apache

2,904 tracked vulnerabilities.

CVE-2019-12404 MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via Plugin Link Invocation
Sep 23, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-10089 MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via WYSIWYG Editor Plugin Link
Sep 23, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-10087 MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via Plugin Link Invocation
Sep 23, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-10071 CRITICAL
Apache Tapestry - Timing Side Channel in HMAC Verification
Sep 16, 2019
CVSS 9.8
EPSS 0.10
CVE-2019-0207 HIGH
Apache Tapestry 5.4.0-5.4.4 and tapestry-core 5.4.0-5.4.5 - Path Traversal via Backslash Character
Sep 16, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-0195 CRITICAL
Apache Tapestry 5.4.0-5.4.2 and 5.4.0-5.4.4 - Remote Code Execution via Classpath Asset File URL Manipulation
Sep 16, 2019
CVSS 9.8
EPSS 0.16
CVE-2019-10074 CRITICAL
Apache OFBiz 16.11.01-16.11.04 - Remote Code Execution via Freemarker Markup in Form Widget Textarea
Sep 11, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-10073 MEDIUM
Apache OFBiz 16.11.01-16.11.05 - Stored Cross-Site Scripting in ecommerce Template Screens
Sep 11, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-0189 CRITICAL
Apache OFBiz 16.11.01-16.11.05 - Remote Code Execution via HttpEngine ServiceContext Deserialization
Sep 11, 2019
CVSS 9.8
EPSS 0.15
CVE-2019-12401 HIGH
Apache Solr 1.3.0-1.4.1, 3.1.0-3.6.2, 4.0.0-4.10.4 - XML Entity Expansion via Update Handler
Sep 10, 2019
CVSS 7.5
EPSS 0.33
CVE-2019-12405 CRITICAL
Apache Traffic Control <3.0.1 - Auth Bypass
Sep 09, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-12402 HIGH
Apache Commons Compress <1.19 - DoS
Aug 30, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-15752 HIGH KEV
Docker Desktop Community Edition < 2.1.0.1 - Privilege Escalation via Trojan Horse docker-credential-wincred.exe
Aug 28, 2019
CVSS 7.8
EPSS 0.46
CVE-2019-15544 HIGH
rust-protobuf < 1.7.5 and protobuf < 2.6.0 - Denial of Service via Vec::reserve Memory Exhaustion
Aug 26, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-12400 MEDIUM
Apache Santuario XML Security for Java <2.0.3 - Info Disclosure
Aug 23, 2019
CVSS 5.5
EPSS 0.01
CVE-2019-10086 HIGH
Apache Commons Beanutils 1.9.2 - Info Disclosure
Aug 20, 2019
CVSS 7.3
EPSS 0.01
CVE-2019-10081 HIGH
Apache HTTP Server 2.4.20-2.4.39 - Out-of-bounds Write via H2PushResource
Aug 15, 2019
CVSS 7.5
EPSS 0.37
CVE-2019-9518 HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Empty Frame Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.04
CVE-2019-9517 HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Window Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.05
CVE-2019-9516 MEDIUM
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Header Leak
Aug 13, 2019
CVSS 6.5
EPSS 0.02
CVE-2019-9515 HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Settings Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.09
CVE-2019-9514 HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Reset Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.09
CVE-2019-9513 HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Priority Tree Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.07
CVE-2019-9512 HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Ping Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.51
CVE-2019-9511 HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Window Size Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.14