Vulnerabilities > Apache > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-06-13 CVE-2021-37404 Out-of-bounds Write vulnerability in Apache Hadoop
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code.
network
low complexity
apache CWE-787
critical
9.8
2022-06-09 CVE-2022-28615 Integer Overflow or Wraparound vulnerability in multiple products
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer.
network
low complexity
apache fedoraproject netapp CWE-190
critical
9.1
2022-06-09 CVE-2022-31813 Insufficient Verification of Data Authenticity vulnerability in multiple products
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism.
network
low complexity
apache netapp fedoraproject CWE-345
critical
9.8
2022-05-23 CVE-2022-29599 Improper Encoding or Escaping of Output vulnerability in multiple products
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
network
low complexity
apache debian CWE-116
critical
9.8
2022-05-05 CVE-2022-28890 XXE vulnerability in Apache Jena 4.4.0
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved.
network
low complexity
apache CWE-611
critical
9.8
2022-04-26 CVE-2022-24706 Insecure Default Initialization of Resource vulnerability in Apache Couchdb
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.
network
low complexity
apache CWE-1188
critical
9.8
2022-04-13 CVE-2022-27479 SQL Injection vulnerability in Apache Superset
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests.
network
low complexity
apache CWE-89
critical
9.8
2022-04-12 CVE-2021-31805 Expression Language Injection vulnerability in Apache Struts
The fix issued for CVE-2020-17530 was incomplete.
network
low complexity
apache CWE-917
critical
9.8
2022-04-07 CVE-2022-26612 Link Following vulnerability in Apache Hadoop
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes.
network
low complexity
apache CWE-59
critical
9.8
2022-03-28 CVE-2022-25757 Improper Input Validation vulnerability in Apache Apisix
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result.
network
low complexity
apache CWE-20
critical
9.8