Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-13925EPSS 20%
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…
Kylin
3.1.0+
CRITICAL 9.8
CVE-2020-13926
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…
Kylin
3.1.0+
CRITICAL 9.8
CVE-2020-9480EPSS 29%
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…
Spark
after 2.4.5
CRITICAL 9.8
CVE-2020-11989EPSS 24%
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Shiro
1.5.3+
CRITICAL 9.8
CVE-2020-11969
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP…
Tomee
after 8.0.1
CRITICAL 9.8
CVE-2020-11975EPSS 30%
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code wi…
Unomi
1.5.1+
CRITICAL 9.1
CVE-2020-1963
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fi…
Ignite
after 2.8.0
CRITICAL 9.8
CVE-2018-21234EPSS 8%
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
Hive
5.0.4+
CRITICAL 9.8
CVE-2020-1955
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…
Couchdb
Mitigation only
CRITICAL 9.8
CVE-2020-11972EPSS 6%
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users…
Camel
after 8.2.2
CRITICAL 9.8
CVE-2020-11973EPSS 7%
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh…
Camel
after 8.5.0
CRITICAL 9.8
CVE-2019-17562
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vul…
Cloudstack
4.13.1.0+
CRITICAL 9.8
CVE-2020-1939
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs…
Nuttx
after 8.2
CRITICAL 9.8
CVE-2018-1285EPSS 17%
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…
Log4net
2.0.10+
CRITICAL 9.8
CVE-2020-1961
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e…
Syncope
2.0.15 / 2.1.6+
CRITICAL 9.8
CVE-2020-1959
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading …
Syncope
2.1.6+
CRITICAL 9.8
CVE-2020-1952
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, c…
Iotdb
after 0.9.1
CRITICAL 9.8
CVE-2020-1964
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …
Heron
Mitigation only
CRITICAL 9.8
CVE-2019-17564EPSS 37%
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in…
Dubbo
after 2.7.4
CRITICAL 9.1
CVE-2019-17560
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to interc…
Netbeans
after 11.2
CRITICAL 9.8
CVE-2020-1957EPSS 23%
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Shiro
1.5.2+
CRITICAL 9.8
CVE-2019-17559
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgr…
Traffic Server
after 8.0.5
CRITICAL 9.8
CVE-2019-17565
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Up…
Traffic Server
after 8.0.5
CRITICAL 9.8
CVE-2020-1944
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding an…
Traffic Server
after 8.0.5
CRITICAL 10.0
CVE-2020-1953EPSS 7%
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…
Commons Configuration
Mitigation only
CRITICAL 9.8
CVE-2020-1947EPSS 34%
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …
Shardingsphere
Mitigation only
CRITICAL 9.8
CVE-2020-1938 KEVEPSS 99%
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as …
Geode
7.0.100 / 8.5.51+
CRITICAL 9.8
CVE-2014-4651
It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc…
Jclouds
1.8.0+
CRITICAL 9.8
CVE-2019-17570EPSS 49%
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar…
Xml Rpc
Patch available
CRITICAL 9.8
CVE-2019-0219EPSS 8%
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially craft…
Cordova Inappbrowser
after 3.0.0