apache

2,902 tracked vulnerabilities.

CVE-2022-25370 MEDIUM
Apache OFBiz < 18.12.06 - Unauthenticated Stored Cross-Site Scripting via Birt Plugin
Sep 02, 2022
CVSS 5.4
EPSS 0.01
CVE-2022-37435 HIGH
Apache ShenYu 2.4.2-2.4.3 - Authenticated Privilege Escalation via Password Modification
Sep 01, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-37023 MEDIUM
Apache Geode < 1.15.0 - Deserialization of Untrusted Data via REST API
Aug 31, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-37022 HIGH
Apache Geode < 1.12.2 and 1.13.2 - Deserialization of Untrusted Data via JMX over RMI
Aug 31, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-37021 CRITICAL
Apache Geode <= 1.12.5, 1.13.4, 1.14.0 - Deserialization of Untrusted Data via JMX over RMI
Aug 31, 2022
CVSS 9.8
EPSS 0.01
CVE-2022-22728 HIGH
Apache libapreq2 <= 2.16 - Denial of Service via Multipart Form Upload Buffer Overflow
Aug 25, 2022
CVSS 7.5
EPSS 0.20
CVE-2022-35278 MEDIUM
Apache ActiveMQ Artemis < 2.24.0 - Cross-Site Scripting via Address or Queue Name
Aug 23, 2022
CVSS 6.1
EPSS 0.08
CVE-2022-34916 CRITICAL
Apache Flume 1.4.0-1.10.0 - Remote Code Execution via JMS Source JNDI LDAP URI
Aug 21, 2022
CVSS 9.8
EPSS 0.03
CVE-2022-38362 HIGH
Apache Airflow Docker <3.0.0 - Authenticated RCE
Aug 16, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-37401 HIGH
Apache OpenOffice <4.1.13 - Info Disclosure
Aug 15, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-37400 HIGH
Apache OpenOffice <4.1.13 - Info Disclosure
Aug 15, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-31780 HIGH
Apache Traffic Server 8.0.0-9.1.2 - HTTP Request Smuggling via HTTP/2 Frame Handling
Aug 10, 2022
CVSS 7.5
EPSS 0.05
CVE-2022-31779 HIGH
Apache Traffic Server 8.0.0-9.1.2 - HTTP Request Smuggling via HTTP/2 Header Parsing
Aug 10, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-31778 HIGH
Apache Traffic Server 8.0.0-9.0.2 - Cache Poisoning via Transfer-Encoding Header
Aug 10, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-28129 HIGH
Apache Traffic Server 8.0.0-9.1.2 - Improper Input Validation in HTTP/1.1 Header Parsing
Aug 10, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-25763 HIGH
Apache Traffic Server 8.0.0-9.1.2 - HTTP Request Smuggling via HTTP/2 Request Validation
Aug 10, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-36125 HIGH
Apache Avro Rust SDK <0.14.0 - Memory Corruption
Aug 09, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-36124 HIGH
Apache Avro Rust SDK <0.14.0 - Memory Corruption
Aug 09, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-35724 HIGH
Apache Avro < 0.14.0 - Denial of Service via Infinite Loop in Data Reader
Aug 09, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-25168 CRITICAL
Apache Hadoop 2.0.0-2.10.1 and 2.10.2-3.3.3 - OS Command Injection via FileUtil.unTar
Aug 04, 2022
CVSS 9.8
EPSS 0.03
CVE-2022-34158 HIGH
Apache JSPWiki < 2.11.3 - Cross-Site Request Forgery via Image Plugin
Aug 04, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-28732 MEDIUM
Apache JSPWiki < 2.11.3 - Cross-Site Scripting via WeblogPlugin
Aug 04, 2022
CVSS 6.1
EPSS 0.09
CVE-2022-28731 MEDIUM
Apache JSPWiki < 2.11.3 - Cross-Site Request Forgery via UserPreferences.jsp
Aug 04, 2022
CVSS 6.5
EPSS 0.15
CVE-2022-28730 MEDIUM
Apache JSPWiki < 2.11.3 - Cross-Site Scripting via Denounce Plugin
Aug 04, 2022
CVSS 6.1
EPSS 0.11
CVE-2022-27166 MEDIUM
Apache JSPWiki <= 2.11.2 - Cross-Site Scripting via XHRHtml2Markup.jsp
Aug 04, 2022
CVSS 6.1
EPSS 0.18