Apache Software Foundation
46 exploits
Active since Aug 2013
Apache Kylin 2.3.0-2.3.1 and 2.6.0-2.6.4 - SQL Injection via RESTful API Input
CVSS 8.8
Apache JSPWiki 2.9.0-2.11.0.M2 - Path Traversal via Specially Crafted URL
CVSS 7.5
Apache Commons Compress <1.19 - DoS
CVSS 7.5
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via WYSIWYG Editor Plugin Link
CVSS 6.1
Apache JSPWiki 2.9.0-2.11.0.M3 - Cross-Site Scripting via Plugin Link Invocation
CVSS 6.1
Apache JSPWiki 2.9.0-2.11.0.M3 - Cross-Site Scripting via InterWiki Link
CVSS 6.1
Apache JSPWiki 2.9.0-2.11.0.M3 - Stored Cross-Site Scripting via Malicious Attachment
CVSS 6.1
Apache Commons Email <1.5 - Info Disclosure
CVSS 7.5
Apache Commons Compress 1.11-1.15 - Denial of Service via ZIP Extra Field Parser
CVSS 5.5
Apache Commons Compress 1.7-1.17 - Denial of Service via Malformed ZIP Archive
CVSS 5.5
Apache Sling XSS Protection API 1.0.4-1.0.18 and 2.0.0 - Cross-Site Scripting via URL Validation Bypass
CVSS 6.1
Apache Qpid AMQP JMS Client < 6.0.4 & JMS (AMQP 1.0) < 0.10.0 - RCE via JMS ObjectMessage Deserialization
CVSS 7.5
Apache Tika < 1.14 - Remote Code Execution via MATLAB File Deserialization
CVSS 9.8
Apache Tomcat 7.x < 7.0.70, 8.x < 8.0.36, 8.5.x < 8.5.3, 9.x < 9.0.0.M7 - Denial of Service via Long Boundary String
CVSS 7.5
Apache Commons FileUpload <1.3.3 - RCE
CVSS 9.8
Apache Commons FileUpload <1.3.1 - DoS
Redhat Jboss Enterprise Brms Platform - Improper Input Validation
Apache MyFaces Core <2.0.12, <2.1.6 - Path Traversal
Apache Tika Server < 1.10 - Exposure of Sensitive Information via HTTP fileUrl Header
CVSS 5.3
Apache Sling Commons JSON < 2.0.20 - Denial of Service via Crafted Input
CVSS 9.8
Apache Airflow FTP Provider <3.7.0 - Certificate Validation
CVSS 2.7