VYPR

Vendor CVEs

Apache

All CVEs

3,418 total · sorted by risk
  • CVE-2022-34870MedOct 25, 2022
    risk 0.35cvss 5.4epss 0.01

    Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.

  • CVE-2022-38398MedSep 22, 2022
    risk 0.35cvss 5.3epss 0.02

    Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.

  • CVE-2022-25370MedSep 2, 2022
    risk 0.35cvss 5.4epss 0.02

    Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an…

  • CVE-2021-4040MedAug 24, 2022
    risk 0.35cvss 5.3epss 0.03

    A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted…

  • CVE-2022-32549MedJun 22, 2022
    risk 0.35cvss 5.3epss 0.02

    Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

  • CVE-2022-28614MedJun 9, 2022
    risk 0.35cvss 5.3epss 0.05

    The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from…

  • CVE-2022-28330MedJun 9, 2022
    risk 0.35cvss 5.3epss 0.04

    Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

  • CVE-2022-29405MedMay 25, 2022
    risk 0.35cvss 6.5epss 0.02

    In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8

  • CVE-2021-43410MedDec 9, 2021
    risk 0.35cvss 5.3epss 0.02

    Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1]…

  • CVE-2021-41532MedNov 19, 2021
    risk 0.35cvss 5.3epss 0.02

    In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.

  • CVE-2021-32609MedOct 18, 2021
    risk 0.35cvss 5.4epss 0.02

    Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.

  • CVE-2021-41831MedOct 11, 2021
    risk 0.35cvss 5.3epss 0.01

    It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.

  • CVE-2021-33190MedJun 8, 2021
    risk 0.35cvss 5.3epss 0.03

    In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to…

  • CVE-2021-26559MedFeb 17, 2021
    risk 0.35cvss 6.5epss 0.03

    Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a…

  • CVE-2020-13922MedJan 11, 2021
    risk 0.35cvss 6.5epss 0.02

    Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

  • CVE-2020-17511MedDec 14, 2020
    risk 0.35cvss 6.5epss 0.03

    In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.

  • CVE-2020-13953MedSep 30, 2020
    risk 0.35cvss 5.3epss 0.03

    In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.

  • CVE-2020-13944MedSep 17, 2020
    risk 0.35cvss 6.1epss 0.25

    In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.

  • CVE-2020-25073MedSep 2, 2020
    risk 0.35cvss 5.3epss 0.02

    FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a local connection. This affects both the freedombox and…

  • CVE-2020-11985MedAug 7, 2020
    risk 0.35cvss 5.3epss 0.07

    IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24…

  • CVE-2020-11983MedJul 17, 2020
    risk 0.35cvss 5.4epss 0.02

    An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handled escaping incorrectly, allowing authenticated users with appropriate permissions to create stored XSS attacks.

  • CVE-2020-13923MedJul 15, 2020
    risk 0.35cvss 5.3epss 0.05

    IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

  • CVE-2020-9482MedApr 28, 2020
    risk 0.35cvss 6.5epss 0.03

    If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12…

  • CVE-2019-12426MedFeb 6, 2020
    risk 0.35cvss 5.3epss 0.05

    an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06

  • CVE-2019-12414MedDec 16, 2019
    risk 0.35cvss 5.3epss 0.03

    In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

  • CVE-2019-12413MedDec 16, 2019
    risk 0.35cvss 5.3epss 0.03

    In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

  • CVE-2019-10083MedNov 19, 2019
    risk 0.35cvss 5.3epss 0.03

    When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had…

  • CVE-2018-17192MedDec 19, 2018
    risk 0.35cvss 6.5epss 0.03

    The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security…

  • CVE-2018-17184MedNov 6, 2018
    risk 0.35cvss 5.4epss 0.01

    A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the…

  • CVE-2017-5658MedOct 4, 2018
    risk 0.35cvss 5.3epss 0.02

    The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, though without…

  • CVE-2017-15705MedSep 17, 2018
    risk 0.35cvss 5.3epss 0.08

    A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we…

  • CVE-2018-1288MedJul 26, 2018
    risk 0.35cvss 5.4epss 0.05

    In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

  • CVE-2018-1313MedMay 7, 2018
    risk 0.35cvss 5.3epss 0.04

    In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy…

  • CVE-2018-8003MedMay 3, 2018
    risk 0.35cvss 5.3epss 0.04

    Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host the Ambari Server runs on that is accessible by the user the…

  • CVE-2018-1283MedMar 26, 2018
    risk 0.35cvss 5.3epss 0.10

    In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by…

  • CVE-2017-15706MedJan 31, 2018
    risk 0.35cvss 5.3epss 0.06

    As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was…

  • CVE-2017-9796MedJan 10, 2018
    risk 0.35cvss 5.3epss 0.01

    When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.

  • CVE-2017-12630MedDec 18, 2017
    risk 0.35cvss 5.4epss 0.01

    In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may…

  • CVE-2009-1197MedOct 30, 2017
    risk 0.35cvss 5.3epss 0.04

    Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.

  • CVE-2015-1835MedOct 27, 2017
    risk 0.35cvss 5.3epss 0.06

    Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.

  • CVE-2016-8748MedOct 19, 2017
    risk 0.35cvss 5.4epss 0.02

    In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.

  • CVE-2014-0043MedOct 3, 2017
    risk 0.35cvss 5.3epss 0.03

    In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.

  • CVE-2017-3165MedSep 13, 2017
    risk 0.35cvss 5.4epss 0.02

    In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources. This is due to improper escaping of server-side content.…

  • CVE-2017-7685MedJul 17, 2017
    risk 0.35cvss 5.3epss 0.03

    Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.

  • CVE-2016-1566MedFeb 2, 2017
    risk 0.35cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. NOTE: this…

  • CVE-2015-3271MedDec 15, 2016
    risk 0.35cvss 5.3epss 0.07

    Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

  • CVE-2016-3093MedJun 7, 2016
    risk 0.35cvss 5.3epss 0.08

    Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

  • CVE-2015-5207MedMay 9, 2016
    risk 0.35cvss 5.3epss 0.03

    Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.

  • CVE-2016-0763MedFeb 25, 2016
    risk 0.35cvss 6.3epss 0.11

    The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote…

  • CVE-2026-54665MedJun 22, 2026
    risk 0.34cvss 5.3epss 0.00

    Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict…

Page 44 of 69