apache
2,904 tracked vulnerabilities.
CVE-2018-17195
HIGH
Apache NiFi 1.0.0-1.7.1 - Cross-Site Request Forgery via Template Upload API
Dec 19, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-17194
HIGH
Apache NiFi 1.0.0-1.7.1 - Denial of Service via DELETE Request Content-Length Handling
Dec 19, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-17193
MEDIUM
Apache NiFi 1.0.0-1.7.1 - Reflected Cross-Site Scripting via X-ProxyContextPath Header
Dec 19, 2018
CVSS 6.1
EPSS 0.02
CVE-2018-17192
MEDIUM
Apache NiFi <1.8.0 - Info Disclosure
Dec 19, 2018
CVSS 6.5
EPSS 0.01
CVE-2018-8033
HIGH
NUCLEI
Apache OFBiz 16.11.01-16.11.04 - Info Disclosure
Dec 13, 2018
CVSS 7.5
EPSS 0.92
CVE-2018-11766
HIGH
Apache Hadoop <2.7.7 - Privilege Escalation
Nov 27, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-17190
CRITICAL
Apache Spark - Unauthenticated Remote Code Execution via Master Host
Nov 19, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-8009
HIGH
Apache Hadoop Path Traversal via Zip Slip
Nov 13, 2018
CVSS 8.8
EPSS 0.05
CVE-2018-17187
HIGH
Apache Qpid Proton-J 0.3-0.29.0 - Improper Certificate Validation in TLS Transport Wrapper
Nov 13, 2018
CVSS 7.4
EPSS 0.00
CVE-2018-1314
MEDIUM
Apache Hive < 2.3.3 and 3.1.0 - Missing Authorization for EXPLAIN Operation
Nov 08, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-11777
HIGH
Apache Hive <2.3.3, <3.1.0 - Info Disclosure
Nov 08, 2018
CVSS 8.1
EPSS 0.00
CVE-2018-8021
CRITICAL
Apache Superset < 0.23 - Remote Code Execution via Pickle Deserialization
Nov 07, 2018
CVSS 9.8
EPSS 0.64
CVE-2018-17186
HIGH
Apache Syncope - XML External Entity Injection
Nov 06, 2018
CVSS 7.2
EPSS 0.01
CVE-2018-17184
MEDIUM
Apache Syncope - Stored Cross-Site Scripting
Nov 06, 2018
CVSS 5.4
EPSS 0.01
CVE-2018-11759
HIGH
NUCLEI
Apache Tomcat JK Connector 1.2.0-1.2.44 - Path Traversal via Request Path Normalization
Oct 31, 2018
CVSS 7.5
EPSS 0.94
CVE-2018-11792
CRITICAL
Apache Impala < 3.0.1 - Incorrect Permission Assignment for Critical Resource
Oct 24, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-11785
MEDIUM
Apache Impala < 3.0.1 - Missing Authorization Check
Oct 24, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-11804
HIGH
Apache Spark 1.3.0-2.2.3 - Information Disclosure via Zinc Server
Oct 24, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-8006
MEDIUM
NUCLEI
Apache ActiveMQ 5.0.0-5.15.5 - Cross-Site Scripting via QueueFilter Parameter
Oct 10, 2018
CVSS 6.1
EPSS 0.78
CVE-2018-11796
HIGH
Apache Tika 0.1-1.19 - XML External Entity Injection via SAXParser Reset
Oct 09, 2018
CVSS 7.5
EPSS 0.04
CVE-2018-11797
MEDIUM
Apache PDFBox 1.8.0-1.8.15 and 2.0.0RC1-2.0.11 - Denial of Service via Page Tree Parsing
Oct 05, 2018
CVSS 5.5
EPSS 0.02
CVE-2018-11778
HIGH
Apache Ranger < 1.2.0 - Stack-based Buffer Overflow in UnixAuthenticationService
Oct 05, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-11784
MEDIUM
NUCLEI
Apache Tomcat 7.0.23-7.0.90, 8.5.0-8.5.33, 9.0.0.M1-9.0.11 - Open Redirect via Default Servlet
Oct 04, 2018
CVSS 4.3
EPSS 0.83
CVE-2018-11763
MEDIUM
Apache HTTP Server 2.4.17-2.4.34 - DoS
Sep 25, 2018
CVSS 5.9
EPSS 0.22
CVE-2018-14889
HIGH
CouchDB - Local Code Execution
Sep 21, 2018
CVSS 7.8
EPSS 0.00
Products
http_server 317
tomcat 254
airflow 120
struts 90
traffic_server 82
ofbiz 74
superset 68
openoffice 60
activemq 57
subversion 47
cxf 46
nifi 46
solr 46
cloudstack 45
camel 40
hadoop 37
inlong 32
openmeetings 28
dolphinscheduler 27
ambari 26
tika 25
jspwiki 24
geode 23
spark 22
wicket 22
zeppelin 22
kylin 21
ranger 21
archiva 20
couchdb 20
Quick Filters