Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2025-57735
When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was inte…
Airflow
3.2.0+
CRITICAL 9.8
CVE-2026-24015
A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrad…
Iotdb
1.3.7 / 2.0.7+
CRITICAL 9.8
CVE-2026-24713
Improper Input Validation vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users a…
Iotdb
1.3.7 / 2.0.7+
CRITICAL 9.8
CVE-2026-27446EPSS 10%
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…
Artemis
after 2.44.0
CRITICAL 9.8
CVE-2025-59059
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to…
Ranger
2.8.0+
CRITICAL 9.1
CVE-2026-23552
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.
The Camel-Keycloak KeycloakSecurityPolicy does not v…
Camel
4.18.0+
CRITICAL 9.1
CVE-2025-66614
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…
Tomcat
9.0.113 / 10.1.50+
CRITICAL 9.8
CVE-2026-23906
Affected Products and Versions
* Apache Druid
* Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0)
* Prerequisites: * d…
Druid
36.0.0+
CRITICAL 9.9
CVE-2016-15057
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum…
Continuum
Mitigation only
CRITICAL 9.8
CVE-2025-60021EPSS 25%
Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …
Brpc
1.15.0+
CRITICAL 9.1
CVE-2025-68637
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname verification by default. This insecure configuration
expos…
Uniffle
0.10.0+
CRITICAL 9.8
CVE-2025-67895
Edge3 Worker RPC RCE on Airflow 2.
This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on …
Apache Airflow Providers Edge3
2.0.0+
CRITICAL 9.8
CVE-2025-54947
In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…
Streampark
2.1.7+
CRITICAL 9.1
CVE-2025-58130
Insufficiently Protected Credentials vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver…
Fineract
1.12.1+
CRITICAL 9.8
CVE-2025-66516EPSS 79%
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…
Tika
3.2.2+
CRITICAL 9.8
CVE-2025-59390
Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…
Druid
35.0.0+
CRITICAL 9.6
CVE-2025-55754EPSS 10%
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.
Tomcat did not escape ANSI escape sequences in log mes…
Tomcat
9.0.109 / 10.0.27+
CRITICAL 9.8
CVE-2025-54539
A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client.
This issue affects all versions of Apache ActiveMQ …
Activemq Nms Amqp
2.4.0+
CRITICAL 9.8
CVE-2025-61622EPSS 41%
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…
Fory
after 0.12.2
CRITICAL 9.8
CVE-2024-43166
Incorrect Default Permissions vulnerability in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
Users are recomme…
Dolphinscheduler
3.2.2+
CRITICAL 9.8
CVE-2025-54466EPSS 15%
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects A…
Ofbiz
24.09.02+
CRITICAL 9.8
CVE-2025-53606
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): 2.4.0.
Users are recomm…
Seata
Mitigation only
CRITICAL 9.8
CVE-2025-48913
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…
Cxf
3.6.8 / 4.0.9+
CRITICAL 9.1
CVE-2025-23048
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 …
HTTP Server
2.4.64+
CRITICAL 9.8
CVE-2025-32897
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This security vulnerability is the same as CVE-2024-47552, but the ver…
Seata
2.3.0+
CRITICAL 9.8
CVE-2025-50213
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.
This is…
Apache Airflow Providers Snowflake
6.4.0+
CRITICAL 9.8
CVE-2025-47868
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that…
Nuttx
12.9.0+
CRITICAL 9.8
CVE-2025-47869
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic…
Nuttx
12.9.0+
CRITICAL 9.8
CVE-2025-27531
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 before 2.1.0,
this issue would al…
Inlong
2.1.0+
CRITICAL 9.1
CVE-2025-27528
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability …
Inlong
2.2.0+