Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "...Show more |
2Apache Oracle13Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Liquidity Management+10 moreJun 17, 2026 Jan 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized...Show more |
2Apache Oracle3Cordova Inappbrowser Instantis EnterprisetrackRetail Xstore Point Of ServiceJun 17, 2026 Jan 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. |
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If...Show more |
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same. |
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. |
2Apache Oracle2Primavera Unifier SolrJun 17, 2026 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 4.6 MEDIUM· v2 Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or...Show more |
5Apache NetappOracle+2 more5Bookkeeper Cloud BackupMysql Workbench+2 moreJun 17, 2026 Dec 24, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling. |
6Apache CanonicalDebian+3 more6Debian Linux LeapOncommand System Manager+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manip...Show more |
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |
6Apache CanonicalDebian+3 more17Application Testing Suite BookkeeperCommunications Network Integrity+14 moreJun 17, 2026 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t...Show more |
3Apache DebianLibreoffice3Debian Linux LibreofficeOpenofficeNov 21, 2024 Dec 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 LibreOffice and OpenOffice automatically open embedded content |
7Apache AppleCanonical+4 more19Bookkeeper Cyrus SaslDebian Linux+16 moreJun 17, 2026 Dec 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in...Show more |
5Apache DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreNov 4, 2025 Dec 18, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current m...Show more |
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab |
In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query. |
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors |
2Apache Debian2Debian Linux SpamassassinJun 17, 2026 Dec 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. |
2Apache Debian2Debian Linux SpamassassinNov 21, 2024 Dec 12, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA...Show more |
5Apache NetappOracle+2 more6Cloud Backup GuacamoleMysql Workbench+3 moreJun 17, 2026 Dec 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. |