Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Tomcat HIGH 7.5
CVE-2026-34486 KEVEPSS 83%

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. …

Mitigation only
Fix from $1,950 2026-04-09
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Tomcat CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…

Fix: 9.0.99 / 10.1.35+
Fix from $2,300 2025-03-10
Ofbiz HIGH 7.5
CVE-2024-45195 KEVEPSS 100%

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrad…

Fix: 18.12.16+
Fix from $1,950 2024-09-04
Ofbiz CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi…

Fix: 18.12.15+
Fix from $2,300 2024-08-05
HTTP Server CRITICAL 9.1
CVE-2024-38475 KEVEPSS 100%

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p…

Fix: 2.4.60 / 10.2.1.14-75sv+
Fix from $2,300 2024-07-01
Ofbiz CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …

Fix: 18.12.13+
Fix from $2,300 2024-05-08
Hugegraph CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Activemq CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to…

Fix: 5.15.16 / 5.16.7+
Fix from $2,300 2023-10-27
Rocketmq CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu…

Fix: 4.9.6 / 5.1.1+
Fix from $2,300 2023-05-24
Superset CRITICAL 9.8
CVE-2023-27524 KEVEPSS 97%

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K…

Fix: after 2.0.1
Fix from $2,300 2023-04-24
Spark HIGH 8.8
CVE-2022-33891 KEVEPSS 93%

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks …

Fix: after 3.2.1
Fix from $1,950 2022-07-18
Couchdb CRITICAL 9.8
CVE-2022-24706 KEVEPSS 92%

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.…

Fix: 3.2.2+
Fix from $2,300 2022-04-26
Apisix CRITICAL 9.8
CVE-2022-24112 KEVEPSS 96%

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX …

Fix: 2.10.4 / 2.12.1+
Fix from $2,300 2022-02-11
Log4j CRITICAL 9.0
CVE-2021-45046 KEVEPSS 100%

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at…

Fix: 2.12.2 / 2.16.0+
Fix from $2,300 2021-12-14
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
HTTP Server CRITICAL 9.8
CVE-2021-42013 KEVEPSS 100%

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs…

Fix: 9.2.6.0 / 18.1.0.1.0+
Fix from $2,300 2021-10-07
HTTP Server CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…

Patch available
Fix from $2,300 2021-10-05
Cordova HIGH 7.8
CVE-2021-21315 KEVEPSS 91%

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,…

Fix: 5.3.1+
Fix from $1,950 2021-02-16
Flink HIGH 7.5
CVE-2020-17519 KEVEPSS 98%

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t…

Fix: 1.11.3+
Fix from $1,950 2021-01-05
Struts CRITICAL 9.8
CVE-2020-17530 KEVEPSS 96%

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.…

Fix: 2.5.30+
Fix from $2,300 2020-12-11
Airflow CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…

Fix: 1.10.11+
Fix from $2,300 2020-11-10
Airflow HIGH 8.8
CVE-2020-11978 KEVEPSS 99%

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…

Fix: 1.10.11+
Fix from $1,950 2020-07-17
Kylin HIGH 8.8
CVE-2020-1956 KEVEPSS 97%

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …

Fix: after 2.6.5
Fix from $1,950 2020-05-22
Geode CRITICAL 9.8
CVE-2020-1938 KEVEPSS 99%

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as …

Fix: 7.0.100 / 8.5.51+
Fix from $2,300 2020-02-24
Solr HIGH 7.5
CVE-2019-17558 KEVEPSS 99%

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…

Fix: 7.7.3 / 8.4.0+
Fix from $1,950 2019-12-30
Solr HIGH 7.2
CVE-2019-0193 KEVEPSS 84%

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…

Fix: 7.7.3 / 8.1.2+
Fix from $1,950 2019-08-01
HTTP Server HIGH 7.8
CVE-2019-0211 KEVEPSS 65%

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads …

Fix: after 2.4.38
Fix from $1,950 2019-04-08
Struts HIGH 8.1
CVE-2018-11776 KEVEPSS 100%

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by u…

Fix: 2.3.35 / 2.5.17+
Fix from $1,950 2018-08-22
Tomcat HIGH 8.1
CVE-2017-12617 KEVEPSS 100%

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…

Fix: 7.0.82 / 8.0.47+
Fix from $1,950 2017-10-04