Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hadoop HIGH 8.8
CVE-2018-8029

In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary …

Fix: after 3.1.0
Fix from $1,950 2019-05-30
Tomcat MEDIUM 6.1
CVE-2019-0221EPSS 46%

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is…

Fix: after 9.0.17
Fix from $1,600 2019-05-28
Camel HIGH 7.5
CVE-2019-0188EPSS 10%

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib lib…

Fix: 2.24.0+
Fix from $1,950 2019-05-28
Roller CRITICAL 9.8
CVE-2018-17198

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S…

Fix: after 5.1.2
Fix from $2,300 2019-05-28
Activemq MEDIUM 5.9
CVE-2019-0201EPSS 10%

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when…

Fix: 18.1.3.1.0 / 19.1.0.0.1+
Fix from $1,600 2019-05-23
Jspwiki MEDIUM 6.1
CVE-2019-10076

A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacki…

Fix: after 2.11.0
Fix from $1,600 2019-05-20
Jspwiki MEDIUM 6.1
CVE-2019-10077

A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

Fix: after 2.11.0
Fix from $1,600 2019-05-20
Jspwiki MEDIUM 6.1
CVE-2019-10078

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijac…

Fix: after 2.11.0
Fix from $1,600 2019-05-20
Activemq CRITICAL 9.8
CVE-2013-7285EPSS 84%

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary…

Fix: after 1.4.6
Fix from $2,300 2019-05-15
Commons Imaging HIGH 7.5
CVE-2018-17201

Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note th…

Mitigation only
Fix from $1,950 2019-05-06
Commons Imaging HIGH 7.5
CVE-2018-17202

Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be use…

Mitigation only
Fix from $1,950 2019-05-06
Axis HIGH 7.5
CVE-2019-0227EPSS 92%

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits…

Patch available
Fix from $1,950 2019-05-01
Uimaducc MEDIUM 6.1
CVE-2018-8035

This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which ru…

Fix: after 2.2.2
Fix from $1,600 2019-05-01
Archiva MEDIUM 6.5
CVE-2019-0214

In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. E…

Fix: after 2.2.3
Fix from $1,600 2019-04-30
Camel HIGH 7.5
CVE-2019-0194EPSS 8%

Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and ea…

Fix: after 2.22.2
Fix from $1,950 2019-04-30
Archiva MEDIUM 6.5
CVE-2019-0213

In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerabili…

Fix: 2.2.4+
Fix from $1,600 2019-04-30
Pluto MEDIUM 6.1
CVE-2019-0186EPSS 21%

The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uni…

No fix yet
Fix from $1,600 2019-04-26
Qpid HIGH 7.4
CVE-2019-0223EPSS 6%

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its languag…

Fix: after 0.27.0
Fix from $1,950 2019-04-23
Zeppelin HIGH 8.8
CVE-2018-1317

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentica…

Fix: 0.8.0+
Fix from $1,950 2019-04-23
Zeppelin HIGH 8.1
CVE-2017-12619

Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "st…

Fix: 0.7.3+
Fix from $1,950 2019-04-23
Zeppelin MEDIUM 6.1
CVE-2018-1328EPSS 6%

Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".

Fix: 0.8.0+
Fix from $1,600 2019-04-23
Pony Mail MEDIUM 6.1
CVE-2019-0218EPSS 5%

A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

Fix: after 0.10
Fix from $1,600 2019-04-22
Pdfbox CRITICAL 9.8
CVE-2019-0228EPSS 9%

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…

Mitigation only
Fix from $2,300 2019-04-17
Tomcat HIGH 8.1
CVE-2019-0232EPSS 100%

When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93…

Fix: after 9.0.17
Fix from $1,950 2019-04-15
Airflow HIGH 8.8
CVE-2019-0229

A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site reques…

Fix: after 1.10.2
Fix from $1,950 2019-04-10
Tomcat HIGH 7.5
CVE-2019-0199EPSS 73%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also…

Fix: after 9.0.14
Fix from $1,950 2019-04-10
HTTP Server HIGH 7.8
CVE-2019-0211 KEVEPSS 65%

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads …

Fix: after 2.4.38
Fix from $1,950 2019-04-08
HTTP Server HIGH 7.5
CVE-2019-0217EPSS 17%

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with val…

Fix: after 2.4.38
Fix from $1,950 2019-04-08
HTTP Server HIGH 7.5
CVE-2019-0215EPSS 11%

In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a…

Mitigation only
Fix from $1,950 2019-04-08
Hbase HIGH 7.5
CVE-2019-0212

In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST ser…

Fix: after 2.1.3
Fix from $1,950 2019-03-28