Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-03 CVE-2022-45143 Unspecified vulnerability in Apache Tomcat
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values.
network
low complexity
apache
7.5
2022-12-30 CVE-2022-43396 Unspecified vulnerability in Apache Kylin
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands.
network
low complexity
apache
8.8
2022-12-19 CVE-2022-32749 Unspecified vulnerability in Apache Traffic Server
Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.
network
low complexity
apache
7.5
2022-12-14 CVE-2022-34271 Unspecified vulnerability in Apache Atlas
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem.
network
low complexity
apache
8.8
2022-12-13 CVE-2022-46363 Unspecified vulnerability in Apache CXF
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration.
network
low complexity
apache
7.5
2022-11-29 CVE-2022-44635 Unspecified vulnerability in Apache Fineract
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code.
network
low complexity
apache
8.8
2022-11-24 CVE-2022-26885 Unspecified vulnerability in Apache Dolphinscheduler
When using tasks to read config files, there is a risk of database password disclosure.
network
low complexity
apache
7.5
2022-11-22 CVE-2022-41131 Unspecified vulnerability in Apache Airflow
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files.
local
low complexity
apache
7.8
2022-11-21 CVE-2022-45470 Unspecified vulnerability in Apache Hama
missing input validation in Apache Hama may cause information disclosure through path traversal and XSS.
network
low complexity
apache
7.5
2022-11-15 CVE-2022-40308 Unspecified vulnerability in Apache Archiva
If anonymous read enabled, it's possible to read the database file directly without logging in.
network
low complexity
apache
7.5