…

Fix: after 1.11.4
Fix from $1,950 2020-10-01