58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Apache vulnerabilities
3483 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-20243 | HIGH 7.5 | apache fineract The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629. | 2.7% | — |
| CVE-2020-9482 | MED 6.5 | apache nifi_registry If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be use | 2.7% | — |
| CVE-2022-40664 | CRIT 9.8 | apache shiro Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. | 2.7% | — |
| CVE-2012-2945 | HIGH 7.5 | apache hadoop Hadoop 1.0.3 contains a symlink vulnerability. | 2.7% | — |
| CVE-2022-28890 | CRIT 9.8 | apache jena A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities. | 2.7% | — |
| CVE-2017-7663 | MED 6.1 | apache openmeetings Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. | 2.7% | — |
| CVE-2022-26650 | HIGH 7.5 | apache shenyu In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions | 2.7% | — |
| CVE-2026-34355 | HIGH 7.5 | apache http_server A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue. | 2.7% | — |
| CVE-2019-0216 | MED 4.8 | apache airflow A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. | 2.7% | — |
| CVE-2023-46589 | HIGH 7.5 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that ex | 2.7% | — |
| CVE-2020-13953 | MED 5.3 | apache tapestry In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run. | 2.7% | — |
| CVE-2021-25958 | MED 6.5 | apache ofbiz In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he | 2.6% | — |
| CVE-2012-3376 | HIGH 7.5 | apache hadoop DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to w | 2.6% | — |
| CVE-2026-28672 | CRIT 9.8 | apache ranger Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. | 2.6% | — |
| CVE-2022-25370 | MED 5.4 | apache ofbiz Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id= | 2.6% | — |
| CVE-2023-39508 | HIGH 8.8 | apache airflow Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It | 2.6% | — |
| CVE-2021-36374 | MED 5.5 | apache ant When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly u | 2.6% | — |
| CVE-2022-39198 | CRIT 9.8 | apache dubbo A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior ve | 2.6% | — |
| CVE-2016-6811 | HIGH 8.8 | apache hadoop In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user. | 2.6% | — |
| CVE-2020-17511 | MED 6.5 | apache airflow In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field. | 2.6% | — |
| CVE-2017-7677 | MED 5.9 | apache ranger In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table. | 2.6% | — |
| CVE-2010-2952 | MED 4.3 | apache traffic_server Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poiso | 2.6% | — |
| CVE-2022-30126 | MED 5.5 | apache tika In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtracting | 2.6% | — |
| CVE-2017-15695 | HIGH 8.8 | apache geode When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be restrict | 2.6% | — |
| CVE-2016-5394 | MED 6.1 | apache sling In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to pass through unencoded, leading to potential XSS vulnerabilit | 2.6% | — |