Apache
apache
3,131 CVEs • 384 products
Products (384)
Click to collapseToggle
Products (384)
Click to collapse
CVEs (3,131)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not i...Show more |
4Apache CanonicalDebian+1 more4Camel Debian LinuxHtmlunit+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded...Show more |
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06 |
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stea...Show more |
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. With this bug unpa...Show more |
6Apache CanonicalDebian+3 more7Debian Linux FedoraJboss Amq Clients+4 moreJun 17, 2026 Jan 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. |
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password...Show more |
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers. |
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing...Show more |
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property whe...Show more |
5Apache CanonicalDebian+2 more5Debian Linux FedoraSoftware Collections+2 moreJun 17, 2026 Jan 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it...Show more |
2Apache Oracle7Commerce Guided Search Communications Element ManagerCommunications Session Report Manager+4 moreJun 17, 2026 Jan 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious ac...Show more |
2Apache Oracle8Commerce Guided Search Communications Diameter Signaling RouterCommunications Element Manager+5 moreJun 17, 2026 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the servi...Show more |
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in...Show more |
In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "...Show more |
2Apache Oracle13Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Liquidity Management+10 moreJun 17, 2026 Jan 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized...Show more |
2Apache Oracle3Cordova Inappbrowser Instantis EnterprisetrackRetail Xstore Point Of ServiceJun 17, 2026 Jan 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. |
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If...Show more |
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same. |
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. |