Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2020-05-12 CVE-2020-1939 NULL Pointer Dereference vulnerability in Apache Nuttx
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs.
network
high complexity
apache CWE-476
5.1
2020-05-11 CVE-2018-1285 XXE vulnerability in multiple products
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files.
network
low complexity
apache fedoraproject oracle netapp CWE-611
critical
9.8
2020-05-04 CVE-2020-1961 Injection vulnerability in Apache Syncope
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.
network
low complexity
apache CWE-74
7.5
2020-05-04 CVE-2020-1959 Code Injection vulnerability in Apache Syncope
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability.
network
low complexity
apache CWE-94
7.5
2020-05-04 CVE-2019-17557 Cross-site Scripting vulnerability in Apache Syncope
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters.
network
apache CWE-79
3.5
2020-04-30 CVE-2019-12425 Injection vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
network
low complexity
apache CWE-74
7.5
2020-04-30 CVE-2019-0235 Cross-Site Request Forgery (CSRF) vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
network
low complexity
apache CWE-352
8.8
2020-04-28 CVE-2020-9482 Insufficient Session Expiration vulnerability in Apache Nifi Registry 0.1.0/0.5.0
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side.
network
low complexity
apache CWE-613
6.4
2020-04-27 CVE-2020-9481 Resource Exhaustion vulnerability in multiple products
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
network
low complexity
apache debian CWE-400
5.0
2020-04-27 CVE-2020-1952 Improper Certificate Validation vulnerability in Apache Iotdb
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.
network
low complexity
apache CWE-295
7.5