VYPR

Vendor CVEs

Apache

All CVEs

3,418 total · sorted by risk
  • CVE-2019-12407MedSep 23, 2019
    risk 0.40cvss 6.1epss 0.03

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the victim's browser and…

  • CVE-2019-10090MedSep 23, 2019
    risk 0.40cvss 6.1epss 0.03

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…

  • CVE-2019-12404MedSep 23, 2019
    risk 0.40cvss 6.1epss 0.03

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…

  • CVE-2019-10089MedSep 23, 2019
    risk 0.40cvss 6.1epss 0.03

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…

  • CVE-2019-10087MedSep 23, 2019
    risk 0.40cvss 6.1epss 0.03

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive…

  • CVE-2019-10073MedSep 11, 2019
    risk 0.40cvss 6.1epss 0.05

    The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595 and 1860616

  • CVE-2019-12397MedAug 8, 2019
    risk 0.40cvss 6.1epss 0.03

    Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apache Ranger with the fix.

  • CVE-2019-0234MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.03

    A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to…

  • CVE-2019-10078MedMay 20, 2019
    risk 0.40cvss 6.1epss 0.05

    A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

  • CVE-2019-10077MedMay 20, 2019
    risk 0.40cvss 6.1epss 0.05

    A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

  • CVE-2019-10076MedMay 20, 2019
    risk 0.40cvss 6.1epss 0.05

    A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

  • CVE-2018-8035MedMay 1, 2019
    risk 0.40cvss 6.1epss 0.05

    This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user…

  • CVE-2018-1328MedApr 23, 2019
    risk 0.40cvss 6.1epss 0.06

    Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".

  • CVE-2019-0218MedApr 22, 2019
    risk 0.40cvss 6.1epss 0.05

    A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

  • CVE-2019-10241MedApr 22, 2019
    risk 0.40cvss 6.1epss 0.10

    In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory…

  • CVE-2019-0224MedMar 28, 2019
    risk 0.40cvss 6.1epss 0.05

    In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.

  • CVE-2018-20242MedFeb 11, 2019
    risk 0.40cvss 6.1epss 0.05

    A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.

  • CVE-2018-17186HigNov 6, 2018
    risk 0.40cvss 7.2epss 0.02

    An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.

  • CVE-2018-8032MedAug 2, 2018
    risk 0.40cvss 6.1epss 0.11

    Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

  • CVE-2018-1325MedApr 18, 2018
    risk 0.40cvss 6.1epss 0.01

    In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.

  • CVE-2018-1301MedMar 26, 2018
    risk 0.40cvss 5.9epss 0.15

    A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both…

  • CVE-2018-1319MedMar 15, 2018
    risk 0.40cvss 6.1epss 0.02

    In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.

  • CVE-2017-15719MedMar 12, 2018
    risk 0.40cvss 6.1epss 0.01

    In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.

  • CVE-2017-15717MedJan 10, 2018
    risk 0.40cvss 6.1epss 0.03

    A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling…

  • CVE-2017-11296MedDec 9, 2017
    risk 0.40cvss 6.1epss 0.03

    An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager.

  • CVE-2012-5636MedOct 30, 2017
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to tags in a rendered response.

  • CVE-2009-1198MedOct 30, 2017
    risk 0.40cvss 6.1epss 0.04

    Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname parameter to happyjuddi.jsp.

  • CVE-2015-5169MedSep 25, 2017
    risk 0.40cvss 6.1epss 0.07

    Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.

  • CVE-2016-6800MedAug 30, 2017
    risk 0.40cvss 6.1epss 0.04

    The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the…

  • CVE-2017-3155MedAug 29, 2017
    risk 0.40cvss 6.1epss 0.02

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.

  • CVE-2017-3153MedAug 29, 2017
    risk 0.40cvss 6.1epss 0.02

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.

  • CVE-2017-3152MedAug 29, 2017
    risk 0.40cvss 6.1epss 0.02

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.

  • CVE-2017-3151MedAug 29, 2017
    risk 0.40cvss 6.1epss 0.02

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.

  • CVE-2017-3150MedAug 29, 2017
    risk 0.40cvss 6.1epss 0.02

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

  • CVE-2017-9802MedAug 14, 2017
    risk 0.40cvss 6.1epss 0.04

    The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings.

  • CVE-2017-7663MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.03

    Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.

  • CVE-2017-7678MedJul 12, 2017
    risk 0.40cvss 6.1epss 0.03

    In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to the Spark master, or history server. This data, which could…

  • CVE-2017-7665MedJun 12, 2017
    risk 0.40cvss 6.1epss 0.04

    In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.

  • CVE-2015-5241MedMay 19, 2017
    risk 0.40cvss 6.1epss 0.02

    After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when utilizing the portlets based user…

  • CVE-2017-3161MedApr 26, 2017
    risk 0.40cvss 6.1epss 0.04

    The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.

  • CVE-2016-1546MedJul 6, 2016
    risk 0.40cvss 5.9epss 0.15

    The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

  • CVE-2015-1776MedApr 19, 2016
    risk 0.40cvss 6.2epss 0.00

    Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the…

  • CVE-2015-7520MedApr 12, 2016
    risk 0.40cvss 6.1epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value"…

  • CVE-2015-5347MedApr 12, 2016
    risk 0.40cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web…

  • CVE-2015-3268MedApr 12, 2016
    risk 0.40cvss 6.1epss 0.09

    Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a…

  • CVE-2015-0265MedApr 11, 2016
    risk 0.40cvss 6.1epss 0.05

    Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header.

  • CVE-2016-2163MedApr 11, 2016
    risk 0.40cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.

  • CVE-2016-0712MedApr 11, 2016
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.

  • CVE-2016-0711MedApr 11, 2016
    risk 0.40cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.

  • CVE-2015-8797MedFeb 15, 2016
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.

Page 38 of 69