apache
2,902 tracked vulnerabilities.
CVE-2022-25370
MEDIUM
Apache OFBiz < 18.12.06 - Unauthenticated Stored Cross-Site Scripting via Birt Plugin
Sep 02, 2022
CVSS 5.4
EPSS 0.01
CVE-2022-37435
HIGH
Apache ShenYu 2.4.2-2.4.3 - Authenticated Privilege Escalation via Password Modification
Sep 01, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-37023
MEDIUM
Apache Geode < 1.15.0 - Deserialization of Untrusted Data via REST API
Aug 31, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-37022
HIGH
Apache Geode < 1.12.2 and 1.13.2 - Deserialization of Untrusted Data via JMX over RMI
Aug 31, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-37021
CRITICAL
Apache Geode <= 1.12.5, 1.13.4, 1.14.0 - Deserialization of Untrusted Data via JMX over RMI
Aug 31, 2022
CVSS 9.8
EPSS 0.01
CVE-2022-22728
HIGH
Apache libapreq2 <= 2.16 - Denial of Service via Multipart Form Upload Buffer Overflow
Aug 25, 2022
CVSS 7.5
EPSS 0.20
CVE-2022-35278
MEDIUM
Apache ActiveMQ Artemis < 2.24.0 - Cross-Site Scripting via Address or Queue Name
Aug 23, 2022
CVSS 6.1
EPSS 0.08
CVE-2022-34916
CRITICAL
Apache Flume 1.4.0-1.10.0 - Remote Code Execution via JMS Source JNDI LDAP URI
Aug 21, 2022
CVSS 9.8
EPSS 0.03
CVE-2022-38362
HIGH
Apache Airflow Docker <3.0.0 - Authenticated RCE
Aug 16, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-37401
HIGH
Apache OpenOffice <4.1.13 - Info Disclosure
Aug 15, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-37400
HIGH
Apache OpenOffice <4.1.13 - Info Disclosure
Aug 15, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-31780
HIGH
Apache Traffic Server 8.0.0-9.1.2 - HTTP Request Smuggling via HTTP/2 Frame Handling
Aug 10, 2022
CVSS 7.5
EPSS 0.05
CVE-2022-31779
HIGH
Apache Traffic Server 8.0.0-9.1.2 - HTTP Request Smuggling via HTTP/2 Header Parsing
Aug 10, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-31778
HIGH
Apache Traffic Server 8.0.0-9.0.2 - Cache Poisoning via Transfer-Encoding Header
Aug 10, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-28129
HIGH
Apache Traffic Server 8.0.0-9.1.2 - Improper Input Validation in HTTP/1.1 Header Parsing
Aug 10, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-25763
HIGH
Apache Traffic Server 8.0.0-9.1.2 - HTTP Request Smuggling via HTTP/2 Request Validation
Aug 10, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-36125
HIGH
Apache Avro Rust SDK <0.14.0 - Memory Corruption
Aug 09, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-36124
HIGH
Apache Avro Rust SDK <0.14.0 - Memory Corruption
Aug 09, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-35724
HIGH
Apache Avro < 0.14.0 - Denial of Service via Infinite Loop in Data Reader
Aug 09, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-25168
CRITICAL
Apache Hadoop 2.0.0-2.10.1 and 2.10.2-3.3.3 - OS Command Injection via FileUtil.unTar
Aug 04, 2022
CVSS 9.8
EPSS 0.03
CVE-2022-34158
HIGH
Apache JSPWiki < 2.11.3 - Cross-Site Request Forgery via Image Plugin
Aug 04, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-28732
MEDIUM
Apache JSPWiki < 2.11.3 - Cross-Site Scripting via WeblogPlugin
Aug 04, 2022
CVSS 6.1
EPSS 0.09
CVE-2022-28731
MEDIUM
Apache JSPWiki < 2.11.3 - Cross-Site Request Forgery via UserPreferences.jsp
Aug 04, 2022
CVSS 6.5
EPSS 0.15
CVE-2022-28730
MEDIUM
Apache JSPWiki < 2.11.3 - Cross-Site Scripting via Denounce Plugin
Aug 04, 2022
CVSS 6.1
EPSS 0.11
CVE-2022-27166
MEDIUM
Apache JSPWiki <= 2.11.2 - Cross-Site Scripting via XHRHtml2Markup.jsp
Aug 04, 2022
CVSS 6.1
EPSS 0.18
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
cxf 46
nifi 46
solr 46
cloudstack 45
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters