Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging. |
2Apache Oracle37Agile Engineering Data Management Agile Product Lifecycle ManagementApplication Testing Suite+34 moreJun 17, 2026 May 1, 2019 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legac...Show more |
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inp...Show more |
In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropria...Show more |
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can chang...Show more |
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected. |
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of t...Show more |
7Apache CanonicalDebian+4 more17Cassandra Debian LinuxEnterprise Linux+14 moreJun 17, 2026 Apr 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit...Show more |
2Apache Redhat10Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+7 moreJun 17, 2026 Apr 23, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when conf...Show more |
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph". |
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication. |
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "stone lone". |
A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface. |
4Apache DebianEclipse+1 more7Activemq Debian LinuxDrill+4 moreJun 17, 2026 Apr 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandle...Show more |
3Apache FedoraprojectOracle14Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+11 moreJun 17, 2026 Apr 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. |
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE...Show more |
A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site request forgery attacks. |
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. |
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request...Show more |
8Apache CanonicalDebian+5 more27Communications Session Report Manager Communications Session Route ManagerDebian Linux+24 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) cou...Show more |