imPC@ndo IT

Apache vulnerabilities

3261 CVE

CVE-2016-3087
Critical 9.8

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

apache struts
0.81EPSS
CVE-2011-4858
Medium 5.0

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) …

apache tomcat
0.80EPSS
CVE-2020-13957
Critical 9.8

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The…

apache solr
0.79EPSS
CVE-2016-8740
High 7.5

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONT…

apache http_server
0.79EPSS
CVE-2022-23944
Critical 9.1

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

apache shenyu
0.79EPSS
CVE-2009-3548
High 7.5

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

apache tomcat
0.79EPSS
CVE-2020-13947
Medium 6.1

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

apache activemq · oracle communications_session_report_manager · oracle communications_session_route_manager
0.79EPSS
CVE-2018-10583
High 7.5

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an offi…

apache openoffice · canonical ubuntu_linux · debian debian_linux · libreoffice libreoffice · and 3 more
0.79EPSS
CVE-2025-66516
High 8.4

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers th…

apache tika
0.79EPSS
CVE-2024-56325
Critical 9.8

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d {\"username\":\"hack2\",\"password\":\"hack\",\"compone…

apache pinot
0.79EPSS
CVE-2020-13937
Medium 5.3

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's …

apache kylin
0.78EPSS
CVE-2024-53677
Critical 9.8

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affec…

apache struts
0.78EPSS
CVE-2010-1587
Medium 5.0

The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.

apache activemq
0.78EPSS
CVE-2020-27223
Medium 5.2

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due …

apache nifi · apache solr · apache spark · debian debian_linux · and 12 more
0.78EPSS
CVE-2022-24288
High 8.8

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

apache airflow
0.78EPSS
CVE-2014-0113
High 7.5

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted reques…

apache struts
0.78EPSS
CVE-2021-21341
High 7.5

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such …

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · and 9 more
0.78EPSS
CVE-2019-0192
Critical 9.8

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote…

apache solr · netapp storage_automation_store
0.78EPSS
CVE-2016-0709
High 7.2

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a …

apache jetspeed
0.77EPSS
CVE-2007-2449
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to …

apache tomcat
0.77EPSS
CVE-2021-41303
Critical 9.8

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

apache shiro · oracle financial_services_crime_and_compliance_management_studio
0.77EPSS
CVE-2021-21346
Medium 6.1

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · and 12 more
0.76EPSS
CVE-2021-21344
Medium 5.3

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · and 12 more
0.76EPSS
CVE-2023-32007
High 8.8

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL…

apache spark
0.76EPSS
CVE-2007-6388
Medium 4.3

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via un…

apache http_server
0.76EPSS