Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2016-3089 Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script … Openmeetings after 3.1.1 Fix from $1,6002016-08-19 HIGH 8.8 CVE-2016-0760 Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re… Sentry Mitigation only Fix from $1,9502016-08-19 MEDIUM 5.4 CVE-2016-0782EPSS 6% The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users… Activemq No fix yet Fix from $1,6002016-08-05 MEDIUM 5.5 CVE-2016-5000 The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external … Poi after 3.13 Fix from $1,6002016-08-05 HIGH 7.8 CVE-2016-1513 The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute… Openoffice after 4.1.2 Fix from $1,9502016-08-05 HIGH 8.8 CVE-2016-4469EPSS 8% Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of… Archiva after 1.3.9 Fix from $1,9502016-07-28 HIGH 8.1 CVE-2016-5387EPSS 56% The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted clie… HTTP Server after 2.4.23 Fix from $1,9502016-07-19 HIGH 7.5 CVE-2016-4974EPSS 6% Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which … Amqp 0 X Jms Client after 6.0.3 Fix from $1,9502016-07-13 HIGH 7.5 CVE-2016-4463EPSS 14% Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD. Xerces C\+\+ after 3.1.3 Fix from $1,9502016-07-08 HIGH 7.5 CVE-2016-4979EPSS 19% The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" direc… HTTP Server Patch available Fix from $1,9502016-07-06 MEDIUM 5.9 CVE-2016-1546EPSS 15% The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 con… HTTP Server Patch available Fix from $1,6002016-07-06 MEDIUM 5.3 CVE-2016-4465EPSS 10% The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n… Struts Mitigation only Fix from $1,6002016-07-04 CRITICAL 9.8 CVE-2016-4438EPSS 17% The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression. Struts Mitigation only Fix from $2,3002016-07-04 HIGH 7.5 CVE-2016-4433EPSS 10% Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted … Struts Mitigation only Fix from $1,9502016-07-04 HIGH 7.5 CVE-2016-4431EPSS 10% Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging … Struts Mitigation only Fix from $1,9502016-07-04 HIGH 8.8 CVE-2016-4430 Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac… Struts Mitigation only Fix from $1,9502016-07-04 HIGH 7.5 CVE-2016-3092EPSS 36% The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.… Tomcat after 1.3.1 Fix from $1,9502016-07-04 HIGH 8.2 CVE-2016-1182EPSS 26% ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to con… Struts Patch available Fix from $1,9502016-07-04 HIGH 8.1 CVE-2016-1181EPSS 13% ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to … Struts Patch available Fix from $1,9502016-07-04 HIGH 7.5 CVE-2015-0899EPSS 21% The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modi… Struts Patch available Fix from $1,9502016-07-04 HIGH 7.2 CVE-2016-2174 SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ… Ranger Mitigation only Fix from $1,9502016-06-13 MEDIUM 6.5 CVE-2016-3085 Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl… Cloudstack No fix yet Fix from $1,6002016-06-10 MEDIUM 5.3 CVE-2016-3093EPSS 8% Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to ca… Struts after 3.0.11 Fix from $1,6002016-06-07 CRITICAL 9.8 CVE-2016-3087EPSS 82% Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec… Struts No fix yet Fix from $2,3002016-06-07 CRITICAL 9.8 CVE-2016-4437 KEVEPSS 93% Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code… Aurora 0.18.1 / 1.2.5+ Fix from $2,3002016-06-07 HIGH 8.1 CVE-2015-7611EPSS 69% Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v… James Server No fix yet Fix from $1,9502016-06-07 CRITICAL 9.1 CVE-2016-4432EPSS 8% The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons… Qpid Broker J 6.0.3+ Fix from $2,3002016-06-01 MEDIUM 5.9 CVE-2016-3094EPSS 8% PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a… Qpid Broker J after 6.0.2 Fix from $1,6002016-06-01 CRITICAL 9.8 CVE-2016-3088 KEVEPSS 99% The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol… Activemq 5.14.0+ Fix from $2,3002016-06-01 HIGH 7.8 CVE-2016-2175 Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XM… Pdfbox Patch available Fix from $1,9502016-06-01