Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Oracle4Camel Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 moreJun 17, 2026 May 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |
2Apache Oracle5Camel Communications Diameter Intelligence HubCommunications Diameter Signaling Router+2 moreJun 17, 2026 May 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0. |
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be cr...Show more |
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in bar...Show more |
5Apache CanonicalFedoraproject+2 more50Agile Engineering Data Management AntBanking Enterprise Collections+47 moreJun 17, 2026 May 14, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replacer...Show more |
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTO...Show more |
4Apache FedoraprojectNetapp+1 more7Application Testing Suite FedoraHospitality Opera 5+4 moreNov 21, 2024 May 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration...Show more |
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remo...Show more |
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache...Show more |
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query strin...Show more |
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host |
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. |
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permit...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Apr 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack. |
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely. |
4Apache DebianOracle+1 more46Communications Application Session Controller Communications Billing And Revenue ManagementCommunications Eagle Ftp Table Base Retrieval+43 moreJun 17, 2026 Apr 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through tha...Show more |
2Apache Oracle5Communications Messaging Server Flexcube Private BankingPrimavera Unifier+2 moreJun 17, 2026 Apr 27, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS...Show more |
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod...Show more |
8Apache BroadcomCanonical+5 more14Brocade Fabric Operating System Communications Element ManagerCommunications Session Report Manager+11 moreJun 17, 2026 Apr 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more |
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is...Show more |