Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-25757
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…
Apisix
2.13.0+
CRITICAL 9.8
CVE-2022-22720EPSS 28%
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server …
HTTP Server
10.15.7 / 11.6.6+
CRITICAL 9.8
CVE-2022-23943EPSS 50%
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. …
HTTP Server
2.4.53+
CRITICAL 9.1
CVE-2022-22721EPSS 42%
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later ca…
HTTP Server
10.15.7 / 11.6.6+
CRITICAL 9.1
CVE-2022-25312
An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions …
Any23
2.7+
CRITICAL 9.8
CVE-2022-24112 KEVEPSS 96%
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX …
Apisix
2.10.4 / 2.12.1+
CRITICAL 9.1
CVE-2021-44521EPSS 55%
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…
Cassandra
3.0.26 / 3.11.12+
CRITICAL 9.8
CVE-2021-36152
Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to ver…
Gobblin
after 0.15.0
CRITICAL 9.1
CVE-2022-23944EPSS 79%
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Patch available
CRITICAL 9.8
CVE-2021-45029EPSS 6%
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Mitigation only
CRITICAL 9.8
CVE-2022-23305EPSS 67%
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from …
Log4j
1.2.18.2+
CRITICAL 9.8
CVE-2021-43297EPSS 17%
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…
Dubbo
2.6.12 / 2.7.15+
CRITICAL 9.8
CVE-2021-31522
Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…
Kylin
3.1.3+
CRITICAL 9.8
CVE-2021-45456EPSS 89%
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…
Kylin
Mitigation only
CRITICAL 9.1
CVE-2021-40525
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writ…
James
3.6.2+
CRITICAL 9.8
CVE-2021-45232EPSS 86%
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all…
Apisix Dashboard
2.10.1+
CRITICAL 9.8
CVE-2021-44548EPSS 5%
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…
Solr
8.11.1+
CRITICAL 9.8
CVE-2021-44790EPSS 97%
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache http…
HTTP Server
2.4.52 / 5.20.0+
CRITICAL 9.0
CVE-2021-45046 KEVEPSS 100%
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at…
Log4j
2.12.2 / 2.16.0+
CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…
Log4j
2.1.0 / 2.3.1+
CRITICAL 9.1
CVE-2021-44140EPSS 6%
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…
Jspwiki
2.11.0+
CRITICAL 9.1
CVE-2021-39231
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…
Ozone
1.2.0+
CRITICAL 9.1
CVE-2021-39233
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any …
Ozone
1.2.0+
CRITICAL 9.8
CVE-2021-36372
In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authentica…
Ozone
1.2.0+
CRITICAL 9.8
CVE-2021-37580EPSS 40%
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…
Shenyu
Mitigation only
CRITICAL 9.8
CVE-2021-43350
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…
Traffic Control
5.1.4 / 6.0.1+
CRITICAL 9.8
CVE-2021-43082
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an…
Traffic Server
after 9.1.0
CRITICAL 9.8
CVE-2021-40865EPSS 66%
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (…
Storm
1.2.4 / 2.1.1+
CRITICAL 9.8
CVE-2021-38294EPSS 84%
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…
Storm
1.2.4 / 2.1.1+
CRITICAL 9.8
CVE-2021-42013 KEVEPSS 100%
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs…
HTTP Server
9.2.6.0 / 18.1.0.1.0+