Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…
HTTP Server
Patch available
CRITICAL 9.8
CVE-2021-41616
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…
Ddlutils
Mitigation only
CRITICAL 9.8
CVE-2021-41303EPSS 77%
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…
Shiro
1.8.0+
CRITICAL 9.8
CVE-2021-39275EPSS 39%
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but t…
HTTP Server
2.4.49+
CRITICAL 9.8
CVE-2021-40146EPSS 6%
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vuln…
Any23
2.5+
CRITICAL 9.1
CVE-2021-38555
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…
Any23
2.5+
CRITICAL 9.8
CVE-2021-38540EPSS 81%
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …
Airflow
2.1.3+
CRITICAL 9.8
CVE-2021-37579EPSS 7%
The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…
Dubbo
2.7.13 / 3.0.2+
CRITICAL 9.8
CVE-2021-36161
Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean…
Dubbo
2.7.13+
CRITICAL 9.8
CVE-2021-36163
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…
Dubbo
after 3.0.1
CRITICAL 9.8
CVE-2019-10095EPSS 6%
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe…
Zeppelin
after 0.9.0
CRITICAL 9.8
CVE-2021-33191
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th…
Nifi Minifi C\+\+
0.10.0+
CRITICAL 9.8
CVE-2021-37608EPSS 6%
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach…
Ofbiz
17.12.08+
CRITICAL 9.8
CVE-2021-37578
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo…
Juddi
3.3.10+
CRITICAL 9.8
CVE-2021-35474
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.…
Traffic Server
after 9.0.1
CRITICAL 9.8
CVE-2021-26461EPSS 5%
Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignmen…
Nuttx
10.1.0+
CRITICAL 9.8
CVE-2020-9493
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.
Chainsaw
1.2.18.1 / 2.0+
CRITICAL 9.8
CVE-2021-26691EPSS 68%
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
HTTP Server
18.1.0.1.0+
CRITICAL 9.8
CVE-2021-25641EPSS 21%
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before…
Dubbo
2.6.9 / 2.7.8+
CRITICAL 9.8
CVE-2021-30179
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha…
Dubbo
2.6.9 / 2.7.10+
CRITICAL 9.8
CVE-2021-30180EPSS 60%
Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the cu…
Dubbo
2.7.10+
CRITICAL 9.8
CVE-2021-30181EPSS 61%
Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are …
Dubbo
2.6.10 / 2.7.10+
CRITICAL 9.8
CVE-2021-22160EPSS 53%
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if th…
Pulsar
2.7.1+
CRITICAL 9.8
CVE-2021-29200EPSS 55%
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Ofbiz
17.12.07+
CRITICAL 9.8
CVE-2021-30128EPSS 81%
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Ofbiz
17.12.07+
CRITICAL 9.1
CVE-2021-26291EPSS 9%
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting …
Maven
1.13.5 / 3.8.1+
CRITICAL 9.8
CVE-2021-27850EPSS 94%
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…
Tapestry
5.6.2 / 5.7.1+
CRITICAL 9.8
CVE-2021-27905EPSS 93%
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …
Solr
8.8.2+
CRITICAL 9.1
CVE-2021-29943EPSS 5%
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usi…
Solr
8.8.2+
CRITICAL 9.8
CVE-2020-1946EPSS 6%
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …
Spamassassin
3.4.5+