apache
2,904 tracked vulnerabilities.
CVE-2019-10080
MEDIUM
Apache NiFi 1.3.0-1.9.2 - XML External Entity Injection in XMLFileLookupService
Nov 19, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-12422
HIGH
Apache Shiro <1.4.2 - Info Disclosure
Nov 18, 2019
CVSS 7.5
EPSS 0.55
CVE-2019-12409
CRITICAL
Apache Solr 8.1.1-8.2.0 - Unauthenticated Remote Code Execution via Insecure JMX Configuration
Nov 18, 2019
CVSS 9.8
EPSS 0.83
CVE-2019-10070
MEDIUM
Apache Atlas 0.8.3 and 1.1.0 - Stored Cross-Site Scripting in Search Functionality
Nov 18, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-10172
HIGH
org.codehaus.jackson:jackson-mapper-asl:1.9.x - XXE
Nov 18, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-12410
HIGH
Apache Arrow <0.14.1 - Memory Corruption
Nov 08, 2019
CVSS 7.5
EPSS 0.05
CVE-2019-12408
HIGH
Apache Arrow <0.14.1 - Memory Corruption
Nov 08, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-12419
CRITICAL
Oracle Retail Order Broker - Incorrect Authorization in OpenId Connect Access Token Service
Nov 06, 2019
CVSS 9.8
EPSS 0.11
CVE-2019-12406
MEDIUM
Apache CXF < 3.2.11 - Denial of Service via Unrestricted Message Attachments
Nov 06, 2019
CVSS 6.5
EPSS 0.04
CVE-2019-10084
HIGH
Apache Impala 2.7.0-3.2.0 - Auth Bypass
Nov 05, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-12417
MEDIUM
Apache Airflow < 1.10.5 - Authenticated Stored Cross-Site Scripting and Local File Disclosure
Oct 30, 2019
CVSS 4.8
EPSS 0.01
CVE-2019-0210
HIGH
Apache Thrift 0.9.3-0.12.0 - Out-of-bounds Read via Invalid JSON Input
Oct 29, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-0205
HIGH
Apache Thrift <= 0.12.0 - Denial of Service via Infinite Loop
Oct 29, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-12415
MEDIUM
Apache POI < 4.1.0 - XML External Entity Injection via XSSFExportToXml
Oct 23, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10079
HIGH
Apache Traffic Server <7.1.7-8.0.4 - DoS
Oct 22, 2019
CVSS 7.5
EPSS 0.05
CVE-2019-17195
CRITICAL
Connect2id Nimbus JOSE+JWT < 7.9 - Denial of Service and Authentication Bypass via JWT Parsing
Oct 15, 2019
CVSS 9.8
EPSS 0.04
CVE-2019-17359
HIGH
Bouncycastle Bc-java < 3.0.2.1 - Resource Allocation Without Limits
Oct 08, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-0231
HIGH
Apache MINA < 2.0.21 and 2.1.0 - Cleartext Transmission of Sensitive Information via SSL/TLS Connection Handling
Oct 01, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-10097
HIGH
Apache HTTP Server 2.4.32-2.4.39 - Buffer Overflow
Sep 26, 2019
CVSS 7.2
EPSS 0.24
CVE-2019-10092
MEDIUM
NUCLEI
Apache HTTP Server 2.4.0-2.4.39 - Cross-Site Scripting in mod_proxy Error Page
Sep 26, 2019
CVSS 6.1
EPSS 0.82
CVE-2019-10082
CRITICAL
Apache HTTP Server <2.4.40 - Use After Free
Sep 26, 2019
CVSS 9.1
EPSS 0.42
CVE-2019-0203
HIGH
Apache Subversion <= 1.9.10, 1.10.4, 1.12.0 - Denial of Service via Protocol Command Sequence
Sep 26, 2019
CVSS 7.5
EPSS 0.04
CVE-2019-10098
MEDIUM
NUCLEI
Apache HTTP Server 2.4.0-2.4.39 - Open Redirect via Encoded Newlines in mod_rewrite
Sep 25, 2019
CVSS 6.1
EPSS 0.77
CVE-2019-12407
MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via Remember Parameter
Sep 23, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-10090
MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via Plugin Link Invocation
Sep 23, 2019
CVSS 6.1
EPSS 0.04
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
cxf 46
nifi 46
solr 46
cloudstack 45
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters