apache
2,902 tracked vulnerabilities.
CVE-2020-17526
HIGH
NUCLEI
Apache Airflow Webserver <1.10.14 - Info Disclosure
Dec 21, 2020
CVSS 7.7
EPSS 0.91
CVE-2020-17520
MEDIUM
Pulsar manager <0.1.0 - Auth Bypass
Dec 18, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-11974
CRITICAL
Apache DolphinScheduler 1.2.0-1.2.1 - Remote Code Execution via MySQL ConnectorJ
Dec 18, 2020
CVSS 9.8
EPSS 0.11
CVE-2020-28052
HIGH
Legion of the Bouncy Castle BC Java <1.67 - Info Disclosure
Dec 18, 2020
CVSS 8.1
EPSS 0.04
CVE-2020-13931
CRITICAL
Apache TomEE <8.0.4 - Unauthenticated RCE
Dec 18, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-26259
MEDIUM
XStream <1.4.15 - File Deletion
Dec 16, 2020
CVSS 6.8
EPSS 0.89
CVE-2020-26258
MEDIUM
NUCLEI
XStream <1.4.15 - Server-Side Request Forgery via XML Unmarshalling
Dec 16, 2020
CVSS 6.3
EPSS 0.94
CVE-2020-17513
MEDIUM
Apache Airflow < 1.10.13 - Server-Side Request Forgery via Charts and Query View
Dec 14, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-17511
MEDIUM
Apache Airflow < 1.10.13 - Cleartext Storage of Sensitive Information in Log Table
Dec 14, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-17515
MEDIUM
Apache Airflow < 1.10.15 - Cross-Site Scripting via Origin Parameter
Dec 11, 2020
CVSS 6.1
EPSS 0.10
CVE-2020-17530
CRITICAL
KEVNUCLEI
Apache Struts 2 Forced Multi OGNL Evaluation
Dec 11, 2020
CVSS 9.8
EPSS 0.94
CVE-2020-17529
CRITICAL
Apache NuttX <9.1.0, 10.0.0 - Memory Corruption
Dec 09, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-17528
CRITICAL
Apache NuttX <10.0.0 - Memory Corruption
Dec 09, 2020
CVSS 9.1
EPSS 0.02
CVE-2020-17531
CRITICAL
Apache Tapestry 4 - Deserialization
Dec 08, 2020
CVSS 9.8
EPSS 0.69
CVE-2020-17521
MEDIUM
Apache Groovy <4.0.0 - Info Disclosure
Dec 07, 2020
CVSS 5.5
EPSS 0.02
CVE-2020-13945
MEDIUM
NUCLEI
Apache APISIX <1.6 - Privilege Escalation
Dec 07, 2020
CVSS 6.5
EPSS 0.93
CVE-2020-17527
HIGH
Apache Tomcat <10.0.0-M9, 9.0.39, 8.5.59 - Info Disclosure
Dec 03, 2020
CVSS 7.5
EPSS 0.11
CVE-2020-25649
HIGH
jackson-databind 2.6.0-2.6.7.3 - XML External Entity Injection
Dec 03, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-13956
MEDIUM
Apache HttpClient <4.5.13, 5.0.3 - SSRF
Dec 02, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-11990
LOW
Cordova (Android) - Info Disclosure
Dec 01, 2020
CVSS 3.3
EPSS 0.00
CVE-2020-27218
MEDIUM
Eclipse Jetty 9.4.0-9.4.34 - Sensitive Information Exposure via GZIP Request Body Reuse
Nov 28, 2020
CVSS 4.8
EPSS 0.01
CVE-2020-13942
CRITICAL
NUCLEI
Apache Unomi 1.5.0-1.5.1 - Unauthenticated Remote Code Execution via /context.json Endpoint
Nov 24, 2020
CVSS 9.8
EPSS 0.94
CVE-2020-13958
HIGH
Apache OpenOffice 4.0.0-4.1.7 - Unauthenticated Arbitrary Executable Execution via Hyperlink in Scripting Events
Nov 17, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-26217
HIGH
NUCLEI
XStream < 1.4.14 - Remote Code Execution via Blocklist Bypass
Nov 16, 2020
CVSS 8.0
EPSS 0.93
CVE-2020-13954
MEDIUM
Apache CXF < 3.3.8 - Reflected Cross-Site Scripting via styleSheetPath
Nov 12, 2020
CVSS 6.1
EPSS 0.15
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
cxf 46
nifi 46
solr 46
cloudstack 45
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters