58.507 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Apache
3430 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-10086 | HIGH 7.3 | apache commons_beanutils In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default charac | 28,4% | — |
| CVE-2022-22720 | CRIT 9.8 | apache http_server Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | 28,2% | — |
| CVE-2009-3720 | MED 5.0 | apache http_server The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 se | 27,9% | — |
| CVE-2019-9517 | HIGH 7.5 | apache http_server Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer | 27,9% | — |
| CVE-2006-5752 | MED 4.3 | apache http_server Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecif | 27,8% | — |
| CVE-2007-2353 | MED 5.0 | apache axis Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message. | 27,7% | — |
| CVE-2014-0002 | HIGH 7.5 | apache camel The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity ref | 27,4% | — |
| CVE-2002-0936 | MED 5.0 | apache tomcat The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). | 27,3% | — |
| CVE-2011-5057 | MED 5.0 | apache struts Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to | 27,2% | — |
| CVE-2002-1567 | MED 6.8 | apache tomcat Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script. | 27,1% | — |
| CVE-2013-6438 | MED 5.0 | apache http_server The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a craft | 26,8% | — |
| CVE-2009-0026 | MED 4.3 | apache jackrabbit Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp. | 26,8% | — |
| CVE-2020-11996 | HIGH 7.5 | apache tomcat A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connec | 26,7% | — |
| CVE-2007-4465 | MED 6.1 | apache http_server Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 c | 26,2% | — |
| CVE-2014-0098 | MED 5.0 | apache http_server The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during | 26,0% | — |
| CVE-1999-0045 | HIGH 7.5 | apache http_server List of arbitrary files on Web host via nph-test-cgi script. | 26,0% | — |
| CVE-2024-38473 | HIGH 8.1 | apache http_server Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, wh | 25,9% | — |
| CVE-1999-0236 | HIGH 7.5 | apache http_server ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. | 25,8% | — |
| CVE-2018-8033 | HIGH 7.5 | apache ofbiz In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain | 25,7% | — |
| CVE-2016-1182 | HIGH 8.2 | apache struts ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE- | 25,7% | — |
| CVE-2025-60021 | CRIT 9.8 | apache brpc Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate t | 25,7% | — |
| CVE-2005-3745 | MED 4.3 | apache struts Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an err | 25,7% | — |
| CVE-2005-4703 | MED 5.0 | apache tomcat Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nik | 25,7% | — |
| CVE-2000-0759 | MED 6.4 | apache tomcat Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path. | 25,7% | — |
| CVE-2022-32532 | CRIT 9.8 | apache shiro Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass. | 25,5% | — |