Skip to content
Noroxi

apache records

3,437 published records for vendor apache.

All records

3,437 records
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · strutsMar 10, 2017

  • Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · archivaJul 19, 2013

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 5, 2021

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 7, 2021

  • Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · tomcatMar 10, 2025

  • Apache OFBiz: Path traversal leading to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · ofbizMay 8, 2024

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · activemqOct 27, 2023

  • The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · airflowNov 10, 2020

  • Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · ofbizAug 5, 2024

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · geodeFeb 24, 2020

  • Apache HugeGraph-Server: Command execution in gremlin

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · hugegraphApr 22, 2024

  • The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · strutsJul 10, 2017

  • The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · activemqJun 1, 2016

  • Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    apache · supersetApr 24, 2023

  • Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    broadcom · spring data commonsApr 11, 2018

  • Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    apache · rocketmqMay 24, 2023

  • apisix/batch-requests plugin allows overwriting the X-REAL-IP header

    CriticalCVSS 9.8KEVWeaponizedEPSS 96%

    apache · apisixFeb 11, 2022

  • Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 96%

    apache · strutsDec 10, 2020

  • Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    apache · auroraJun 7, 2016

  • Remote Code Execution Vulnerability in Packaging

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    apache · couchdbApr 26, 2022

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    oracle · jdkApr 21, 2016

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    apache · log4jDec 14, 2021

  • Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    CriticalCVSS 9.1KEVWeaponizedEPSS 100%

    apache · http serverJul 1, 2024