58.306 CVE seguite
790 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.306 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2020-1957 | CRIT 9.8 | apache shiro Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | 23,3% | — |
| CVE-2020-1955 | CRIT 9.8 | apache couchdb CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the long standing setting `require_valid_user`, which in turn re | 1,8% | — |
| CVE-2020-1954 | MED 5.3 | apache cxf Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in- | 6,1% | — |
| CVE-2020-1953 | CRIT 10.0 | apache commons_configuration Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default s | 6,8% | — |
| CVE-2020-1952 | CRIT 9.8 | apache iotdb An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely. | 2,7% | — |
| CVE-2020-19510 | CRIT 9.8 | textpattern textpattern Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. | 1,5% | — |
| CVE-2020-1951 | MED 5.5 | apache tika A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. | 2,9% | — |
| CVE-2020-1950 | MED 5.5 | apache tika A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. | 3,0% | — |
| CVE-2020-1949 | MED 6.1 | apache sling_cms Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks. | 2,0% | — |
| CVE-2020-1948 | CRIT 9.8 | apache dubbo This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will ex | 16,4% | — |
| CVE-2020-1947 | CRIT 9.8 | apache shardingsphere In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshallin | 33,9% | — |
| CVE-2020-1946 | CRIT 9.8 | apache spamassassin In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, use | 6,1% | — |
| CVE-2020-1945 | MED 6.3 | apache ant Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the tem | 1,8% | — |
| CVE-2020-1944 | CRIT 9.8 | apache traffic_server There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions. | 2,7% | — |
| CVE-2020-1943 | MED 6.1 | apache ofbiz Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. | 97,3% | — |
| CVE-2020-1942 | HIGH 7.5 | apache nifi In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both | 3,1% | — |
| CVE-2020-1941 | MED 6.1 | apache activemq In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. | 6,2% | — |
| CVE-2020-1940 | HIGH 7.5 | apache jackrabbit_oak The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute | 4,5% | — |
| CVE-2020-1939 | CRIT 9.8 | apache nuttx The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the o | 2,5% | — |
| CVE-2020-1937 | HIGH 8.8 | apache kylin Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries. | 2,7% | — |
| CVE-2020-1936 | MED 6.1 | apache ambari A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4. | 2,9% | — |
| CVE-2020-1935 | MED 4.8 | apache tomcat In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if T | 9,4% | — |
| CVE-2020-1934 | MED 5.3 | apache http_server In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. | 52,0% | — |
| CVE-2020-1933 | MED 6.1 | apache nifi A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers. | 2,8% | — |
| CVE-2020-1932 | MED 6.5 | apache superset An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint | 1,4% | — |