imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2016-3087
Critica 9.8

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

apache struts
0.81EPSS
CVE-2011-4858
Media 5.0

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) …

apache tomcat
0.80EPSS
CVE-2020-13957
Critica 9.8

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The…

apache solr
0.79EPSS
CVE-2016-8740
Alta 7.5

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONT…

apache http_server
0.79EPSS
CVE-2022-23944
Critica 9.1

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

apache shenyu
0.79EPSS
CVE-2009-3548
Alta 7.5

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

apache tomcat
0.79EPSS
CVE-2020-13947
Media 6.1

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

apache activemq · oracle communications_session_report_manager · oracle communications_session_route_manager
0.79EPSS
CVE-2018-10583
Alta 7.5

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an offi…

apache openoffice · canonical ubuntu_linux · debian debian_linux · libreoffice libreoffice · e altri 3
0.79EPSS
CVE-2025-66516
Alta 8.4

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers th…

apache tika
0.79EPSS
CVE-2024-56325
Critica 9.8

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d {\"username\":\"hack2\",\"password\":\"hack\",\"compone…

apache pinot
0.79EPSS
CVE-2020-13937
Media 5.3

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's …

apache kylin
0.78EPSS
CVE-2024-53677
Critica 9.8

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affec…

apache struts
0.78EPSS
CVE-2010-1587
Media 5.0

The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.

apache activemq
0.78EPSS
CVE-2020-27223
Media 5.2

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due …

apache nifi · apache solr · apache spark · debian debian_linux · e altri 12
0.78EPSS
CVE-2022-24288
Alta 8.8

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

apache airflow
0.78EPSS
CVE-2014-0113
Alta 7.5

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted reques…

apache struts
0.78EPSS
CVE-2021-21341
Alta 7.5

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such …

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 9
0.78EPSS
CVE-2019-0192
Critica 9.8

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote…

apache solr · netapp storage_automation_store
0.78EPSS
CVE-2016-0709
Alta 7.2

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a …

apache jetspeed
0.77EPSS
CVE-2007-2449
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to …

apache tomcat
0.77EPSS
CVE-2021-41303
Critica 9.8

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

apache shiro · oracle financial_services_crime_and_compliance_management_studio
0.77EPSS
CVE-2021-21346
Media 6.1

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.76EPSS
CVE-2021-21344
Media 5.3

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.76EPSS
CVE-2023-32007
Alta 8.8

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL…

apache spark
0.76EPSS
CVE-2007-6388
Media 4.3

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via un…

apache http_server
0.76EPSS