imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2021-27644
Alta 8.8

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)

apache dolphinscheduler
0.02EPSS
CVE-2025-29953
Critica 9.8

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserializatio…

apache activemq_nms_openwire
0.02EPSS
CVE-2021-37533
Media 6.5

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may le…

apache commons_net · debian debian_linux
0.02EPSS
CVE-2017-15700
Alta 8.8

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.

apache sling_authentication_service
0.02EPSS
CVE-2024-26280
Media 4.7

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permitted to view. With 2.8.2 and newer, Ops and Viewer users do n…

apache airflow
0.02EPSS
CVE-2021-25642
Alta 8.8

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users shou…

apache hadoop
0.02EPSS
CVE-2022-46751
Alta 8.2

Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML file…

apache ivy
0.02EPSS
CVE-2023-42794
Media 5.9

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service …

apache tomcat
0.02EPSS
CVE-2020-1955
Critica 9.8

CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the long standing setting `require_valid_user`, which in turn re…

apache couchdb
0.02EPSS
CVE-2019-12421
Alta 8.8

When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used f…

apache nifi
0.02EPSS
CVE-2021-38296
Alta 7.5

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an i…

apache spark · oracle financial_services_crime_and_compliance_management_studio
0.02EPSS
CVE-2019-0226
Media 4.9

Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Kara…

apache karaf
0.02EPSS
CVE-2010-2234
Media 6.8

Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.

apache couchdb
0.02EPSS
CVE-2023-28708
Media 4.3

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0…

apache tomcat
0.02EPSS
CVE-2026-66713
Critica 9.8

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthentic…

apache axis2\/java
0.02EPSS
CVE-2023-25692
Alta 7.5

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.

apache apache-airflow-providers-google
0.02EPSS
CVE-2022-29158
Alta 7.5

Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599

apache ofbiz
0.02EPSS
CVE-2017-5658
Media 5.3

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies,…

apache pony_mail
0.02EPSS
CVE-2025-52434
Alta 7.5

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue aff…

apache tomcat
0.02EPSS
CVE-2022-39944
Alta 8.8

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and malicious par…

apache linkis
0.02EPSS
CVE-2023-27603
Critica 9.8

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

apache linkis
0.02EPSS
CVE-2020-1945
Media 6.3

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the tem…

apache ant · canonical ubuntu_linux · fedoraproject fedora · opensuse leap · e altri 46
0.02EPSS
CVE-2017-7680
Alta 7.5

Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.

apache openmeetings
0.02EPSS
CVE-2017-9806
Alta 7.8

A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in a…

apache openoffice
0.02EPSS
CVE-2023-48291
Media 4.3

Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no ac…

apache airflow
0.02EPSS