Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2022-12-16 CVE-2022-46870 Unspecified vulnerability in Apache Zeppelin
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2.
network
low complexity
apache
5.4
2022-12-15 CVE-2022-32531 Unspecified vulnerability in Apache Bookkeeper
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails.
network
high complexity
apache
5.9
2022-12-14 CVE-2022-34271 Unspecified vulnerability in Apache Atlas
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem.
network
low complexity
apache
8.8
2022-12-13 CVE-2022-46364 Unspecified vulnerability in Apache CXF
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 
network
low complexity
apache
critical
9.8
2022-12-13 CVE-2022-46363 Unspecified vulnerability in Apache CXF
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration.
network
low complexity
apache
7.5
2022-12-07 CVE-2022-45910 Injection vulnerability in Apache Manifoldcf
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions.
network
low complexity
apache CWE-74
5.3
2022-12-03 CVE-2021-37533 Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default.
network
low complexity
apache debian
6.5
2022-12-02 CVE-2022-46366 Unspecified vulnerability in Apache Tapestry
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution.
network
low complexity
apache
critical
9.8
2022-11-29 CVE-2022-44635 Unspecified vulnerability in Apache Fineract
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code.
network
low complexity
apache
8.8
2022-11-24 CVE-2022-26885 Unspecified vulnerability in Apache Dolphinscheduler
When using tasks to read config files, there is a risk of database password disclosure.
network
low complexity
apache
7.5