apache
2,902 tracked vulnerabilities.
CVE-2021-42357
MEDIUM
Apache Knox < 1.6.1 - Open Redirect via Crafted Request Parameter
Jan 17, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-43999
HIGH
Apache Guacamole <1.3.0 - Privilege Escalation
Jan 11, 2022
CVSS 8.8
EPSS 0.01
CVE-2021-41767
MEDIUM
Apache Guacamole < 1.3.0 - Authenticated Exposure of Sensitive Information via REST Response
Jan 11, 2022
CVSS 6.5
EPSS 0.01
CVE-2021-43297
CRITICAL
Apache Dubbo <2.6.12, <2.7.15, <3.0 - Code Injection
Jan 10, 2022
CVSS 9.8
EPSS 0.46
CVE-2021-43045
HIGH
Apache Avro < 1.11.0 - Denial of Service via Resource Allocation
Jan 06, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-45458
HIGH
Apache Kylin <2.6.6, <3.1.2 - Info Disclosure
Jan 06, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-45457
HIGH
Apache Kylin 2.0.0-2.6.6, 3.0.0-3.1.2, 4.0.0 - Incorrect Authorization via Cross-Origin Request Handling
Jan 06, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-45456
CRITICAL
Apache Kylin 4.0.0 - Command Injection via Project Name Parameter
Jan 06, 2022
CVSS 9.8
EPSS 0.38
CVE-2021-36774
MEDIUM
Apache Kylin 2.0.0-2.6.6 and 3.0.0-3.1.2 - Remote Code Execution via MySQL JDBC Driver Properties
Jan 06, 2022
CVSS 6.5
EPSS 0.01
CVE-2021-31522
CRITICAL
Apache Kylin <2.6.6, <3.1.2, <4.0.0 - RCE
Jan 06, 2022
CVSS 9.8
EPSS 0.03
CVE-2021-27738
HIGH
Apache Kylin <3.1.2 - Coordinator API Access and Server-Side Request Forgery
Jan 06, 2022
CVSS 7.5
EPSS 0.02
CVE-2021-36739
MEDIUM
Apache Pluto 3.1.0 - Cross-Site Scripting in MVCBean JSP Portlet Archetype
Jan 06, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-36738
MEDIUM
Apache Pluto < 3.1.1 - Cross-Site Scripting in Applicant MVCBean CDI Portlet
Jan 06, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-36737
MEDIUM
Apache Pluto < 3.1.1 - Cross-Site Scripting in UrlTestPortlet Input Fields
Jan 06, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-40525
CRITICAL
Apache James <3.6.1 - Path Traversal
Jan 04, 2022
CVSS 9.1
EPSS 0.03
CVE-2021-40111
MEDIUM
Apache James < 3.6.1 - Authenticated Denial of Service via Crafted IMAP APPEND and STATUS Commands
Jan 04, 2022
CVSS 6.5
EPSS 0.01
CVE-2021-40110
HIGH
Apache James < 3.6.1 - Denial of Service via IMAP LIST Command Regular Expression
Jan 04, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-38542
MEDIUM
Apache James <3.6.1 - Command Injection
Jan 04, 2022
CVSS 5.9
EPSS 0.01
CVE-2021-34797
HIGH
Apache Geode < 1.12.4 and 1.13.4 - Sensitive Information Exposure in Log Files
Jan 04, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-44832
MEDIUM
Apache Log4j 2.0-beta7-2.17.0 - Remote Code Execution via JDBC Appender JNDI LDAP Data Source
Dec 28, 2021
CVSS 6.6
EPSS 0.54
CVE-2021-45232
CRITICAL
NUCLEI
Apache APISIX Dashboard < 2.10.1 - Unauthenticated API Access via Gin Framework Bypass
Dec 27, 2021
CVSS 9.8
EPSS 0.94
CVE-2021-44548
CRITICAL
Apache Solr < 8.11.1 - Path Traversal via DataImportHandler Windows UNC Path
Dec 23, 2021
CVSS 9.8
EPSS 0.05
CVE-2021-44790
CRITICAL
Apache HTTP Server < 2.4.52 - Buffer Overflow in mod_lua Multipart Parser
Dec 20, 2021
CVSS 9.8
EPSS 0.86
CVE-2021-44224
HIGH
Apache HTTP Server 2.4.7-2.4.51 - NULL Pointer Dereference and Server-Side Request Forgery via Forward Proxy
Dec 20, 2021
CVSS 8.2
EPSS 0.09
CVE-2021-41561
HIGH
Apache Parquet-MR 1.9.0-1.11.1 and 1.12.0 - Denial of Service via Malicious Parquet File
Dec 20, 2021
CVSS 7.5
EPSS 0.01
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
cxf 46
nifi 46
solr 46
cloudstack 45
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters