Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. T...Show more |
4Apache FedoraprojectGradle+1 more37Agile Engineering Data Management AntApi Gateway+34 moreJun 17, 2026 Oct 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file...Show more |
In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the...Show more |
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run. |
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. |
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled. |
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. |
While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `o...Show more |
Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability. |
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited...Show more |
2Apache Oracle5Communications Policy Management Financial Services Data Integration HubFinancial Services Market Risk Measurement And Management+2 moreJun 17, 2026 Sep 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload. |
2Apache Oracle5Communications Policy Management Financial Services Data Integration HubFinancial Services Market Risk Measurement And Management+2 moreJun 17, 2026 Sep 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. |
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system. |
3Apache DebianOracle4Activemq Communications Diameter Signaling RouterDebian Linux+1 moreJun 17, 2026 Sep 10, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method...Show more |
2Apache Oracle7Activemq Communications Diameter Signaling RouterCommunications Element Manager+4 moreJun 17, 2026 Sep 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open t...Show more |
To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load time of the project. Apache NetBeans up t...Show more |
2Apache Netapp2Cassandra Oncommand InsightJun 17, 2026 Sep 1, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI reg...Show more |
2Apache Debian2Debian Linux ShiroJun 17, 2026 Aug 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass. |
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replic...Show more |
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during renderi...Show more |