Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-22696EPSS 7% CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F… Cxf 3.3.10 / 3.4.3+ Fix from $1,9502021-04-02 MEDIUM 5.5 CVE-2021-28657 A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade … Tika after 17.12 Fix from $1,6002021-03-31 HIGH 8.8 CVE-2021-26919EPSS 23% Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissio… Druid 0.20.2+ Fix from $1,9502021-03-30 CRITICAL 9.8 CVE-2020-1946EPSS 6% In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. … Spamassassin 3.4.5+ Fix from $2,3002021-03-25 CRITICAL 9.8 CVE-2021-21347EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21350EPSS 15% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21351EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 8.6 CVE-2021-21349EPSS 47% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-21348EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 CRITICAL 9.9 CVE-2021-21345EPSS 72% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21344EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21346EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21342EPSS 50% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed … Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 7.5 CVE-2021-21341EPSS 78% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-21343EPSS 47% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed … Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 CRITICAL 9.8 CVE-2021-26295EPSS 98% Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF… Ofbiz 17.12.06+ Fix from $2,3002021-03-22 MEDIUM 5.5 CVE-2021-27807 A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x ver… Pdfbox after 14.3.0 Fix from $1,6002021-03-19 MEDIUM 5.5 CVE-2021-27906 A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2… Pdfbox after 2.0.22 Fix from $1,6002021-03-19 HIGH 7.5 CVE-2020-17525EPSS 40% Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a c… Subversion 1.10.7 / 1.14.1+ Fix from $1,9502021-03-17 HIGH 7.5 CVE-2020-13924 In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to … Ambari after 2.6.2.2 Fix from $1,9502021-03-17 MEDIUM 5.9 CVE-2020-1926 Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow rec… Hive 2.3.8+ Fix from $1,6002021-03-16 HIGH 7.5 CVE-2021-27576 If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache O… Openmeetings 6.0.0+ Fix from $1,9502021-03-15 HIGH 8.8 CVE-2020-13936EPSS 23% An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as th… Velocity Engine 2.3+ Fix from $1,9502021-03-10 MEDIUM 6.1 CVE-2020-13959EPSS 6% The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attac… Velocity Tools 3.1+ Fix from $1,6002021-03-10 MEDIUM 5.4 CVE-2021-27907EPSS 86% Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related informatio… Superset after 0.38.0 Fix from $1,6002021-03-05 MEDIUM 6.1 CVE-2020-1936 A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4. Ambari 2.7.4+ Fix from $1,6002021-03-02 MEDIUM 5.5 CVE-2020-9479 When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache A… Asterixdb 0.9.5+ Fix from $1,6002021-03-01 HIGH 7.0 CVE-2021-25329EPSS 9% The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with… Tomcat 21.3.0+ Fix from $1,9502021-03-01 HIGH 7.5 CVE-2021-25122EPSS 18% When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate re… Tomcat 21.3.0+ Fix from $1,9502021-03-01 MEDIUM 5.3 CVE-2020-27223EPSS 78% In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers … Nifi 9.4.36+ Fix from $1,6002021-02-26