Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openmeetings MEDIUM 6.1
CVE-2016-3089

Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script …

Fix: after 3.1.1
Fix from $1,600 2016-08-19
Sentry HIGH 8.8
CVE-2016-0760

Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re…

Mitigation only
Fix from $1,950 2016-08-19
Activemq MEDIUM 5.4
CVE-2016-0782EPSS 6%

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users…

No fix yet
Fix from $1,600 2016-08-05
Poi MEDIUM 5.5
CVE-2016-5000

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external …

Fix: after 3.13
Fix from $1,600 2016-08-05
Openoffice HIGH 7.8
CVE-2016-1513

The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute…

Fix: after 4.1.2
Fix from $1,950 2016-08-05
Archiva HIGH 8.8
CVE-2016-4469EPSS 8%

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of…

Fix: after 1.3.9
Fix from $1,950 2016-07-28
HTTP Server HIGH 8.1
CVE-2016-5387EPSS 56%

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted clie…

Fix: after 2.4.23
Fix from $1,950 2016-07-19
Amqp 0 X Jms Client HIGH 7.5
CVE-2016-4974EPSS 6%

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which …

Fix: after 6.0.3
Fix from $1,950 2016-07-13
Xerces C\+\+ HIGH 7.5
CVE-2016-4463EPSS 14%

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

Fix: after 3.1.3
Fix from $1,950 2016-07-08
HTTP Server HIGH 7.5
CVE-2016-4979EPSS 19%

The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" direc…

Patch available
Fix from $1,950 2016-07-06
HTTP Server MEDIUM 5.9
CVE-2016-1546EPSS 15%

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 con…

Patch available
Fix from $1,600 2016-07-06
Struts MEDIUM 5.3
CVE-2016-4465EPSS 10%

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n…

Mitigation only
Fix from $1,600 2016-07-04
Struts CRITICAL 9.8
CVE-2016-4438EPSS 17%

The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

Mitigation only
Fix from $2,300 2016-07-04
Struts HIGH 7.5
CVE-2016-4433EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted …

Mitigation only
Fix from $1,950 2016-07-04
Struts HIGH 7.5
CVE-2016-4431EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging …

Mitigation only
Fix from $1,950 2016-07-04
Struts HIGH 8.8
CVE-2016-4430

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac…

Mitigation only
Fix from $1,950 2016-07-04
Tomcat HIGH 7.5
CVE-2016-3092EPSS 36%

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.…

Fix: after 1.3.1
Fix from $1,950 2016-07-04
Struts HIGH 8.2
CVE-2016-1182EPSS 26%

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to con…

Patch available
Fix from $1,950 2016-07-04
Struts HIGH 8.1
CVE-2016-1181EPSS 13%

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to …

Patch available
Fix from $1,950 2016-07-04
Struts HIGH 7.5
CVE-2015-0899EPSS 21%

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modi…

Patch available
Fix from $1,950 2016-07-04
Ranger HIGH 7.2
CVE-2016-2174

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2016-06-13
Cloudstack MEDIUM 6.5
CVE-2016-3085

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl…

No fix yet
Fix from $1,600 2016-06-10
Struts MEDIUM 5.3
CVE-2016-3093EPSS 8%

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to ca…

Fix: after 3.0.11
Fix from $1,600 2016-06-07
Struts CRITICAL 9.8
CVE-2016-3087EPSS 82%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…

No fix yet
Fix from $2,300 2016-06-07
Aurora CRITICAL 9.8
CVE-2016-4437 KEVEPSS 93%

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code…

Fix: 0.18.1 / 1.2.5+
Fix from $2,300 2016-06-07
James Server HIGH 8.1
CVE-2015-7611EPSS 69%

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v…

No fix yet
Fix from $1,950 2016-06-07
Qpid Broker J CRITICAL 9.1
CVE-2016-4432EPSS 8%

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons…

Fix: 6.0.3+
Fix from $2,300 2016-06-01
Qpid Broker J MEDIUM 5.9
CVE-2016-3094EPSS 8%

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a…

Fix: after 6.0.2
Fix from $1,600 2016-06-01
Activemq CRITICAL 9.8
CVE-2016-3088 KEVEPSS 99%

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol…

Fix: 5.14.0+
Fix from $2,300 2016-06-01
Pdfbox HIGH 7.8
CVE-2016-2175

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XM…

Patch available
Fix from $1,950 2016-06-01