Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-40920
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixe…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-62183
Improper Privilege Management vulnerability in Apache Syncope.
When:
* the all-Java user workflow adapter is configured, or
* the Flowable user wor…
Syncope
4.0.7 / 4.1.2+
HIGH 8.1
CVE-2026-59245
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour…
Apache Airflow Providers Fab
3.7.2+
MEDIUM 5.5
CVE-2026-44119
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges…
HTTP Server
2.4.68+
HIGH 8.8
CVE-2026-24072
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges …
HTTP Server
2.4.67+
HIGH 8.1
CVE-2025-47411EPSS 15%
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th…
Streampipes
0.98.0+
MEDIUM 5.4
CVE-2025-59790
Improper Privilege Management vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0.
Users are recommende…
Kvrocks
2.14.0+
HIGH 8.8
CVE-2025-47713
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…
Cloudstack
4.19.3.0 / 4.20.1.0+
HIGH 8.8
CVE-2025-47849
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…
Cloudstack
4.19.3.0 / 4.20.1.0+
MEDIUM 6.5
CVE-2024-24778
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know.
This i…
Streampipes
0.97.0+
MEDIUM 6.5
CVE-2024-31141
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients.
Apache Kafka Clients accep…
Kafka
after 3.6.2
HIGH 8.8
CVE-2024-27181
In Apache Linkis <= 1.5.0,
Privilege Escalation in Basic management services where the attacking user is
a trusted account
allows access to Link…
Linkis
1.6.0+
HIGH 8.8
CVE-2024-23537
Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.
Users are recommended to upgrade to versi…
Fineract
1.9.0+
HIGH 8.8
CVE-2023-31469
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi…
Streampipes
after 0.91.0
HIGH 7.8
CVE-2023-30601
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This iss…
Cassandra
4.0.10 / 4.1.2+
CRITICAL 9.8
CVE-2023-31062
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.…
Inlong
after 1.6.0
CRITICAL 9.9
CVE-2023-22946
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…
Spark
3.4.0+
HIGH 8.8
CVE-2022-42735
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
ShenYu Admin allows low-privilege low-level administrators…
Shenyu
Mitigation only
CRITICAL 9.8
CVE-2021-38540EPSS 81%
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …
Airflow
2.1.3+
MEDIUM 5.3
CVE-2021-26697
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…
Airflow
Mitigation only
HIGH 7.4
CVE-2018-11767
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-d…
Hadoop
after 2.9.1
HIGH 8.8
CVE-2018-11786
In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…
Karaf
4.2.0+
CRITICAL 9.8
CVE-2017-12635EPSS 100%
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1…
Couchdb
1.7.0+