Apache
apache
3,131 CVEs • 384 products
Products (384)
Click to collapseToggle
Products (384)
Click to collapse
CVEs (3,131)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Oracle2Graalvm NetbeansJun 17, 2026 Mar 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected b...Show more |
2Apache Oracle2Graalvm NetbeansJun 17, 2026 Mar 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injec...Show more |
2Apache Debian2Debian Linux ShiroJun 17, 2026 Mar 25, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions. |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions. |
4Apache CanonicalDebian+1 more6Business Process Management Suite Communications Messaging ServerDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. |
4Apache CanonicalDebian+1 more6Business Process Management Suite Communications Messaging ServerDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. |
we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default. |
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cl...Show more |
2Apache Oracle3Commons Configuration Database ServerHealthcare FoundationJun 17, 2026 Mar 13, 2020 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2....Show more |
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java...Show more |
2Apache Redhat10Cxf Jboss Business Rules Management SystemJboss Enterprise Application Platform+7 moreNov 21, 2024 Mar 11, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. |
3Apache FasterxmlRedhat8Decision Manager GeodeJackson Databind+5 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more |
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability. |
7Apache BlackberryDebian+4 more21Agile Engineering Data Management Agile PlmCommunications Element Manager+18 moreJun 17, 2026 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Apache DebianNetapp+2 more16Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+13 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed...Show more |
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries. |
It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks...Show more |