apache

2,902 tracked vulnerabilities.

CVE-2021-42357 MEDIUM
Apache Knox < 1.6.1 - Open Redirect via Crafted Request Parameter
Jan 17, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-43999 HIGH
Apache Guacamole <1.3.0 - Privilege Escalation
Jan 11, 2022
CVSS 8.8
EPSS 0.01
CVE-2021-41767 MEDIUM
Apache Guacamole < 1.3.0 - Authenticated Exposure of Sensitive Information via REST Response
Jan 11, 2022
CVSS 6.5
EPSS 0.01
CVE-2021-43297 CRITICAL
Apache Dubbo <2.6.12, <2.7.15, <3.0 - Code Injection
Jan 10, 2022
CVSS 9.8
EPSS 0.46
CVE-2021-43045 HIGH
Apache Avro < 1.11.0 - Denial of Service via Resource Allocation
Jan 06, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-45458 HIGH
Apache Kylin <2.6.6, <3.1.2 - Info Disclosure
Jan 06, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-45457 HIGH
Apache Kylin 2.0.0-2.6.6, 3.0.0-3.1.2, 4.0.0 - Incorrect Authorization via Cross-Origin Request Handling
Jan 06, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-45456 CRITICAL
Apache Kylin 4.0.0 - Command Injection via Project Name Parameter
Jan 06, 2022
CVSS 9.8
EPSS 0.38
CVE-2021-36774 MEDIUM
Apache Kylin 2.0.0-2.6.6 and 3.0.0-3.1.2 - Remote Code Execution via MySQL JDBC Driver Properties
Jan 06, 2022
CVSS 6.5
EPSS 0.01
CVE-2021-31522 CRITICAL
Apache Kylin <2.6.6, <3.1.2, <4.0.0 - RCE
Jan 06, 2022
CVSS 9.8
EPSS 0.03
CVE-2021-27738 HIGH
Apache Kylin <3.1.2 - Coordinator API Access and Server-Side Request Forgery
Jan 06, 2022
CVSS 7.5
EPSS 0.02
CVE-2021-36739 MEDIUM
Apache Pluto 3.1.0 - Cross-Site Scripting in MVCBean JSP Portlet Archetype
Jan 06, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-36738 MEDIUM
Apache Pluto < 3.1.1 - Cross-Site Scripting in Applicant MVCBean CDI Portlet
Jan 06, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-36737 MEDIUM
Apache Pluto < 3.1.1 - Cross-Site Scripting in UrlTestPortlet Input Fields
Jan 06, 2022
CVSS 6.1
EPSS 0.06
CVE-2021-40525 CRITICAL
Apache James <3.6.1 - Path Traversal
Jan 04, 2022
CVSS 9.1
EPSS 0.03
CVE-2021-40111 MEDIUM
Apache James < 3.6.1 - Authenticated Denial of Service via Crafted IMAP APPEND and STATUS Commands
Jan 04, 2022
CVSS 6.5
EPSS 0.01
CVE-2021-40110 HIGH
Apache James < 3.6.1 - Denial of Service via IMAP LIST Command Regular Expression
Jan 04, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-38542 MEDIUM
Apache James <3.6.1 - Command Injection
Jan 04, 2022
CVSS 5.9
EPSS 0.01
CVE-2021-34797 HIGH
Apache Geode < 1.12.4 and 1.13.4 - Sensitive Information Exposure in Log Files
Jan 04, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-44832 MEDIUM
Apache Log4j 2.0-beta7-2.17.0 - Remote Code Execution via JDBC Appender JNDI LDAP Data Source
Dec 28, 2021
CVSS 6.6
EPSS 0.54
CVE-2021-45232 CRITICAL NUCLEI
Apache APISIX Dashboard < 2.10.1 - Unauthenticated API Access via Gin Framework Bypass
Dec 27, 2021
CVSS 9.8
EPSS 0.94
CVE-2021-44548 CRITICAL
Apache Solr < 8.11.1 - Path Traversal via DataImportHandler Windows UNC Path
Dec 23, 2021
CVSS 9.8
EPSS 0.05
CVE-2021-44790 CRITICAL
Apache HTTP Server < 2.4.52 - Buffer Overflow in mod_lua Multipart Parser
Dec 20, 2021
CVSS 9.8
EPSS 0.86
CVE-2021-44224 HIGH
Apache HTTP Server 2.4.7-2.4.51 - NULL Pointer Dereference and Server-Side Request Forgery via Forward Proxy
Dec 20, 2021
CVSS 8.2
EPSS 0.09
CVE-2021-41561 HIGH
Apache Parquet-MR 1.9.0-1.11.1 and 1.12.0 - Denial of Service via Malicious Parquet File
Dec 20, 2021
CVSS 7.5
EPSS 0.01