Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-35003
Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut…
Nuttx
12.9.0+
CRITICAL 9.8
CVE-2025-47436
Heap-based Buffer Overflow vulnerability in Apache ORC.
A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially …
Orc
1.8.9 / 1.9.6+
CRITICAL 9.8
CVE-2024-24780
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…
Iotdb
1.3.4+
CRITICAL 9.8
CVE-2025-31651
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, i…
Tomcat
9.0.104 / 10.1.40+
CRITICAL 9.8
CVE-2025-29953
Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.
This issue affects Apache ActiveMQ NMS OpenWire Client befor…
Activemq Nms Openwire
2.1.1+
CRITICAL 9.8
CVE-2024-56325EPSS 79%
Authentication Bypass Issue
If the path does not contain / and contain., authentication is not required.
Expected Normal Request and Response Examp…
Pinot
1.3.0+
CRITICAL 9.8
CVE-2025-30065EPSS 41%
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code
Users are reco…
Parquet Java
1.15.1+
CRITICAL 9.8
CVE-2024-47552
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): from 2.0.0 before 2.…
Seata
2.2.0+
CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…
Tomcat
9.0.99 / 10.1.35+
CRITICAL 9.8
CVE-2024-55532
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0.
Users are recommended to upgrade…
Ranger
2.6.0+
CRITICAL 9.8
CVE-2024-56180
CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo…
Eventmesh
1.11.0+
CRITICAL 9.0
CVE-2024-52577
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili…
Ignite
2.17.0+
CRITICAL 9.1
CVE-2024-45479
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger…
Ranger
2.5.0+
CRITICAL 9.8
CVE-2024-54676EPSS 65%
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions …
Openmeetings
8.0.0+
CRITICAL 9.8
CVE-2024-52046EPSS 24%
The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process
incoming serialized data but lacks the necessary…
Mina
2.0.27 / 2.1.10+
CRITICAL 9.8
CVE-2024-43441EPSS 69%
Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server.
This issue affects Apache HugeGraph-Server: from 1.0.0 bef…
Hugegraph
1.5.0+
CRITICAL 9.8
CVE-2024-56337EPSS 9%
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, f…
Tomcat
9.0.98 / 10.1.34+
CRITICAL 9.8
CVE-2024-50379EPSS 44%
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file syste…
Tomcat
9.0.98 / 10.1.34+
CRITICAL 9.8
CVE-2024-53677EPSS 78%
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th…
Struts
6.4.0+
CRITICAL 9.8
CVE-2024-53947
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s…
Superset
4.1.0+
CRITICAL 9.8
CVE-2024-52338
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut…
Arrow
17.0.0+
CRITICAL 9.8
CVE-2024-52316EPSS 6%
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuth…
Tomcat
9.0.96 / 10.1.31+
CRITICAL 9.8
CVE-2024-47208
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.17+
CRITICAL 9.1
CVE-2024-50306
Unchecked return value can allow Apache Traffic Server to retain privileges on startup.
This issue affects Apache Traffic Server: from 9.2.0 through…
Traffic Server
9.2.6 / 10.0.2+
CRITICAL 9.9
CVE-2024-50386
Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan…
Cloudstack
4.18.2.5 / 4.19.1.3+
CRITICAL 9.1
CVE-2024-51504
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP bas…
Zookeeper
3.9.3+
CRITICAL 9.1
CVE-2024-23590
Session Fixation vulnerability in Apache Kylin.
This issue affects Apache Kylin: from 2.0.0 through 4.x.
Users are recommended to upgrade to versio…
Kylin
5.0.0+
CRITICAL 9.8
CVE-2024-45216EPSS 92%
Improper Authentication vulnerability in Apache Solr.
Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…
Solr
8.11.4 / 9.7.0+
CRITICAL 9.8
CVE-2024-22399
Deserialization of Untrusted Data vulnerability in Apache Seata.
When developers disable authentication on the Seata-Server and do not use the Seat…
Seata
1.8.1+
CRITICAL 9.8
CVE-2024-45507EPSS 93%
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.16+