apache
2,904 tracked vulnerabilities.
CVE-2019-12404
MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via Plugin Link Invocation
Sep 23, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-10089
MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via WYSIWYG Editor Plugin Link
Sep 23, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-10087
MEDIUM
Apache JSPWiki < 2.11.0.M5 - Cross-Site Scripting via Plugin Link Invocation
Sep 23, 2019
CVSS 6.1
EPSS 0.04
CVE-2019-10071
CRITICAL
Apache Tapestry - Timing Side Channel in HMAC Verification
Sep 16, 2019
CVSS 9.8
EPSS 0.10
CVE-2019-0207
HIGH
Apache Tapestry 5.4.0-5.4.4 and tapestry-core 5.4.0-5.4.5 - Path Traversal via Backslash Character
Sep 16, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-0195
CRITICAL
Apache Tapestry 5.4.0-5.4.2 and 5.4.0-5.4.4 - Remote Code Execution via Classpath Asset File URL Manipulation
Sep 16, 2019
CVSS 9.8
EPSS 0.16
CVE-2019-10074
CRITICAL
Apache OFBiz 16.11.01-16.11.04 - Remote Code Execution via Freemarker Markup in Form Widget Textarea
Sep 11, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-10073
MEDIUM
Apache OFBiz 16.11.01-16.11.05 - Stored Cross-Site Scripting in ecommerce Template Screens
Sep 11, 2019
CVSS 6.1
EPSS 0.01
CVE-2019-0189
CRITICAL
Apache OFBiz 16.11.01-16.11.05 - Remote Code Execution via HttpEngine ServiceContext Deserialization
Sep 11, 2019
CVSS 9.8
EPSS 0.15
CVE-2019-12401
HIGH
Apache Solr 1.3.0-1.4.1, 3.1.0-3.6.2, 4.0.0-4.10.4 - XML Entity Expansion via Update Handler
Sep 10, 2019
CVSS 7.5
EPSS 0.33
CVE-2019-12405
CRITICAL
Apache Traffic Control <3.0.1 - Auth Bypass
Sep 09, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-12402
HIGH
Apache Commons Compress <1.19 - DoS
Aug 30, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-15752
HIGH
KEV
Docker Desktop Community Edition < 2.1.0.1 - Privilege Escalation via Trojan Horse docker-credential-wincred.exe
Aug 28, 2019
CVSS 7.8
EPSS 0.46
CVE-2019-15544
HIGH
rust-protobuf < 1.7.5 and protobuf < 2.6.0 - Denial of Service via Vec::reserve Memory Exhaustion
Aug 26, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-12400
MEDIUM
Apache Santuario XML Security for Java <2.0.3 - Info Disclosure
Aug 23, 2019
CVSS 5.5
EPSS 0.01
CVE-2019-10086
HIGH
Apache Commons Beanutils 1.9.2 - Info Disclosure
Aug 20, 2019
CVSS 7.3
EPSS 0.01
CVE-2019-10081
HIGH
Apache HTTP Server 2.4.20-2.4.39 - Out-of-bounds Write via H2PushResource
Aug 15, 2019
CVSS 7.5
EPSS 0.37
CVE-2019-9518
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Empty Frame Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.04
CVE-2019-9517
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Window Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.05
CVE-2019-9516
MEDIUM
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Header Leak
Aug 13, 2019
CVSS 6.5
EPSS 0.02
CVE-2019-9515
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Settings Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.09
CVE-2019-9514
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Reset Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.09
CVE-2019-9513
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Priority Tree Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.07
CVE-2019-9512
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Ping Flood
Aug 13, 2019
CVSS 7.5
EPSS 0.51
CVE-2019-9511
HIGH
SwiftNIO 1.0.0-1.3.9 - Denial of Service via HTTP/2 Window Size Manipulation
Aug 13, 2019
CVSS 7.5
EPSS 0.14
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
cxf 46
nifi 46
solr 46
cloudstack 45
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters