imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2014-3579
Critica 9.8

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

apache activemq_apollo
0.05EPSS
CVE-2020-9493
Critica 9.8

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

apache chainsaw · apache log4j · qos reload4j
0.05EPSS
CVE-2015-0249
Alta 7.2

The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).

apache roller
0.05EPSS
CVE-2025-53020
Alta 7.5

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

apache http_server
0.05EPSS
CVE-2020-1958
Media 6.5

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid. The…

apache druid
0.05EPSS
CVE-2020-13920
Media 5.9

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If a…

apache activemq · debian debian_linux · oracle communications_diameter_signaling_router · oracle flexcube_private_banking
0.05EPSS
CVE-2019-10079
Alta 7.5

Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4,…

apache traffic_server
0.05EPSS
CVE-2021-26697
Media 5.3

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to…

apache airflow
0.05EPSS
CVE-2014-3525
Alta 10.0

Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

apache traffic_server
0.05EPSS
CVE-2016-8612
Media 4.3

Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.

apache http_server · netapp storage_automation_store · redhat enterprise_linux
0.05EPSS
CVE-2018-1309
Critica 9.8

Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi …

apache nifi
0.05EPSS
CVE-2003-0043
Media 5.0

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

apache tomcat
0.05EPSS
CVE-2020-1940
Alta 7.5

The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute…

apache jackrabbit_oak
0.05EPSS
CVE-2018-1313
Media 5.3

In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Securi…

apache derby · oracle weblogic_server
0.05EPSS
CVE-2020-11994
Alta 7.5

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

apache camel · oracle communications_diameter_signaling_router · oracle enterprise_manager_base_platform · oracle enterprise_repository
0.04EPSS
CVE-2016-1513
Alta 7.8

The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file.

apache openoffice
0.04EPSS
CVE-2018-1331
Alta 8.8

In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.

apache storm
0.04EPSS
CVE-2017-17837
Media 6.1

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1…

apache deltaspike
0.04EPSS
CVE-2010-4644
Bassa 3.5

Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

apache subversion
0.04EPSS
CVE-2021-21501
Alta 7.5

Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0.

apache servicecomb
0.04EPSS
CVE-2022-23437
Media 6.5

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged durati…

apache xerces-j · netapp active_iq_unified_manager · oracle agile_engineering_data_management · oracle agile_plm · e altri 25
0.04EPSS
CVE-2015-8320
Media 5.0

Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.

apache cordova
0.04EPSS
CVE-2024-39887
Media 4.3

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorizat…

apache superset
0.04EPSS
CVE-2021-43350
Critica 9.8

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.

apache traffic_control
0.04EPSS
CVE-2022-29599
Critica 9.8

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

apache maven_shared_utils · debian debian_linux
0.04EPSS