Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tika MEDIUM 5.5
CVE-2020-1950

A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

Fix: after 1.23
Fix from $1,600 2020-03-23
Tika MEDIUM 5.5
CVE-2020-1951

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

Fix: after 1.23
Fix from $1,600 2020-03-23
Deltaspike MEDIUM 6.1
CVE-2019-12416

we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrat…

Fix: after 1.9.2
Fix from $1,600 2020-03-19
Geode HIGH 7.4
CVE-2019-10091

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c…

Mitigation only
Fix from $1,950 2020-03-16
Commons Configuration CRITICAL 10.0
CVE-2020-1953EPSS 7%

Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…

Mitigation only
Fix from $2,300 2020-03-13
Shardingsphere CRITICAL 9.8
CVE-2020-1947EPSS 34%

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …

Mitigation only
Fix from $2,300 2020-03-11
Cxf MEDIUM 5.9
CVE-2011-2487

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbac…

Fix: 1.6.5+
Fix from $1,600 2020-03-11
Struts MEDIUM 6.1
CVE-2015-2992EPSS 6%

Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.

Fix: 2.3.20+
Fix from $1,600 2020-02-27
Geode CRITICAL 9.8
CVE-2020-1938 KEVEPSS 99%

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as …

Fix: 7.0.100 / 8.5.51+
Fix from $2,300 2020-02-24
Kylin HIGH 8.8
CVE-2020-1937

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

Fix: after 2.6.4
Fix from $1,950 2020-02-24
Jclouds CRITICAL 9.8
CVE-2014-4651

It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc…

Fix: 1.8.0+
Fix from $2,300 2020-02-18
Nifi HIGH 7.5
CVE-2020-1942

In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the …

Fix: after 1.11.0
Fix from $1,950 2020-02-11
Ofbiz MEDIUM 5.3
CVE-2019-12426

an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06

Fix: after 16.11.06
Fix from $1,600 2020-02-06
Spamassassin HIGH 8.1
CVE-2020-1930EPSS 7%

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur…

Fix: 3.4.3+
Fix from $1,950 2020-01-30
Spamassassin HIGH 8.1
CVE-2020-1931EPSS 6%

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to…

Fix: 3.4.3+
Fix from $1,950 2020-01-30
Jackrabbit Oak HIGH 7.5
CVE-2020-1940

The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive infor…

Fix: after 1.22.0
Fix from $1,950 2020-01-28
Superset MEDIUM 6.5
CVE-2020-1932

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retr…

Mitigation only
Fix from $1,600 2020-01-28
Nifi MEDIUM 6.1
CVE-2020-1933

A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticate…

Fix: after 1.10.0
Fix from $1,600 2020-01-28
Nifi MEDIUM 5.3
CVE-2020-1928

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose…

Mitigation only
Fix from $1,600 2020-01-28
Xml Rpc CRITICAL 9.8
CVE-2019-17570EPSS 49%

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar…

Patch available
Fix from $2,300 2020-01-23
Cxf HIGH 7.5
CVE-2019-12423EPSS 6%

Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to ver…

Fix: 3.2.12 / 3.3.5+
Fix from $1,950 2020-01-16
Cxf MEDIUM 6.1
CVE-2019-17573EPSS 7%

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a r…

Fix: 3.3.5+
Fix from $1,600 2020-01-16
Beam HIGH 7.5
CVE-2020-1929

The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not res…

Fix: after 2.16.0
Fix from $1,950 2020-01-15
Cordova Inappbrowser CRITICAL 9.8
CVE-2019-0219EPSS 8%

A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially craft…

Fix: after 3.0.0
Fix from $2,300 2020-01-14
Kafka HIGH 7.5
CVE-2019-12399

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a conne…

Fix: after 14.4.0
Fix from $1,950 2020-01-14
Olingo HIGH 7.5
CVE-2020-1925

Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or D…

Fix: after 4.7.0
Fix from $1,950 2020-01-09
Rust Sgx Sdk CRITICAL 9.8
CVE-2020-5499

Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.

Fix: after 1.0.8
Fix from $2,300 2020-01-04
Solr HIGH 7.5
CVE-2019-17558 KEVEPSS 99%

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…

Fix: 7.7.3 / 8.4.0+
Fix from $1,950 2019-12-30
Tomcat HIGH 7.0
CVE-2019-12418

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker witho…

Fix: after 9.0.28
Fix from $1,950 2019-12-23
Tomcat HIGH 7.5
CVE-2019-17563EPSS 11%

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker…

Fix: after 17.3
Fix from $1,950 2019-12-23