İçeriğe atla
Noroxi

apache kayıtları

apache üreticisine ait 3.437 yayımlanmış kayıt.

Tüm kayıtlar

3.437 kayıt
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    apache · log4j10 Ara 2021

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · struts10 Mar 2017

  • Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · archiva19 Tem 2013

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server5 Eki 2021

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server7 Eki 2021

  • Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · tomcat10 Mar 2025

  • Apache OFBiz: Path traversal leading to RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · ofbiz8 May 2024

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · activemq27 Eki 2023

  • The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · airflow10 Kas 2020

  • Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · ofbiz5 Ağu 2024

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · geode24 Şub 2020

  • Apache HugeGraph-Server: Command execution in gremlin

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · hugegraph22 Nis 2024

  • The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · struts10 Tem 2017

  • The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · activemq1 Haz 2016

  • Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    apache · superset24 Nis 2023

  • Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    broadcom · spring data commons11 Nis 2018

  • Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    apache · rocketmq24 May 2023

  • apisix/batch-requests plugin allows overwriting the X-REAL-IP header

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96

    apache · apisix11 Şub 2022

  • Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96

    apache · struts10 Ara 2020

  • Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93

    apache · aurora7 Haz 2016

  • Remote Code Execution Vulnerability in Packaging

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93

    apache · couchdb26 Nis 2022

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    oracle · jdk21 Nis 2016

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    resf · rocky linux16 Eyl 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    apache · log4j14 Ara 2021

  • Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100

    apache · http server1 Tem 2024