Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-42920
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds wri…
Commons Bcel
6.6.0+
CRITICAL 9.1
CVE-2022-37865
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip…
Ivy
2.5.1+
CRITICAL 9.8
CVE-2022-42468
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…
Flume
after 1.10.1
CRITICAL 9.8
CVE-2021-42010
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-…
Heron
0.20.5-incubating+
CRITICAL 9.8
CVE-2022-39198
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…
Dubbo
after 3.0.11
CRITICAL 9.8
CVE-2022-42889EPSS 100%
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…
Commons Text
1.10.0 / 7.5.0+
CRITICAL 9.8
CVE-2022-24697EPSS 85%
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can…
Kylin
2.6.6+
CRITICAL 9.8
CVE-2022-40664
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
Shiro
1.10.0+
CRITICAL 9.8
CVE-2022-26112
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…
Pinot
0.11.0+
CRITICAL 9.8
CVE-2022-39135
Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe…
Calcite
1.32.0+
CRITICAL 9.8
CVE-2022-25371
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in…
Ofbiz
18.12.06+
CRITICAL 9.8
CVE-2022-29063
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier…
Ofbiz
18.12.06+
CRITICAL 9.8
CVE-2022-38054
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
Airflow
after 2.3.3
CRITICAL 9.8
CVE-2022-37021
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A…
Geode
after 1.13.4
CRITICAL 9.8
CVE-2022-34916
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI …
Flume
1.10.1+
CRITICAL 9.8
CVE-2022-25168
Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary…
Hadoop
after 3.3.2
CRITICAL 9.8
CVE-2022-35741EPSS 8%
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entit…
Cloudstack
4.16.1.1+
CRITICAL 9.8
CVE-2022-33980EPSS 43%
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for i…
Commons Configuration
2.8+
CRITICAL 9.8
CVE-2022-32533
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…
Jetspeed
Mitigation only
CRITICAL 9.8
CVE-2022-32532EPSS 27%
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…
Shiro
1.9.1+
CRITICAL 9.8
CVE-2022-25167
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…
Flume
1.10.0+
CRITICAL 9.8
CVE-2021-37404
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in…
Hadoop
2.10.2 / 3.2.3+
CRITICAL 9.8
CVE-2022-31813
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop m…
HTTP Server
2.4.54+
CRITICAL 9.1
CVE-2022-28615EPSS 6%
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extrem…
HTTP Server
2.4.54+
CRITICAL 9.8
CVE-2022-29599
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing she…
Maven Shared Utils
3.3.3+
CRITICAL 9.8
CVE-2022-28890
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…
Jena
Mitigation only
CRITICAL 9.8
CVE-2022-24706 KEVEPSS 92%
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.…
Couchdb
3.2.2+
CRITICAL 9.8
CVE-2022-27479
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
Superset
1.4.2+
CRITICAL 9.8
CVE-2021-31805EPSS 85%
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double ev…
Struts
after 2.5.29
CRITICAL 9.8
CVE-2022-26612
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR …
Hadoop
3.2.3+