Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2016-0710EPSS 52% Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL co… Jetspeed after 2.3.0 Fix from $1,9502016-04-11 HIGH 7.2 CVE-2016-0709EPSS 77% Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticate… Jetspeed after 2.3.0 Fix from $1,9502016-04-11 MEDIUM 6.1 CVE-2016-0734EPSS 9% The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for rem… Activemq Mitigation only Fix from $1,6002016-04-07 HIGH 8.8 CVE-2016-0714EPSS 13% The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s… Tomcat Mitigation only Fix from $1,9502016-02-25 HIGH 8.8 CVE-2015-5351EPSS 10% The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a… Tomcat No fix yet Fix from $1,9502016-02-25 HIGH 8.1 CVE-2015-5346EPSS 11% Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are us… Tomcat No fix yet Fix from $1,9502016-02-25 MEDIUM 6.1 CVE-2015-8797 Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows rem… Solr after 5.3 Fix from $1,6002016-02-15 MEDIUM 6.1 CVE-2015-8796 Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers… Solr after 5.2.1 Fix from $1,6002016-02-15 MEDIUM 6.1 CVE-2015-8795 Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script o… Solr after 5.0 Fix from $1,6002016-02-15 HIGH 7.5 CVE-2016-0956EPSS 46% The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen… Sling Patch available Fix from $1,9502016-02-10 CRITICAL 9.8 CVE-2015-3252 Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain ac… Cloudstack after 4.5.1 Fix from $2,3002016-02-08 CRITICAL 9.8 CVE-2015-5344EPSS 7% The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted… Camel after 2.15.4 Fix from $2,3002016-02-03 HIGH 8.3 CVE-2015-7521EPSS 6% The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, … Hive No fix yet Fix from $1,9502016-01-29 HIGH 8.6 CVE-2015-5259EPSS 57% Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar… Subversion Mitigation only Fix from $1,9502016-01-08 HIGH 8.4 CVE-2015-7430 The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to… Hadoop Mitigation only Fix from $1,9502016-01-02 HIGH 7.3 CVE-2015-1836EPSS 7% Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o… Hbase Mitigation only Fix from $1,9502015-12-21 HIGH 7.3 CVE-2015-1772EPSS 7% The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.… Hive Mitigation only Fix from $1,9502015-12-21 CRITICAL 9.8 CVE-2015-6420EPSS 18% Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and… Commons Collections 3.2.2+ Fix from $2,3002015-12-15 MEDIUM 5.0 CVE-2015-8320 Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge h… Cordova after 3.6.4 Fix from $1,6002015-11-23 MEDIUM 6.8 CVE-2015-5212EPSS 9% Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the docu… Openoffice after 4.4.4 Fix from $1,6002015-11-10 MEDIUM 5.8 CVE-2015-5210 Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac… Ambari after 2.1.1 Fix from $1,6002015-11-02 MEDIUM 6.5 CVE-2015-3270 Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl… Ambari Mitigation only Fix from $1,6002015-11-02 MEDIUM 5.5 CVE-2015-1775 Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users… Ambari Mitigation only Fix from $1,6002015-11-02 HIGH 7.5 CVE-2014-3612EPSS 7% The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att… Activemq Mitigation only Fix from $1,9502015-08-24 HIGH 7.8 CVE-2014-1972EPSS 10% Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attac… Tapestry after 5.3.5 Fix from $1,9502015-08-22 MEDIUM 5.0 CVE-2015-1830EPSS 84% Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows … Activemq No fix yet Fix from $1,6002015-08-19 HIGH 7.5 CVE-2014-3576EPSS 13% The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of s… Activemq after 5.10.0 Fix from $1,9502015-08-14 CRITICAL 9.8 CVE-2015-3253EPSS 41% The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause… Groovy Patch available Fix from $2,3002015-08-13 MEDIUM 5.0 CVE-2015-3184EPSS 11% mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous a… Subversion after 7.2.1 Fix from $1,6002015-08-12 MEDIUM 5.0 CVE-2015-3183EPSS 73% The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attacke… HTTP Server 2.2.31 / 2.4.16+ Fix from $1,6002015-07-20