Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-21347EPSS 14%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21350EPSS 15%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21351EPSS 82%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…
Activemq
1.4.16 / 5.5+
CRITICAL 9.9
CVE-2021-21345EPSS 72%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21344EPSS 76%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21346EPSS 76%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21342EPSS 50%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-26295EPSS 98%
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF…
Ofbiz
17.12.06+
CRITICAL 9.8
CVE-2020-17523EPSS 86%
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Shiro
1.7.1+
CRITICAL 9.1
CVE-2021-23901
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa…
Nutch
1.18+
CRITICAL 9.1
CVE-2021-23926EPSS 6%
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities …
Xmlbeans
after 2.6.0
CRITICAL 9.8
CVE-2020-11995EPSS 6%
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H…
Dubbo
after 2.7.7
CRITICAL 9.8
CVE-2020-11974EPSS 8%
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
Dolphinscheduler
Mitigation only
CRITICAL 9.8
CVE-2020-13931
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker co…
Tomee
after 8.0.3
CRITICAL 9.8
CVE-2020-17530 KEVEPSS 96%
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.…
Struts
2.5.30+
CRITICAL 9.8
CVE-2020-17529
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …
Nuttx
after 9.1.0
CRITICAL 9.1
CVE-2020-17528
Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt …
Nuttx
after 9.1.0
CRITICAL 9.8
CVE-2020-17531EPSS 10%
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok…
Tapestry
5.0.1+
CRITICAL 9.8
CVE-2020-13942EPSS 68%
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…
Unomi
1.5.2+
CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…
Airflow
1.10.11+
CRITICAL 9.8
CVE-2020-17510EPSS 9%
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Shiro
1.7.0+
CRITICAL 9.8
CVE-2020-13957EPSS 79%
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co…
Solr
after 8.6.2
CRITICAL 9.8
CVE-2019-0230EPSS 97%
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Struts
after 8.0.23
CRITICAL 9.8
CVE-2020-11998EPSS 51%
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map …
Activemq
after 8.5.0
CRITICAL 9.8
CVE-2020-11986EPSS 10%
To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build…
Netbeans
after 12.0
CRITICAL 9.8
CVE-2020-11984EPSS 90%
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
HTTP Server
after 8.2.2
CRITICAL 9.8
CVE-2020-13921EPSS 33%
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
Skywalking
Patch available
CRITICAL 9.8
CVE-2020-11981EPSS 37%
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ…
Airflow
after 1.10.10
CRITICAL 9.8
CVE-2020-11982EPSS 7%
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) …
Airflow
after 1.10.10
CRITICAL 9.8
CVE-2020-1948EPSS 16%
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met…
Dubbo
after 2.7.6