58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
Apache vulnerabilities
3430 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-1183 | MED 5.8 | apache tomcat Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exist | 6.2% | — |
| CVE-2020-1954 | MED 5.3 | apache cxf Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in- | 6.1% | — |
| CVE-2018-17197 | MED 6.5 | apache tika A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika. | 6.1% | — |
| CVE-2011-2088 | MED 5.0 | apache struts XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a differ | 6.1% | — |
| CVE-2020-1946 | CRIT 9.8 | apache spamassassin In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, use | 6.1% | — |
| CVE-2011-2087 | MED 4.3 | apache struts Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .ac | 6.1% | — |
| CVE-2013-6348 | MED 4.3 | apache struts Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/. | 6.1% | — |
| CVE-2007-1862 | MED 5.0 | apache http_server The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitiv | 6.1% | — |
| CVE-2015-7521 | HIGH 8.3 | apache hive The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations | 6.1% | — |
| CVE-2016-4460 | CRIT 9.8 | apache pony_mail Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication. | 6.1% | — |
| CVE-2016-6810 | MED 6.1 | apache activemq In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation. | 6.1% | — |
| CVE-2017-15706 | MED 5.3 | apache tomcat As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execut | 6.1% | — |
| CVE-2016-0782 | MED 5.4 | apache activemq The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory | 6.1% | — |
| CVE-2019-12423 | HIGH 7.5 | apache cxf Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local k | 6.1% | — |
| CVE-2002-2103 | MED 5.0 | apache http_server Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities. | 6.1% | — |
| CVE-2023-41080 | MED 6.1 | apache tomcat URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 thro | 6.0% | — |
| CVE-2017-9801 | HIGH 7.5 | apache commons_email When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers. | 6.0% | — |
| CVE-2021-37608 | CRIT 9.8 | apache ofbiz Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.ap | 6.0% | — |
| CVE-2021-45029 | CRIT 9.8 | apache shenyu Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 6.0% | — |
| CVE-2014-3503 | MED 5.0 | apache syncope Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack. | 6.0% | — |
| CVE-2013-2210 | HIGH 7.5 | apache xml_security_for_c\+\+ Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via m | 6.0% | — |
| CVE-2011-1582 | MED 4.3 | apache tomcat Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this v | 6.0% | — |
| CVE-2018-1328 | MED 6.1 | apache zeppelin Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph". | 6.0% | — |
| CVE-2003-0134 | MED 5.0 | apache http_server Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names. | 6.0% | — |
| CVE-2012-4418 | MED 5.8 | apache axis2 Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." | 6.0% | — |