Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Derby HIGH 7.5
CVE-2010-2232

In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.

Patch available
Fix from $1,950 2017-10-23
James Server HIGH 7.8
CVE-2017-12628

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex…

Fix: after 3.0.0
Fix from $1,950 2017-10-20
Nifi CRITICAL 9.8
CVE-2017-5636

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…

Mitigation only
Fix from $2,300 2017-10-19
Nifi HIGH 7.5
CVE-2017-5635

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin…

Mitigation only
Fix from $1,950 2017-10-19
Nifi MEDIUM 5.4
CVE-2016-8748

In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an au…

Fix: after 1.0.0
Fix from $1,600 2017-10-19
Struts HIGH 8.8
CVE-2016-4461EPSS 8%

Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva…

Fix: 2.3.29+
Fix from $1,950 2017-10-16
Subversion MEDIUM 6.5
CVE-2016-8734EPSS 6%

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack…

Mitigation only
Fix from $1,600 2017-10-16
Solr CRITICAL 9.8
CVE-2017-12629EPSS 92%

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li…

Fix: after 7.0.1
Fix from $2,300 2017-10-14
Ranger MEDIUM 6.5
CVE-2016-6815

In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.

Mitigation only
Fix from $1,600 2017-10-13
Openmeetings CRITICAL 9.8
CVE-2016-8736

Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.

Fix: 3.1.2+
Fix from $2,300 2017-10-12
Nifi MEDIUM 6.5
CVE-2017-12623

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f…

Mitigation only
Fix from $1,600 2017-10-10
Zookeeper HIGH 7.5
CVE-2017-5637EPSS 73%

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead…

Mitigation only
Fix from $1,950 2017-10-10
Roller CRITICAL 9.8
CVE-2014-0030EPSS 17%

The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

No fix yet
Fix from $2,300 2017-10-10
Impala MEDIUM 6.5
CVE-2017-9792

In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt…

Mitigation only
Fix from $1,600 2017-10-04
Tomcat HIGH 8.1
CVE-2017-12617 KEVEPSS 100%

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…

Fix: 7.0.82 / 8.0.47+
Fix from $1,950 2017-10-04
Geode MEDIUM 6.5
CVE-2017-9797

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send m…

Fix: after 1.2.0
Fix from $1,600 2017-10-03
Opennlp CRITICAL 9.8
CVE-2017-12620

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…

No fix yet
Fix from $2,300 2017-10-03
Wicket HIGH 8.8
CVE-2016-6806

Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. …

Mitigation only
Fix from $1,950 2017-10-03
Wicket MEDIUM 5.3
CVE-2014-0043

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla…

Mitigation only
Fix from $1,600 2017-10-03
Tika HIGH 7.8
CVE-2016-4434

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En…

Mitigation only
Fix from $1,950 2017-09-30
Mesos HIGH 7.5
CVE-2017-7687

When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x befo…

Fix: after 1.1.2
Fix from $1,950 2017-09-29
Mesos HIGH 7.5
CVE-2017-9790

When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1…

Fix: after 1.1.2
Fix from $1,950 2017-09-29
Commons Jelly CRITICAL 9.8
CVE-2017-12621EPSS 9%

During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used …

Fix: 1.0.1+
Fix from $2,300 2017-09-28
Struts MEDIUM 6.1
CVE-2015-5169EPSS 8%

Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.

Fix: after 2.3.16.3
Fix from $1,600 2017-09-25
Struts CRITICAL 9.8
CVE-2016-6795EPSS 8%

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for…

Mitigation only
Fix from $2,300 2017-09-20
Struts CRITICAL 9.8
CVE-2017-12611EPSS 87%

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can …

Patch available
Fix from $2,300 2017-09-20
Struts HIGH 7.5
CVE-2017-9793EPSS 9%

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allo…

Patch available
Fix from $1,950 2017-09-20
Struts HIGH 7.5
CVE-2017-9804EPSS 8%

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is us…

Patch available
Fix from $1,950 2017-09-20
Struts MEDIUM 5.9
CVE-2016-8738

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to …

Patch available
Fix from $1,600 2017-09-20
Tomcat HIGH 8.1
CVE-2017-12615 KEVEPSS 100%

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t…

Fix: after 7.0.79
Fix from $1,950 2017-09-19