Apache
apache
3,131 CVEs • 384 products
Products (384)
Click to collapseToggle
Products (384)
Click to collapse
CVEs (3,131)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache DebianOracle12Agile Plm Communications Cloud Native Core PolicyCommunications Cloud Native Core Security Edge Protection Proxy+9 moreJun 17, 2026 Mar 1, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tom...Show more |
3Apache DebianOracle12Agile Plm Communications Cloud Native Core PolicyCommunications Cloud Native Core Security Edge Protection Proxy+9 moreJun 17, 2026 Mar 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to...Show more |
5Apache DebianEclipse+2 more16Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services+13 moreJun 17, 2026 Feb 26, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may en...Show more |
2Apache Fedoraproject2Fedora Xmlgraphics CommonsJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnera...Show more |
4Apache DebianFedoraproject+1 more22Agile Engineering Data Management Banking ApisBanking Digital Experience+19 moreJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the...Show more |
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with th...Show more |
2Apache Netapp2Myfaces Oncommand InsightJun 17, 2026 Feb 19, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tok...Show more |
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to b...Show more |
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_co...Show more |
2Apache Systeminformation2Cordova SysteminformationJun 17, 2026 Feb 16, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 t...Show more |
2Apache Oracle4Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core PolicyHive+1 moreJun 17, 2026 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. |
2Apache Oracle3Activemq Communications Session Report ManagerCommunications Session Route ManagerJun 17, 2026 Feb 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0. |
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. |
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A mi...Show more |
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in...Show more |
2Apache Netapp3Activemq Artemis ArtemisOncommand Workflow AutomationJun 17, 2026 Jan 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production...Show more |
4Apache DebianNetapp+1 more9Activemq Activemq ArtemisArtemis+6 moreJun 17, 2026 Jan 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.1...Show more |
2Apache Oracle3Financial Services Crime And Compliance Management Studio HadoopSolrJun 17, 2026 Jan 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification. |
4Apache AppleDebian+1 more5Bookkeeper Debian LinuxMac Os X+2 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service. |
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arb...Show more |