apache

2,902 tracked vulnerabilities.

CVE-2020-17526 HIGH NUCLEI
Apache Airflow Webserver <1.10.14 - Info Disclosure
Dec 21, 2020
CVSS 7.7
EPSS 0.91
CVE-2020-17520 MEDIUM
Pulsar manager <0.1.0 - Auth Bypass
Dec 18, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-11974 CRITICAL
Apache DolphinScheduler 1.2.0-1.2.1 - Remote Code Execution via MySQL ConnectorJ
Dec 18, 2020
CVSS 9.8
EPSS 0.11
CVE-2020-28052 HIGH
Legion of the Bouncy Castle BC Java <1.67 - Info Disclosure
Dec 18, 2020
CVSS 8.1
EPSS 0.04
CVE-2020-13931 CRITICAL
Apache TomEE <8.0.4 - Unauthenticated RCE
Dec 18, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-26259 MEDIUM
XStream <1.4.15 - File Deletion
Dec 16, 2020
CVSS 6.8
EPSS 0.89
CVE-2020-26258 MEDIUM NUCLEI
XStream <1.4.15 - Server-Side Request Forgery via XML Unmarshalling
Dec 16, 2020
CVSS 6.3
EPSS 0.94
CVE-2020-17513 MEDIUM
Apache Airflow < 1.10.13 - Server-Side Request Forgery via Charts and Query View
Dec 14, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-17511 MEDIUM
Apache Airflow < 1.10.13 - Cleartext Storage of Sensitive Information in Log Table
Dec 14, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-17515 MEDIUM
Apache Airflow < 1.10.15 - Cross-Site Scripting via Origin Parameter
Dec 11, 2020
CVSS 6.1
EPSS 0.10
CVE-2020-17530 CRITICAL KEVNUCLEI
Apache Struts 2 Forced Multi OGNL Evaluation
Dec 11, 2020
CVSS 9.8
EPSS 0.94
CVE-2020-17529 CRITICAL
Apache NuttX <9.1.0, 10.0.0 - Memory Corruption
Dec 09, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-17528 CRITICAL
Apache NuttX <10.0.0 - Memory Corruption
Dec 09, 2020
CVSS 9.1
EPSS 0.02
CVE-2020-17531 CRITICAL
Apache Tapestry 4 - Deserialization
Dec 08, 2020
CVSS 9.8
EPSS 0.69
CVE-2020-17521 MEDIUM
Apache Groovy <4.0.0 - Info Disclosure
Dec 07, 2020
CVSS 5.5
EPSS 0.02
CVE-2020-13945 MEDIUM NUCLEI
Apache APISIX <1.6 - Privilege Escalation
Dec 07, 2020
CVSS 6.5
EPSS 0.93
CVE-2020-17527 HIGH
Apache Tomcat <10.0.0-M9, 9.0.39, 8.5.59 - Info Disclosure
Dec 03, 2020
CVSS 7.5
EPSS 0.11
CVE-2020-25649 HIGH
jackson-databind 2.6.0-2.6.7.3 - XML External Entity Injection
Dec 03, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-13956 MEDIUM
Apache HttpClient <4.5.13, 5.0.3 - SSRF
Dec 02, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-11990 LOW
Cordova (Android) - Info Disclosure
Dec 01, 2020
CVSS 3.3
EPSS 0.00
CVE-2020-27218 MEDIUM
Eclipse Jetty 9.4.0-9.4.34 - Sensitive Information Exposure via GZIP Request Body Reuse
Nov 28, 2020
CVSS 4.8
EPSS 0.01
CVE-2020-13942 CRITICAL NUCLEI
Apache Unomi 1.5.0-1.5.1 - Unauthenticated Remote Code Execution via /context.json Endpoint
Nov 24, 2020
CVSS 9.8
EPSS 0.94
CVE-2020-13958 HIGH
Apache OpenOffice 4.0.0-4.1.7 - Unauthenticated Arbitrary Executable Execution via Hyperlink in Scripting Events
Nov 17, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-26217 HIGH NUCLEI
XStream < 1.4.14 - Remote Code Execution via Blocklist Bypass
Nov 16, 2020
CVSS 8.0
EPSS 0.93
CVE-2020-13954 MEDIUM
Apache CXF < 3.3.8 - Reflected Cross-Site Scripting via styleSheetPath
Nov 12, 2020
CVSS 6.1
EPSS 0.15