apache
2,902 tracked vulnerabilities.
CVE-2020-13959
MEDIUM
Apache Velocity Tools < 3.1 - Cross-Site Scripting via URL vm File Parameter
Mar 10, 2021
CVSS 6.1
EPSS 0.03
CVE-2020-13936
HIGH
Apache Velocity Engine < 2.3 - Remote Code Execution via Template Modification
Mar 10, 2021
CVSS 8.8
EPSS 0.16
CVE-2020-35451
MEDIUM
Apache Oozie < 5.2.1 - Race Condition in OozieSharelibCLI
Mar 09, 2021
CVSS 4.7
EPSS 0.00
CVE-2020-1936
MEDIUM
Apache Ambari < 2.7.4 - Cross-Site Scripting in Views
Mar 02, 2021
CVSS 6.1
EPSS 0.03
CVE-2020-9479
MEDIUM
Apache AsterixDB < 0.9.5 - Path Traversal via UDF Zip File Extraction
Mar 01, 2021
CVSS 5.5
EPSS 0.09
CVE-2020-27223
MEDIUM
Eclipse Jetty 9.4.6-9.4.36, 10.0.0, 11.0.0 - Denial of Service via Multiple Accept Headers with Quality Parameters
Feb 26, 2021
CVSS 5.2
EPSS 0.28
CVE-2020-11988
HIGH
Apache XmlGraphics Commons < 2.4 - Server-Side Request Forgery via XMPParser
Feb 24, 2021
CVSS 8.2
EPSS 0.00
CVE-2020-11987
HIGH
Apache Batik < 1.13 - Server-Side Request Forgery via NodePickerPanel
Feb 24, 2021
CVSS 8.2
EPSS 0.01
CVE-2020-13949
HIGH
Apache Thrift 0.9.3-0.13.0 - Uncontrolled Resource Consumption via Short RPC Messages
Feb 12, 2021
CVSS 7.5
EPSS 0.01
CVE-2020-13947
MEDIUM
Apache ActiveMQ 5.15.12-5.16.0 - Stored Cross-Site Scripting in message.jsp
Feb 08, 2021
CVSS 6.1
EPSS 0.04
CVE-2020-17523
CRITICAL
Apache Shiro < 1.7.1 - Authentication Bypass via Crafted HTTP Request
Feb 03, 2021
CVSS 9.8
EPSS 0.89
CVE-2020-17516
HIGH
Apache Cassandra <3.11.10 - Info Disclosure
Feb 03, 2021
CVSS 7.5
EPSS 0.01
CVE-2020-9492
HIGH
Apache Hadoop 2.0.0-2.10.0 and 3.0.0-alpha1-3.2.1 - Incorrect Authorization via WebHDFS SPNEGO Header
Jan 26, 2021
CVSS 8.8
EPSS 0.00
CVE-2020-36230
HIGH
OpenLDAP < 2.4.57 - Denial of Service via X.509 DN Parsing Assertion Failure
Jan 26, 2021
CVSS 7.5
EPSS 0.04
CVE-2020-17522
MEDIUM
Apache Traffic Control <4.1.0 - Info Disclosure
Jan 26, 2021
CVSS 5.8
EPSS 0.02
CVE-2020-17532
HIGH
Apache ServiceComb-Java-Chassis <2.1.4 - Authenticated RCE
Jan 25, 2021
CVSS 8.8
EPSS 0.03
CVE-2020-11997
MEDIUM
Apache Guacamole < 1.2.0 - Unauthorized Connection History Access
Jan 19, 2021
CVSS 4.3
EPSS 0.01
CVE-2020-17534
HIGH
HTML/Java API <1.7.1 - Privilege Escalation
Jan 11, 2021
CVSS 7.0
EPSS 0.00
CVE-2020-17509
HIGH
Apache Traffic Server <8.1.0 - Cache Poisoning
Jan 11, 2021
CVSS 7.5
EPSS 0.03
CVE-2020-17508
HIGH
Apache Traffic Server <8.2 - Info Disclosure
Jan 11, 2021
CVSS 7.5
EPSS 0.03
CVE-2020-13922
MEDIUM
Apache DolphinScheduler < 1.3.2 - Unauthenticated Password Override via API Interface
Jan 11, 2021
CVSS 6.5
EPSS 0.01
CVE-2020-11995
CRITICAL
Apache Dubbo 2.5.0-2.5.9 and 2.7.0-2.7.7 - Remote Code Execution via Hessian2 Deserialization
Jan 11, 2021
CVSS 9.8
EPSS 0.02
CVE-2020-17519
HIGH
KEVNUCLEI
Apache Flink JobManager Traversal
Jan 05, 2021
CVSS 7.5
EPSS 0.94
CVE-2020-17518
HIGH
NUCLEI
Apache Flink <1.11.3-1.12.0 - Path Traversal
Jan 05, 2021
CVSS 7.5
EPSS 0.94
CVE-2020-17533
HIGH
Apache Accumulo <2.0.0 - Privilege Escalation
Dec 29, 2020
CVSS 8.1
EPSS 0.05
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
cxf 46
nifi 46
solr 46
cloudstack 45
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters