imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2021-33192
Medium 6.1

A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive).

apache jena_fuseki
0.03EPSS
CVE-2016-5396
High 7.5

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

apache traffic_server
0.03EPSS
CVE-2015-5207
Medium 5.3

Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.

apache cordova
0.03EPSS
CVE-2024-24795
Medium 6.3

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixe…

apache http_server · apple macos · broadcom fabric_operating_system · debian debian_linux · and 3 more
0.03EPSS
CVE-2020-9491
High 7.5

In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication…

apache nifi
0.03EPSS
CVE-2020-1936
Medium 6.1

A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.

apache ambari
0.03EPSS
CVE-2026-55957
High 7.3

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-…

apache tomcat
0.03EPSS
CVE-2016-3085
Medium 6.5

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related …

apache cloudstack
0.03EPSS
CVE-2021-40110
High 7.5

In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 …

apache james
0.03EPSS
CVE-2017-7685
Medium 5.3

Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.

apache openmeetings
0.03EPSS
CVE-2022-25312
Critical 9.1

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacke…

apache any23
0.03EPSS
CVE-2022-27479
Critical 9.8

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

apache superset
0.03EPSS
CVE-2020-17529
Critical 9.8

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impacts bui…

apache nuttx
0.03EPSS
CVE-2017-5640
Critical 9.8

It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If the malicious server responds with 'COMPL…

apache impala
0.03EPSS
CVE-2022-26779
High 7.5

Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that…

apache cloudstack
0.03EPSS
CVE-2023-28935
High 8.8

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA…

apache unstructured_information_management_architecture
0.03EPSS
CVE-2017-12632
High 7.5

A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x relea…

apache nifi
0.03EPSS
CVE-2021-27576
High 7.5

If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0

apache openmeetings
0.03EPSS
CVE-2020-11977
High 7.2

In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execu…

apache syncope
0.03EPSS
CVE-2022-42920
Critical 9.8

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pas…

apache commons_bcel · fedoraproject fedora
0.03EPSS
CVE-2022-42468
Critical 9.8

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.…

apache flume
0.03EPSS
CVE-2022-22932
Medium 5.3

Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: http…

apache karaf
0.03EPSS
CVE-2020-1925
High 7.5

Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect t…

apache olingo
0.03EPSS
CVE-2021-42009
Medium 4.3

An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an arbitra…

apache traffic_control
0.03EPSS
CVE-2019-12398
Medium 4.8

In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected.

apache airflow
0.03EPSS