apache

2,905 tracked vulnerabilities.

CVE-2016-8743 HIGH
Apache HTTP Server <2.2.32 & 2.4.25 - Info Disclosure
Jul 27, 2017
CVSS 7.5
EPSS 0.10
CVE-2016-2161 HIGH
Apache HTTP Server 2.4.0-2.4.23 - Denial of Service via mod_auth_digest Input
Jul 27, 2017
CVSS 7.5
EPSS 0.26
CVE-2016-0736 HIGH
Apache HTTP Server <2.4.24 - Info Disclosure
Jul 27, 2017
CVSS 7.5
EPSS 0.42
CVE-2016-6798 CRITICAL
Apache Sling XSS Protection API < 1.0.12 - XML External Entity Injection via Insecure SAX Parser
Jul 19, 2017
CVSS 9.8
EPSS 0.01
CVE-2016-5394 MEDIUM
Apache Sling XSS Protection API < 1.0.12 - Cross-Site Scripting via encodeForJSString Method
Jul 19, 2017
CVSS 6.1
EPSS 0.01
CVE-2016-6793 CRITICAL
Apache Wicket 1.5.0-1.5.16 - Deserialization of Untrusted Data in DiskFileItem
Jul 17, 2017
CVSS 9.1
EPSS 0.04
CVE-2016-8751 MEDIUM
Apache Ranger < 0.6.3 - Stored Cross-Site Scripting in Custom Policy Conditions
Jun 14, 2017
CVSS 4.8
EPSS 0.00
CVE-2016-8746 MEDIUM
Apache Ranger <0.6.3 - Info Disclosure
Jun 14, 2017
CVSS 5.9
EPSS 0.01
CVE-2016-5004 MEDIUM
Apache ws-xmlrpc 3.1.3 - Denial of Service via Content-Encoding Header Decompression
Jun 06, 2017
CVSS 6.5
EPSS 0.01
CVE-2016-3083 HIGH
Apache Hive < 1.2.2 and 2.0.x < 2.0.1 - Improper Certificate Validation
May 30, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-8741 HIGH
Apache Qpid Broker for Java <6.0.6, <6.1.1 - Info Disclosure
May 15, 2017
CVSS 7.5
EPSS 0.01
CVE-2016-6799 HIGH
Apache Cordova Android < 5.2.2 - Sensitive Information Exposure via Log File Insertion
May 09, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-4467 MEDIUM
Apache Qpid Proton - Improper Certificate Validation
May 02, 2017
CVSS 5.9
EPSS 0.00
CVE-2016-5396 HIGH
Apache Traffic Server 6.0.0-6.2.0 - Denial of Service via HPACK Bomb Attack
Apr 17, 2017
CVSS 7.5
EPSS 0.02
CVE-2016-4970 HIGH
Netty 4.0.20-4.0.36 - Denial of Service via Infinite Loop in OpenSslEngine
Apr 13, 2017
CVSS 7.5
EPSS 0.08
CVE-2016-6808 CRITICAL
Apache Tomcat JK Connector < 1.2.42 - Buffer Overflow
Apr 12, 2017
CVSS 9.8
EPSS 0.29
CVE-2016-0779 CRITICAL
Apache TomEE <1.7.4, <7.0.0-M3 - RCE
Apr 11, 2017
CVSS 9.8
EPSS 0.05
CVE-2016-6811 HIGH
Apache Hadoop 2.2.0-2.7.3 - Privilege Escalation to Root via YARN User
Apr 11, 2017
CVSS 8.8
EPSS 0.01
CVE-2016-6805 MEDIUM
Apache Ignite < 1.9 - XML External Entity Injection via Update-Notifier Documents
Apr 07, 2017
CVSS 5.9
EPSS 0.01
CVE-2016-8735 CRITICAL KEVNUCLEI
Apache Tomcat , 7.x , 8.x , 8.5.x , 9.x <6.0.48 <7.0.73 <8.0.39 <8.5.7 - Remote Code Execution
Apr 06, 2017
CVSS 9.8
EPSS 0.94
CVE-2016-6809 CRITICAL
Apache Tika < 1.14 - Remote Code Execution via MATLAB File Deserialization
Apr 06, 2017
CVSS 9.8
EPSS 0.07
CVE-2016-4976 MEDIUM
Apache Ambari 2.0.0-2.3.9 - Exposure of Sensitive Information via KDC Administrator Password
Mar 29, 2017
CVSS 5.5
EPSS 0.00
CVE-2016-6807 CRITICAL
Apache Ambari 2.4.0-2.4.1 - Unauthenticated Remote Code Execution via Custom Commands
Mar 28, 2017
CVSS 9.8
EPSS 0.01
CVE-2016-8749 CRITICAL
Apache Camel 2.16.0-2.16.4 2.17.0-2.17.4 2.18.0-2.18.1 - Remote Code Execution via Jackson Unmarshalling
Mar 28, 2017
CVSS 9.8
EPSS 0.12
CVE-2016-9775 HIGH
Debian Linux - Access Control
Mar 23, 2017
CVSS 7.8
EPSS 0.00