Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-24853 A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the v… Jspwiki 2.12.3+ Fix from $1,9502025-07-31 MEDIUM 6.5 CVE-2025-54656 ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: bef… Struts Extras 2.0+ Fix from $1,6002025-07-30 MEDIUM 6.3 CVE-2025-54090 A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2… HTTP Server Patch available Fix from $1,6002025-07-23 HIGH 8.8 CVE-2025-50151 File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to… Jena 5.5.0+ Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-49656 Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to… Jena 5.5.0+ Fix from $1,9502025-07-21 MEDIUM 5.6 CVE-2025-48795 Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary … Cxf Mitigation only Fix from $1,6002025-07-15 HIGH 8.8 CVE-2025-53689 Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to … Jackrabbit 2.20.17+ Fix from $1,9502025-07-14 HIGH 7.5 CVE-2024-41169 The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files… Zeppelin 0.12.0+ Fix from $1,9502025-07-12 MEDIUM 5.3 CVE-2025-48924 Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to … Commons Lang 2.6 / 3.18.0+ Fix from $1,6002025-07-11 HIGH 7.5 CVE-2025-53506 Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the … Tomcat after 11.0.8 Fix from $1,9502025-07-10 HIGH 7.5 CVE-2025-52434 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native … Tomcat 9.0.107+ Fix from $1,9502025-07-10 HIGH 7.5 CVE-2025-52520 For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size li… Tomcat 9.0.107 / 10.1.43+ Fix from $1,9502025-07-10 HIGH 7.5 CVE-2025-49630 In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untruste… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.5 CVE-2025-53020 Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.4 CVE-2025-49812 In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 CRITICAL 9.1 CVE-2025-23048 In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 … HTTP Server 2.4.64+ Fix from $2,3002025-07-10 HIGH 7.5 CVE-2024-43394 Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or … HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.5 CVE-2024-47252 Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape c… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.5 CVE-2024-42516 HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hos… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.5 CVE-2024-43204 SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.8 CVE-2025-27446 Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX… Apisix after 0.5 Fix from $1,9502025-07-06 MEDIUM 5.3 CVE-2025-46647 A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1… Apisix 3.12.0+ Fix from $1,6002025-07-02 HIGH 7.5 CVE-2024-35164 The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols lik… Guacamole 1.6.0+ Fix from $1,9502025-07-02 CRITICAL 9.8 CVE-2025-32897 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver… Seata 2.3.0+ Fix from $2,3002025-06-28 CRITICAL 9.8 CVE-2025-50213 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This is… Apache Airflow Providers Snowflake 6.4.0+ Fix from $2,3002025-06-24 MEDIUM 6.5 CVE-2025-32896 # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized … Seatunnel 2.3.11+ Fix from $1,6002025-06-19 HIGH 7.5 CVE-2025-49763 ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. … Traffic Server 9.2.11 / 10.0.6+ Fix from $1,9502025-06-19 HIGH 7.5 CVE-2025-31698 ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.… Traffic Server 9.2.11 / 10.0.6+ Fix from $1,9502025-06-19 HIGH 8.4 CVE-2025-49124 Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe wit… Tomcat 9.0.106 / 10.1.42+ Fix from $1,9502025-06-16 HIGH 7.5 CVE-2025-48976EPSS 68% Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects … Commons Fileupload 1.6+ Fix from $1,9502025-06-16