Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2020-11987EPSS 14% Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf… Batik after 1.13 Fix from $1,9502021-02-24 HIGH 8.2 CVE-2020-11988EPSS 7% Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi… Xmlgraphics Commons after 2.4 Fix from $1,9502021-02-24 MEDIUM 5.4 CVE-2021-26544 Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw t… Livy Patch available Fix from $1,6002021-02-20 HIGH 7.5 CVE-2021-26296 In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptograph… Myfaces after 2.3.7 Fix from $1,9502021-02-19 MEDIUM 6.5 CVE-2021-26559 Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur… Airflow Mitigation only Fix from $1,6002021-02-17 MEDIUM 5.3 CVE-2021-26697 The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h… Airflow Mitigation only Fix from $1,6002021-02-17 HIGH 7.8 CVE-2021-21315 KEVEPSS 91% The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… Cordova 5.3.1+ Fix from $1,9502021-02-16 HIGH 7.5 CVE-2020-13949EPSS 7% In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leadin… Hive 4.0.0+ Fix from $1,9502021-02-12 MEDIUM 6.1 CVE-2020-13947EPSS 79% An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of A… Activemq 5.15.14 / 5.16.1+ Fix from $1,6002021-02-08 CRITICAL 9.8 CVE-2020-17523EPSS 86% Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Shiro 1.7.1+ Fix from $2,3002021-02-03 HIGH 7.5 CVE-2020-17516 Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption set… Cassandra after 3.11.9 Fix from $1,9502021-02-03 HIGH 8.8 CVE-2021-25646EPSS 99% Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for … Druid after 0.20.0 Fix from $1,9502021-01-29 HIGH 7.5 CVE-2021-26117EPSS 11% The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior… Activemq 2.16.0 / 5.15.14+ Fix from $1,9502021-01-27 HIGH 7.5 CVE-2021-26118 While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 … Artemis Mitigation only Fix from $1,9502021-01-27 HIGH 8.8 CVE-2020-9492 In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote UR… Hadoop after 3.2.1 Fix from $1,9502021-01-26 MEDIUM 5.8 CVE-2020-17522 When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi… Traffic Control after 4.1.0 Fix from $1,6002021-01-26 CRITICAL 9.1 CVE-2021-23901 An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa… Nutch 1.18+ Fix from $2,3002021-01-25 HIGH 8.8 CVE-2020-17532 When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The… Java Chassis 2.1.5+ Fix from $1,9502021-01-25 CRITICAL 9.1 CVE-2021-23926EPSS 6% The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities … Xmlbeans after 2.6.0 Fix from $2,3002021-01-14 MEDIUM 5.9 CVE-2021-24122EPSS 23% When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 t… Tomcat after 9.0.39 Fix from $1,6002021-01-14 HIGH 7.0 CVE-2020-17534 There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/J… Html\/java Api Mitigation only Fix from $1,9502021-01-11 CRITICAL 9.8 CVE-2020-11995EPSS 6% A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H… Dubbo after 2.7.7 Fix from $2,3002021-01-11 HIGH 7.5 CVE-2020-17508 The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.1… Traffic Server after 8.1.0 Fix from $1,9502021-01-11 HIGH 7.5 CVE-2020-17509 ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache … Traffic Server after 8.0.7 Fix from $1,9502021-01-11 MEDIUM 6.5 CVE-2020-13922 Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter… Dolphinscheduler Mitigation only Fix from $1,6002021-01-11 HIGH 7.5 CVE-2020-17518EPSS 50% Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a m… Flink 1.11.3+ Fix from $1,9502021-01-05 HIGH 7.5 CVE-2020-17519 KEVEPSS 98% A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t… Flink 1.11.3+ Fix from $1,9502021-01-05 HIGH 8.1 CVE-2020-17533 Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before pe… Accumulo after 1.10.0 Fix from $1,9502020-12-29 HIGH 7.7 CVE-2020-17526EPSS 23% Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A wher… Airflow 1.10.14+ Fix from $1,9502020-12-21 CRITICAL 9.8 CVE-2020-11974EPSS 8% In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database. Dolphinscheduler Mitigation only Fix from $2,3002020-12-18