58.493 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Apache
3422 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-12616 | HIGH 7.5 | apache tomcat When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. | 70,1% | — |
| CVE-2018-1303 | HIGH 7.5 | apache http_server A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_ | 69,8% | — |
| CVE-2002-0661 | HIGH 7.5 | apache http_server Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters. | 69,7% | — |
| CVE-2024-38472 | HIGH 7.5 | apache http_server SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access | 69,5% | — |
| CVE-2024-43441 | CRIT 9.8 | apache hugegraph Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue. | 69,4% | — |
| CVE-2022-22719 | HIGH 7.5 | apache http_server A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | 69,1% | — |
| CVE-2019-17571 | CRIT 9.8 | apache bookkeeper Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data | 69,1% | — |
| CVE-2022-44635 | HIGH 8.8 | apache fineract Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and pr | 68,8% | — |
| CVE-2025-27817 | HIGH 7.5 | apache kafka A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and " | 68,8% | — |
| CVE-2015-7611 | HIGH 8.1 | apache james_server Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors. | 68,6% | — |
| CVE-2020-13951 | HIGH 7.5 | apache openmeetings Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | 68,6% | — |
| CVE-2023-50290 | MED 6.5 | apache solr Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variables to hide, | 68,4% | — |
| CVE-2020-13942 | CRIT 9.8 | apache unomi It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly | 68,3% | — |
| CVE-2021-26691 | CRIT 9.8 | apache http_server In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow | 68,3% | — |
| CVE-2019-0233 | HIGH 7.5 | apache struts An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload. | 68,0% | — |
| CVE-2025-30676 | MED 6.1 | apache ofbiz Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue. | 67,6% | — |
| CVE-2022-25813 | HIGH 7.5 | apache ofbiz In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in th | 67,3% | — |
| CVE-2022-23305 | CRIT 9.8 | apache log4j By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate | 66,5% | — |
| CVE-2018-11770 | MED 4.2 | apache spark From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for auth | 65,8% | — |
| CVE-2021-26690 | HIGH 7.5 | apache http_server Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service | 65,3% | — |
| CVE-2024-54676 | CRIT 9.8 | apache openmeetings Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads t | 64,9% | — |
| CVE-2008-0455 | MED 4.3 | apache http_server Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inje | 64,8% | — |
| CVE-2021-34798 | HIGH 7.5 | apache http_server Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | 64,5% | — |
| CVE-2025-55752 | HIGH 7.5 | apache tomcat Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query paramete | 64,4% | — |
| CVE-2021-40865 | CRIT 9.8 | apache storm An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrad | 64,2% | — |