Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2023-47804
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose.
…
Openoffice
4.1.15+
HIGH 8.8
CVE-2023-39913
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apach…
Uimaj
3.5.0+
HIGH 7.5
CVE-2023-39456EPSS 53%
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th…
Traffic Server
9.2.3+
MEDIUM 5.3
CVE-2023-45648EPSS 6%
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro…
Tomcat
8.5.94 / 9.0.81+
MEDIUM 5.5
CVE-2023-42503
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common…
Commons Compress
1.24.0+
MEDIUM 6.5
CVE-2023-39265EPSS 84%
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+p…
Superset
after 2.1.0
CRITICAL 9.8
CVE-2023-40743
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S…
Axis
2023-08-01+
HIGH 8.8
CVE-2023-27604
Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, wh…
Airflow Sqoop Provider
4.0.0+
HIGH 7.5
CVE-2023-40272
Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when est…
Apache Airflow Providers Apache Spark
4.1.3+
HIGH 7.5
CVE-2023-39553
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.
Apache Airflow Drill Provider is affected by a …
Apache Airflow Providers Apache Drill
2.4.3+
HIGH 7.5
CVE-2022-47185
Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Ser…
Traffic Server
after 9.2.1
HIGH 8.8
CVE-2023-37415
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.
Patching on top of CVE-2023-35797
Before …
Apache Airflow Providers Apache Hive
6.1.2+
MEDIUM 6.5
CVE-2023-22888
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_i…
Airflow
2.6.3+
MEDIUM 5.3
CVE-2023-34150
** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.
Any23
after 2.7
CRITICAL 9.8
CVE-2023-35797
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider.
This issue affects Apache Airflow Apache Hive Pro…
Apache Airflow Providers Apache Hive
6.1.1+
HIGH 8.8
CVE-2023-22886
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider.
Airflow JDBC Provider Connection’s [Connection UR…
Apache Airflow Providers Jdbc
4.0.0+
HIGH 7.5
CVE-2023-30631
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_…
Traffic Server
8.1.7 / 9.2.1+
CRITICAL 9.8
CVE-2022-47937
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted inpu…
Sling Commons Json
after 2.0.20
HIGH 7.2
CVE-2023-29246
An attacker who has gained access to an admin account can perform RCE via null-byte injection
Vendor: The Apache Software Foundation
Versions Affec…
Openmeetings
7.1.0+
CRITICAL 9.8
CVE-2023-31039
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file.
An attacker tha…
Brpc
1.5.0+
CRITICAL 9.1
CVE-2022-46365
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …
Streampark
2.0.0+
HIGH 7.5
CVE-2023-28707
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider:…
Apache Airflow Providers Apache Drill
2.3.2+
HIGH 7.5
CVE-2023-28710
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider:…
Apache Airflow Providers Apache Spark
4.0.1+
HIGH 7.8
CVE-2022-47502
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose.
…
Openoffice
after 4.1.13
CRITICAL 9.8
CVE-2023-25691
Improper Input Validation vulnerability in the Apache Airflow Google Provider.
This issue affects Apache Airflow Google Provider versions before 8.1…
Apache Airflow Providers Google
8.10.0+
CRITICAL 9.8
CVE-2023-25693
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
Apache Airflow Providers Apache Sqoop
3.1.1+
CRITICAL 9.8
CVE-2023-25696
Improper Input Validation vulnerability in the Apache Airflow Hive Provider.
This issue affects Apache Airflow Hive Provider versions before 5.1.3.
Apache Airflow Providers Apache Hive
5.1.3+
HIGH 7.5
CVE-2023-25692
Improper Input Validation vulnerability in the Apache Airflow Google Provider.
This issue affects Apache Airflow Google Provider versions before 8.1…
Apache Airflow Providers Google
8.10.0+
MEDIUM 6.5
CVE-2022-44644
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files b…
Linkis
after 1.3.0
CRITICAL 9.8
CVE-2022-45875
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects…
Dolphinscheduler
3.0.2+