Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2010-2232 In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file. Derby Patch available Fix from $1,9502017-10-23 HIGH 7.8 CVE-2017-12628 The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex… James Server after 3.0.0 Fix from $1,9502017-10-20 CRITICAL 9.8 CVE-2017-5636 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio… Nifi Mitigation only Fix from $2,3002017-10-19 HIGH 7.5 CVE-2017-5635 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin… Nifi Mitigation only Fix from $1,9502017-10-19 MEDIUM 5.4 CVE-2016-8748 In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an au… Nifi after 1.0.0 Fix from $1,6002017-10-19 HIGH 8.8 CVE-2016-4461EPSS 8% Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva… Struts 2.3.29+ Fix from $1,9502017-10-16 MEDIUM 6.5 CVE-2016-8734EPSS 6% Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack… Subversion Mitigation only Fix from $1,6002017-10-16 CRITICAL 9.8 CVE-2017-12629EPSS 92% Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li… Solr after 7.0.1 Fix from $2,3002017-10-14 MEDIUM 6.5 CVE-2016-6815 In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role. Ranger Mitigation only Fix from $1,6002017-10-13 CRITICAL 9.8 CVE-2016-8736 Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. Openmeetings 3.1.2+ Fix from $2,3002017-10-12 MEDIUM 6.5 CVE-2017-12623 An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f… Nifi Mitigation only Fix from $1,6002017-10-10 HIGH 7.5 CVE-2017-5637EPSS 73% Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead… Zookeeper Mitigation only Fix from $1,9502017-10-10 CRITICAL 9.8 CVE-2014-0030EPSS 17% The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. Roller No fix yet Fix from $2,3002017-10-10 MEDIUM 6.5 CVE-2017-9792 In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt… Impala Mitigation only Fix from $1,6002017-10-04 HIGH 8.1 CVE-2017-12617 KEVEPSS 100% When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett… Tomcat 7.0.82 / 8.0.47+ Fix from $1,9502017-10-04 MEDIUM 6.5 CVE-2017-9797 When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send m… Geode after 1.2.0 Fix from $1,6002017-10-03 CRITICAL 9.8 CVE-2017-12620 When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap… Opennlp No fix yet Fix from $2,3002017-10-03 HIGH 8.8 CVE-2016-6806 Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. … Wicket Mitigation only Fix from $1,9502017-10-03 MEDIUM 5.3 CVE-2014-0043 In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla… Wicket Mitigation only Fix from $1,6002017-10-03 HIGH 7.8 CVE-2016-4434 Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En… Tika Mitigation only Fix from $1,9502017-09-30 HIGH 7.5 CVE-2017-7687 When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x befo… Mesos after 1.1.2 Fix from $1,9502017-09-29 HIGH 7.5 CVE-2017-9790 When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1… Mesos after 1.1.2 Fix from $1,9502017-09-29 CRITICAL 9.8 CVE-2017-12621EPSS 9% During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used … Commons Jelly 1.0.1+ Fix from $2,3002017-09-28 MEDIUM 6.1 CVE-2015-5169EPSS 8% Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20. Struts after 2.3.16.3 Fix from $1,6002017-09-25 CRITICAL 9.8 CVE-2016-6795EPSS 8% In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for… Struts Mitigation only Fix from $2,3002017-09-20 CRITICAL 9.8 CVE-2017-12611EPSS 87% In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can … Struts Patch available Fix from $2,3002017-09-20 HIGH 7.5 CVE-2017-9793EPSS 9% The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allo… Struts Patch available Fix from $1,9502017-09-20 HIGH 7.5 CVE-2017-9804EPSS 8% In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is us… Struts Patch available Fix from $1,9502017-09-20 MEDIUM 5.9 CVE-2016-8738 In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to … Struts Patch available Fix from $1,6002017-09-20 HIGH 8.1 CVE-2017-12615 KEVEPSS 100% When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t… Tomcat after 7.0.79 Fix from $1,9502017-09-19