VYPR

Vendor CVEs

Apache

All CVEs

3,418 total · sorted by risk
  • CVE-2002-0935Oct 4, 2002
    risk 0.01cvss epss 0.08

    Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.

  • CVE-2002-1593Sep 25, 2002
    risk 0.01cvss epss 0.07

    mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

  • CVE-2002-0240May 29, 2002
    risk 0.01cvss epss 0.08

    PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.

  • CVE-2002-0249May 29, 2002
    risk 0.01cvss epss 0.08

    PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.

  • CVE-2002-1592May 6, 2002
    risk 0.01cvss epss 0.12

    The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.

  • CVE-2002-0061Mar 21, 2002
    risk 0.01cvss epss 0.50

    Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically…

  • CVE-2001-0829Dec 6, 2001
    risk 0.01cvss epss 0.12

    A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

  • CVE-2001-1449Nov 28, 2001
    risk 0.01cvss epss 0.08

    The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

  • CVE-2001-0917Nov 22, 2001
    risk 0.01cvss epss 0.08

    Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.

  • CVE-2001-0729Oct 30, 2001
    risk 0.01cvss epss 0.07

    Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.

  • CVE-2001-0730Oct 30, 2001
    risk 0.01cvss epss 0.12

    split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.

  • CVE-2001-1342May 12, 2001
    risk 0.01cvss epss 0.12

    Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.

  • CVE-2000-1204Oct 13, 2000
    risk 0.01cvss epss 0.11

    Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

  • CVE-2000-0672Jul 20, 2000
    risk 0.01cvss epss 0.10

    The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.

  • CVE-1999-1237Jun 6, 1999
    risk 0.01cvss epss 0.08

    Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.

  • CVE-2026-34884Aug 18, 2026
    risk 0.00cvss epss

    SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

  • CVE-2026-66144HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by…

  • CVE-2026-66143HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.01

    It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3,…

  • CVE-2026-66142HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version…

  • CVE-2026-46452MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.01

    Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to…

  • CVE-2026-45816HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.01

    NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE:…

  • CVE-2026-45815HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.01

    Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue…

  • CVE-2026-45813HigJul 24, 2026
    risk 0.00cvss 8.8epss 0.00

    Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This…

  • CVE-2026-45812MedJul 24, 2026
    risk 0.00cvss 6.5epss 0.00

    Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause the host to read…

  • CVE-2026-45811HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low:…

  • CVE-2026-60080HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.00

    Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to…

  • CVE-2026-64606CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version…

  • CVE-2026-64609CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are…

  • CVE-2026-63071CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope:…

  • CVE-2026-62418HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are…

  • CVE-2026-62183CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update…

  • CVE-2026-57308CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue…

  • CVE-2026-53421CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This…

  • CVE-2026-53405CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported…

  • CVE-2026-26032MedJul 15, 2026
    risk 0.00cvss 5.4epss 0.01

    The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. This subdirectory is…

  • CVE-2026-57821HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.01

    A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission…

  • CVE-2026-56287HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.00

    A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an…

  • CVE-2026-35152HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.02

    A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with…

  • CVE-2026-62393MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. …

  • CVE-2026-62392CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade…

  • CVE-2026-62390CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended…

  • CVE-2026-49488MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS…

  • CVE-2026-58319CriJul 14, 2026
    risk 0.00cvss 9.1epss 0.01

    Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and…

  • CVE-2026-59084CriJul 14, 2026
    risk 0.00cvss 9.1epss 0.01

    Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13…

  • CVE-2026-59083CriJul 14, 2026
    risk 0.00cvss 9.1epss 0.00

    Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through…

  • CVE-2026-59245HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission…

  • CVE-2026-58065HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server…

  • CVE-2026-49876MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 through 1.2.1. Users are…

  • CVE-2026-41041CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.00

    URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.

  • CVE-2026-40454HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server data. This issue affects Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5…

Page 60 of 69