Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-29216
In Apache Linkis <=1.3.1, because the parameters are not
effectively filtered, the attacker uses the MySQL data source and malicious parameters to
co…
Linkis
after 1.3.1
CRITICAL 9.1
CVE-2023-27987
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the de…
Linkis
after 1.3.1
CRITICAL 9.8
CVE-2023-27602
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recomme…
Linkis
after 1.3.1
CRITICAL 9.8
CVE-2023-28706
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects…
Airflow Hive Provider
6.0.0+
CRITICAL 9.8
CVE-2023-28326
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0
Description: Attacker can elevate their privi…
Openmeetings
7.0.0+
CRITICAL 9.8
CVE-2023-23638
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution.
This issue affects Apache Dubbo 2.…
Dubbo
after 3.1.5
CRITICAL 9.8
CVE-2023-25690EPSS 85%
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affec…
HTTP Server
after 2.4.55
CRITICAL 9.8
CVE-2023-25691
Improper Input Validation vulnerability in the Apache Airflow Google Provider.
This issue affects Apache Airflow Google Provider versions before 8.1…
Apache Airflow Providers Google
8.10.0+
CRITICAL 9.8
CVE-2023-25693
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
Apache Airflow Providers Apache Sqoop
3.1.1+
CRITICAL 9.8
CVE-2023-25696
Improper Input Validation vulnerability in the Apache Airflow Hive Provider.
This issue affects Apache Airflow Hive Provider versions before 5.1.3.
Apache Airflow Providers Apache Hive
5.1.3+
CRITICAL 9.8
CVE-2023-25613
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
Kerby Ldap Backend
2.0.3+
CRITICAL 9.8
CVE-2023-24997
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.…
Inlong
after 1.5.0
CRITICAL 9.8
CVE-2022-24963
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a …
Portable Runtime
Mitigation only
CRITICAL 9.8
CVE-2022-28331
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int…
Portable Runtime
after 1.7.0
CRITICAL 9.8
CVE-2023-22884EPSS 11%
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…
Airflow
2.5.1 / 4.0.0+
CRITICAL 9.0
CVE-2022-36760
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to sm…
HTTP Server
2.4.55+
CRITICAL 9.8
CVE-2022-45875
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects…
Dolphinscheduler
3.0.2+
CRITICAL 9.8
CVE-2021-32824
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…
Dubbo
2.6.10 / 2.7.10+
CRITICAL 9.8
CVE-2022-44621
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
Kylin
4.0.3+
CRITICAL 9.8
CVE-2022-45347
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentic…
Shardingsphere
5.3.0+
CRITICAL 9.8
CVE-2022-40145
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.
The function …
Karaf
4.3.8 / 4.4.2+
CRITICAL 9.8
CVE-2022-46421
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P…
Apache Airflow Providers Apache Hive
5.0.0+
CRITICAL 9.8
CVE-2022-46364
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…
Cxf
3.4.10 / 3.5.5+
CRITICAL 9.8
CVE-2022-46366
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…
Tapestry
4.0.0+
CRITICAL 9.8
CVE-2022-45462
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade…
Dolphinscheduler
2.0.6+
CRITICAL 9.8
CVE-2022-40189
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…
Airflow
2.3.0 / 4.0.0+
CRITICAL 9.8
CVE-2022-38649
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…
Airflow
2.3.0 / 4.0.0+
CRITICAL 9.8
CVE-2022-45047
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j…
Sshd
after 2.9.1
CRITICAL 9.8
CVE-2022-45136
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u…
Jena Sdb
after 3.17.0
CRITICAL 9.8
CVE-2022-45378
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invok…
Soap
after 2.3