Apache
apache
3,131 CVEs • 384 products
Products (384)
Click to collapseToggle
Products (384)
Click to collapse
CVEs (3,131)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache DebianFedoraproject+1 more4Debian Linux FedoraStruts+1 moreJun 17, 2026 Dec 16, 2020 N/A· v4 7.7 HIGH· v3 5.0 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remot...Show more |
In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack. |
In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field. |
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but the implemented fix in...Show more |
2Apache Oracle8Business Intelligence Communications Diameter Intelligence HubCommunications Policy Management+5 moreJun 17, 2026 Dec 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. |
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in...Show more |
Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP pa...Show more |
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without auth...Show more |
3Apache NetappOracle21Agile Engineering Data Management Agile PlmAgile Plm Mcad Connector+18 moreJun 17, 2026 Dec 7, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potential...Show more |
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5. |
4Apache DebianNetapp+1 more12Blockchain Platform Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Policy+9 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 c...Show more |
6Apache FasterxmlFedoraproject+3 more39Agile Plm Agile Product Lifecycle Management Integration PackBanking Apis+36 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is...Show more |
4Apache NetappOracle+1 more17Active Iq Unified Manager Commerce Guided SearchCommunications Cloud Native Core Service Communication Proxy+14 moreJun 17, 2026 Dec 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request executio...Show more |
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) And...Show more |
5Apache DebianEclipse+2 more17Blockchain Platform Communications Converged Application Server Service ControllerCommunications Offline Mediation Controller+14 moreJun 17, 2026 Nov 28, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto...Show more |
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completel...Show more |
A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service atta...Show more |
A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditi...Show more |
5Apache DebianNetapp+2 more15Activemq Banking Cash ManagementBanking Corporate Lending Process Management+12 moreJun 17, 2026 Nov 16, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on b...Show more |
2Apache Oracle18Api Gateway BatikBusiness Intelligence+15 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause...Show more |