Перейти к содержимому
Noroxi

Записи apache

3 437 опубликованных записей вендора apache.

Профиль для исследователя

Попали в KEV
45 · 1,3 %
С эксплойтом
107 · 3,1 %
Pre-auth RCE
333
С записью об исправлении
87,2 %
Медиана: публикация → KEV
503 дн.

Все записи

3 437 записей
  • CVE-2021-44228
    100Срочно

    Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j10 дек. 2021 г.

  • CVE-2017-5638
    99Срочно

    The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · struts10 мар. 2017 г.

  • CVE-2013-2251
    99Срочно

    Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · archiva19 июл. 2013 г.

  • CVE-2021-41773
    99Срочно

    Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · http server5 окт. 2021 г.

  • CVE-2021-42013
    99Срочно

    Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · http server7 окт. 2021 г.

  • CVE-2025-24813
    99Срочно

    Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · tomcat10 мар. 2025 г.

  • CVE-2024-32113
    99Срочно

    Apache OFBiz: Path traversal leading to RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · ofbiz8 мая 2024 г.

  • CVE-2023-46604
    99Срочно

    Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · activemq27 окт. 2023 г.

  • CVE-2020-13927
    99Срочно

    The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · airflow10 нояб. 2020 г.

  • CVE-2024-38856
    99Срочно

    Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · ofbiz5 авг. 2024 г.

  • CVE-2020-1938
    99Срочно

    When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · geode24 февр. 2020 г.

  • CVE-2024-27348
    99Срочно

    Apache HugeGraph-Server: Command execution in gremlin

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · hugegraph22 апр. 2024 г.

  • CVE-2017-9791
    99Срочно

    The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · struts10 июл. 2017 г.

  • CVE-2016-3088
    99Срочно

    The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · activemq1 июн. 2016 г.

  • CVE-2023-27524
    98Срочно

    Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    apache · superset24 апр. 2023 г.

  • CVE-2018-1273
    98Срочно

    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    broadcom · spring data commons11 апр. 2018 г.

  • CVE-2023-33246
    98Срочно

    Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    apache · rocketmq24 мая 2023 г.

  • CVE-2022-24112
    98Срочно

    apisix/batch-requests plugin allows overwriting the X-REAL-IP header

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %

    apache · apisix11 февр. 2022 г.

  • CVE-2020-17530
    98Срочно

    Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %

    apache · struts10 дек. 2020 г.

  • CVE-2016-4437
    97Срочно

    Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %

    apache · aurora7 июн. 2016 г.

  • CVE-2022-24706
    97Срочно

    Remote Code Execution Vulnerability in Packaging

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %

    apache · couchdb26 апр. 2022 г.

  • CVE-2016-3427
    97Срочно

    Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %

    oracle · jdk21 апр. 2016 г.

  • CVE-2021-40438
    96Срочно

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    resf · rocky linux16 сент. 2021 г.

  • CVE-2021-45046
    96Срочно

    Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j14 дек. 2021 г.

  • CVE-2024-38475
    96Срочно

    Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %

    apache · http server1 июл. 2024 г.