Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Airflow CRITICAL 9.8
CVE-2020-11982EPSS 7%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) …

Fix: after 1.10.10
Fix from $2,300 2020-07-17
Airflow HIGH 8.8
CVE-2020-11978 KEVEPSS 99%

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…

Fix: 1.10.11+
Fix from $1,950 2020-07-17
Airflow MEDIUM 5.4
CVE-2020-11983

An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handl…

Fix: after 1.10.10
Fix from $1,600 2020-07-17
Ofbiz MEDIUM 6.1
CVE-2020-9496EPSS 99%

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

No fix yet
Fix from $1,600 2020-07-15
Ofbiz MEDIUM 5.3
CVE-2020-13923EPSS 5%

IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

Fix: 17.12.04+
Fix from $1,600 2020-07-15
Tomcat HIGH 7.5
CVE-2020-13934EPSS 64%

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after…

Fix: after 9.0.36
Fix from $1,950 2020-07-14
Tomcat HIGH 7.5
CVE-2020-13935EPSS 87%

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and …

Fix: after 9.0.36
Fix from $1,950 2020-07-14
Dubbo CRITICAL 9.8
CVE-2020-1948EPSS 16%

This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met…

Fix: after 2.7.6
Fix from $2,300 2020-07-14
Kylin CRITICAL 9.8
CVE-2020-13925EPSS 20%

Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…

Fix: 3.1.0+
Fix from $2,300 2020-07-14
Kylin CRITICAL 9.8
CVE-2020-13926

Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…

Fix: 3.1.0+
Fix from $2,300 2020-07-14
Camel HIGH 7.5
CVE-2020-11994

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

Fix: after 8.5.0
Fix from $1,950 2020-07-08
Guacamole MEDIUM 6.7
CVE-2020-9498

Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a m…

Fix: after 1.1.0
Fix from $1,600 2020-07-02
Skywalking HIGH 7.5
CVE-2020-9483EPSS 35%

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability…

Fix: after 6.6.0
Fix from $1,950 2020-06-30
Tomcat HIGH 7.8
CVE-2020-8022

A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE …

Fix: 8.0.53-29.32.1 / 9.0.35-3.39.1+
Fix from $1,950 2020-06-29
Tomcat HIGH 7.5
CVE-2020-11996EPSS 27%

A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger hi…

Fix: after 20.12
Fix from $1,950 2020-06-26
Artemis MEDIUM 5.5
CVE-2020-10727

A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in t…

Fix: after 2.12.0
Fix from $1,600 2020-06-26
Traffic Server HIGH 7.5
CVE-2020-9494

Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the …

Fix: after 8.0.7
Fix from $1,950 2020-06-24
Spark CRITICAL 9.8
CVE-2020-9480EPSS 29%

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…

Fix: after 2.4.5
Fix from $2,300 2020-06-23
Shiro CRITICAL 9.8
CVE-2020-11989EPSS 24%

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

Fix: 1.5.3+
Fix from $2,300 2020-06-22
Archiva MEDIUM 5.3
CVE-2020-9495EPSS 8%

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP…

Fix: 2.2.5+
Fix from $1,600 2020-06-19
Tomee CRITICAL 9.8
CVE-2020-11969

If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP…

Fix: after 8.0.1
Fix from $2,300 2020-06-15
Karaf MEDIUM 6.3
CVE-2020-11980

In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…

Fix: 4.2.9+
Fix from $1,600 2020-06-12
Unomi CRITICAL 9.8
CVE-2020-11975EPSS 30%

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code wi…

Fix: 1.5.1+
Fix from $2,300 2020-06-05
Ignite CRITICAL 9.1
CVE-2020-1963

Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fi…

Fix: after 2.8.0
Fix from $2,300 2020-06-03
Kylin HIGH 8.8
CVE-2020-1956 KEVEPSS 97%

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …

Fix: after 2.6.5
Fix from $1,950 2020-05-22
Hive CRITICAL 9.8
CVE-2018-21234EPSS 8%

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

Fix: 5.0.4+
Fix from $2,300 2020-05-21
Tomcat HIGH 7.0
CVE-2020-9484EPSS 57%

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to contr…

Fix: 7.0.108 / 8.5.63+
Fix from $1,950 2020-05-20
Couchdb CRITICAL 9.8
CVE-2020-1955

CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…

Mitigation only
Fix from $2,300 2020-05-20
Camel CRITICAL 9.8
CVE-2020-11972EPSS 6%

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users…

Fix: after 8.2.2
Fix from $2,300 2020-05-14
Camel CRITICAL 9.8
CVE-2020-11973EPSS 7%

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh…

Fix: after 8.5.0
Fix from $2,300 2020-05-14