Apache
apache
3,131 CVEs • 384 products
Products (384)
Click to collapseToggle
Products (384)
Click to collapse
CVEs (3,131)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can b...Show more |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts()...Show more |
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module. |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue af...Show more |
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability. |
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial...Show more |
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 |
2Apache Debian2Debian Linux Maven Shared UtilsJun 17, 2026 May 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. |
In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacke...Show more |
2Apache Oracle2Primavera Unifier TikaJun 17, 2026 May 16, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users...Show more |
2Apache Oracle2Primavera Unifier TikaJun 17, 2026 May 16, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. |
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application wil...Show more |
3Apache DebianOracle3Debian Linux Hospitality Cruise Shipboard Property Management SystemTomcatJun 17, 2026 May 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted...Show more |
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow...Show more |
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when...Show more |
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure. |
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly...Show more |