Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Camel HIGH 7.5
CVE-2020-11971EPSS 14%

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to …

Fix: after 8.2.3
Fix from $1,950 2020-05-14
Activemq MEDIUM 6.1
CVE-2020-1941EPSS 6%

In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.

Fix: after 8.2.2
Fix from $1,600 2020-05-14
Cloudstack CRITICAL 9.8
CVE-2019-17562

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vul…

Fix: 4.13.1.0+
Fix from $2,300 2020-05-14
Rocketmq MEDIUM 5.3
CVE-2019-17572

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020…

Fix: after 4.6.0
Fix from $1,600 2020-05-14
Ant MEDIUM 6.3
CVE-2020-1945

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several …

Fix: after 14.4.0
Fix from $1,600 2020-05-14
Nuttx CRITICAL 9.8
CVE-2020-1939

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs…

Fix: after 8.2
Fix from $2,300 2020-05-12
Log4net CRITICAL 9.8
CVE-2018-1285EPSS 17%

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…

Fix: 2.0.10+
Fix from $2,300 2020-05-11
Syncope CRITICAL 9.8
CVE-2020-1961

Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e…

Fix: 2.0.15 / 2.1.6+
Fix from $2,300 2020-05-04
Syncope CRITICAL 9.8
CVE-2020-1959

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading …

Fix: 2.1.6+
Fix from $2,300 2020-05-04
Syncope MEDIUM 5.4
CVE-2019-17557

It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user acce…

Fix: 2.0.15 / 2.1.6+
Fix from $1,600 2020-05-04
Ofbiz HIGH 8.8
CVE-2019-0235EPSS 33%

Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

No fix yet
Fix from $1,950 2020-04-30
Ofbiz HIGH 7.5
CVE-2019-12425

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

Mitigation only
Fix from $1,950 2020-04-30
Nifi Registry MEDIUM 6.5
CVE-2020-9482

If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authenti…

Fix: after 0.5.0
Fix from $1,600 2020-04-28
Traffic Server HIGH 7.5
CVE-2020-9481

Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

Fix: after 8.0.6
Fix from $1,950 2020-04-27
Iotdb CRITICAL 9.8
CVE-2020-1952

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, c…

Fix: after 0.9.1
Fix from $2,300 2020-04-27
Tika MEDIUM 5.5
CVE-2020-9489

A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory error…

Fix: after 17.12
Fix from $1,600 2020-04-27
Heron CRITICAL 9.8
CVE-2020-1964

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …

Mitigation only
Fix from $2,300 2020-04-16
HTTP Server MEDIUM 6.1
CVE-2020-1927EPSS 57%

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…

Fix: after 2.4.41
Fix from $1,600 2020-04-02
Druid MEDIUM 6.5
CVE-2020-1958

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…

Mitigation only
Fix from $1,600 2020-04-01
Dubbo CRITICAL 9.8
CVE-2019-17564EPSS 37%

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in…

Fix: after 2.7.4
Fix from $2,300 2020-04-01
Cxf MEDIUM 5.3
CVE-2020-1954EPSS 6%

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnector…

Fix: 3.2.13 / 3.3.6+
Fix from $1,600 2020-04-01
HTTP Server MEDIUM 5.3
CVE-2020-1934EPSS 52%

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

Fix: after 2.4.41
Fix from $1,600 2020-04-01
Ofbiz MEDIUM 6.1
CVE-2020-1943EPSS 97%

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

Fix: after 16.11.07
Fix from $1,600 2020-04-01
Sling Cms MEDIUM 6.1
CVE-2020-1949

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative c…

Fix: 0.16.0+
Fix from $1,600 2020-04-01
Netbeans CRITICAL 9.1
CVE-2019-17560

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to interc…

Fix: after 11.2
Fix from $2,300 2020-03-30
Netbeans HIGH 7.5
CVE-2019-17561

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional c…

Fix: after 11.2
Fix from $1,950 2020-03-30
Shiro CRITICAL 9.8
CVE-2020-1957EPSS 23%

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

Fix: 1.5.2+
Fix from $2,300 2020-03-25
Traffic Server CRITICAL 9.8
CVE-2019-17559

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgr…

Fix: after 8.0.5
Fix from $2,300 2020-03-23
Traffic Server CRITICAL 9.8
CVE-2019-17565

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Up…

Fix: after 8.0.5
Fix from $2,300 2020-03-23
Traffic Server CRITICAL 9.8
CVE-2020-1944

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding an…

Fix: after 8.0.5
Fix from $2,300 2020-03-23