Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache solr vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2016-5663
Multiple cross-site scripting (XSS) vulnerabilities in oauth_callback.php on Accellion Kiteworks appliances before kw2016.03.00 allow remote malicious users to inject arbitrary web script or HTML via the (1) code, (2) error, or (3) error_description parameter.
Accellion Kiteworks Appliance
383
VMScore
CVE-2015-8796
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr prior to 5.3 allows remote malicious users to inject arbitrary web script or HTML via a crafted schema-browse URL.
Apache Solr
383
VMScore
CVE-2015-8795
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr prior to 5.1 allow remote malicious users to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scrip...
Apache Solr
383
VMScore
CVE-2015-8797
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr prior to 5.3.1 allows remote malicious users to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
Apache Solr
383
VMScore
CVE-2014-3628
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x prior to 4.10.3 allows remote malicious users to inject arbitrary web script or HTML via the fieldvaluecache object.
Apache Solr 4.5.0
Apache Solr 4.7.1
Apache Solr 4.10.2
Apache Solr 4.0.0
Apache Solr 4.6.1
Apache Solr 4.2.1
Apache Solr 4.10.1
Apache Solr 4.3.0
Apache Solr 4.8.0
Apache Solr 4.9.1
Apache Solr 4.7.2
Apache Solr 4.4.0
Apache Solr 4.2.0
Apache Solr 4.6.0
Apache Solr 4.5.1
Apache Solr 4.3.1
Apache Solr 4.7.0
Apache Solr 4.10.0
Apache Solr 4.8.1
Apache Solr 4.1.0
Apache Solr 4.9.0
383
VMScore
CVE-2013-6397
Directory traversal vulnerability in SolrResourceLoader in Apache Solr prior to 4.6 allows remote malicious users to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this ca...
Apache Solr 4.5.0
Apache Solr 4.0.0
Apache Solr
Apache Solr 4.2.1
Apache Solr 4.3.0
Apache Solr 4.4.0
Apache Solr 4.2.0
Apache Solr 4.3.1
Apache Solr 4.1.0
1 Github repository
383
VMScore
CVE-2013-6289
Cross-site scripting (XSS) vulnerability in the Apache Solr for TYPO3 (solr) extension prior to 2.8.3 for TYPO3 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Ingo Renner Apache Solr 2.8.1
Ingo Renner Apache Solr 2.8.0
Ingo Renner Apache Solr 1.0
Ingo Renner Apache Solr 2.2.0
Ingo Renner Apache Solr 2.1.0
Ingo Renner Apache Solr 2.2.2
Ingo Renner Apache Solr 2.2.1
Ingo Renner Apache Solr
Ingo Renner Apache Solr 1.3.1
Ingo Renner Apache Solr 1.3.0
383
VMScore
CVE-2012-6573
Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x prior to 6.x-1.4 and 7.x-1.x prior to 7.x-1.3 for Drupal allows remote malicious users to inject arbitrary web script or HTML via vectors involving autocomplete results.
Alejandro Garza Apachesolr Autocomplete 6.x-1.3
Alejandro Garza Apachesolr Autocomplete 6.x-1.x
Alejandro Garza Apachesolr Autocomplete 7.x-1.x
Alejandro Garza Apachesolr Autocomplete 6.x-1.0
Alejandro Garza Apachesolr Autocomplete 6.x-1.1
Alejandro Garza Apachesolr Autocomplete 6.x-1.2
Alejandro Garza Apachesolr Autocomplete 7.x-1.0
Alejandro Garza Apachesolr Autocomplete 7.x-1.1
Alejandro Garza Apachesolr Autocomplete 7.x-1.2
383
VMScore
CVE-2009-3821
Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Apache Solr 1.0.0
357
VMScore
CVE-2021-28163
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that m...
Eclipse Jetty 11.0.0
Eclipse Jetty 10.0.0
Eclipse Jetty 11.0.1
Eclipse Jetty 10.0.1
Eclipse Jetty
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Apache Solr 8.8.1
Apache Ignite
Netapp Santricity Cloud Connector -
Netapp Snapcenter -
Netapp E-series Performance Analyzer -
Netapp E-series Santricity Web Services -
Netapp Virtual Storage Console
Netapp Storage Replication Adapter For Clustered Data Ontap
Netapp Vasa Provider For Clustered Data Ontap
Netapp Cloud Manager -
Netapp Snapcenter Plug-in -
Netapp Element Plug-in For Vcenter Server -
Netapp E-series Santricity Os Controller
Oracle Banking Digital Experience 20.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »