Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-29158 Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, un… Ofbiz 18.12.06+ Fix from $1,9502022-09-02 MEDIUM 5.4 CVE-2022-25370 Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.… Ofbiz 18.12.06+ Fix from $1,6002022-09-02 HIGH 8.8 CVE-2022-37435 Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This i… Shenyu Patch available Fix from $1,9502022-09-01 CRITICAL 9.8 CVE-2022-37021 Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A… Geode after 1.13.4 Fix from $2,3002022-08-31 HIGH 8.8 CVE-2022-37022 Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user… Geode after 1.13.2 Fix from $1,9502022-08-31 MEDIUM 6.5 CVE-2022-37023 Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user w… Geode 1.15.0+ Fix from $1,6002022-08-31 HIGH 7.5 CVE-2022-22728 A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could s… Libapreq2 after 2.16 Fix from $1,9502022-08-25 HIGH 8.8 CVE-2021-25642 ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation… Hadoop 2.10.2 / 3.2.4+ Fix from $1,9502022-08-25 MEDIUM 6.1 CVE-2022-35278 In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by u… Artemis 2.24.0+ Fix from $1,6002022-08-23 CRITICAL 9.8 CVE-2022-34916 Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI … Flume 1.10.1+ Fix from $2,3002022-08-21 HIGH 8.8 CVE-2022-38362 Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the… Apache Airflow Providers Docker 3.0.0+ Fix from $1,9502022-08-16 HIGH 8.8 CVE-2022-37401 Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with… Openoffice 4.1.13+ Fix from $1,9502022-08-15 HIGH 8.8 CVE-2022-37400 Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with… Openoffice 4.1.13+ Fix from $1,9502022-08-15 HIGH 7.5 CVE-2021-37150 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-25763 Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison at… Traffic Server 8.1.5 / 9.1.3+ Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-28129 Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue af… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31778 Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. Thi… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31779 Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects … Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31780 Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects … Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-35724 It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin… Avro 0.14.0+ Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-36124 It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust ap… Avro 0.14.0+ Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-36125 It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust … Avro 0.14.0+ Fix from $1,9502022-08-09 CRITICAL 9.8 CVE-2022-25168 Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary… Hadoop after 3.3.2 Fix from $2,3002022-08-04 HIGH 8.8 CVE-2022-34158 A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri… Jspwiki 2.11.3+ Fix from $1,9502022-08-04 MEDIUM 6.5 CVE-2022-28731EPSS 57% A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacke… Jspwiki 2.11.3+ Fix from $1,6002022-08-04 MEDIUM 6.1 CVE-2022-27166EPSS 85% A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow … Jspwiki 2.11.3+ Fix from $1,6002022-08-04 MEDIUM 6.1 CVE-2022-28730EPSS 85% A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javasc… Jspwiki 2.11.3+ Fix from $1,6002022-08-04 MEDIUM 6.1 CVE-2022-28732EPSS 82% A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascrip… Jspwiki 2.11.3+ Fix from $1,6002022-08-04 HIGH 8.8 CVE-2022-36364 Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, th… Apache Calcite Avatica 1.22.0+ Fix from $1,9502022-07-28 HIGH 7.5 CVE-2022-24294 A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul… Mxnet 1.9.1+ Fix from $1,9502022-07-24