Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-45626
Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu…
James Server
3.7.6 / 3.8.2+
MEDIUM 6.5
CVE-2024-53299
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.…
Wicket
9.19.0 / 10.3.0+
HIGH 7.5
CVE-2025-23184
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutput…
Cxf
3.5.10 / 3.6.5+
MEDIUM 5.3
CVE-2024-54677
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue a…
Tomcat
9.0.98 / 10.1.34+
HIGH 7.5
CVE-2024-32007
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of…
Cxf
3.5.9 / 3.6.4+
HIGH 7.5
CVE-2024-34750
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomc…
Tomcat
9.0.90 / 10.1.25+
MEDIUM 6.5
CVE-2024-23952
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset.
Uncontrolled resource consumption can be trig…
Superset
2.1.3 / 3.0.2+
MEDIUM 6.5
CVE-2023-46104
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.…
Superset
2.1.3 / 3.0.1+
HIGH 7.5
CVE-2023-43622EPSS 71%
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP …
HTTP Server
2.4.58+
MEDIUM 5.5
CVE-2023-42503
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common…
Commons Compress
1.24.0+
HIGH 8.1
CVE-2023-37379
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…
Airflow
2.7.0+
HIGH 7.5
CVE-2022-43766
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP que…
Iotdb
after 0.13.2
HIGH 7.5
CVE-2022-24294
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul…
Mxnet
1.9.1+
HIGH 7.5
CVE-2022-26477
The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered wi…
Systemds
after 2.2.1
HIGH 7.5
CVE-2022-29885EPSS 73%
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor in…
Tomcat
after 10.0.20
CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…
Log4j
2.1.0 / 2.3.1+
HIGH 7.5
CVE-2021-33580
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression…
Roller
6.0.2+
HIGH 7.5
CVE-2021-30468EPSS 7%
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr…
Cxf
3.3.11 / 3.4.4+
HIGH 7.5
CVE-2021-22696EPSS 7%
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…
Cxf
3.3.10 / 3.4.3+
HIGH 7.5
CVE-2021-21348EPSS 14%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
HIGH 7.5
CVE-2021-21341EPSS 78%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo…
Activemq
1.4.16 / 5.5+
MEDIUM 5.3
CVE-2020-27223EPSS 78%
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers …
Nifi
9.4.36+
HIGH 7.5
CVE-2020-13949EPSS 7%
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leadin…
Hive
4.0.0+
HIGH 7.5
CVE-2020-9481
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
Traffic Server
after 8.0.6
MEDIUM 5.5
CVE-2020-1950
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
Tika
after 1.23
HIGH 7.5
CVE-2014-0212
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
Qpid Cpp
Mitigation only
HIGH 7.5
CVE-2019-12420EPSS 7%
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r…
Spamassassin
3.4.3+
HIGH 7.5
CVE-2019-9518EPSS 25%
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra…
Traffic Server
after 8.0.3
HIGH 7.5
CVE-2019-9511EPSS 60%
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser…
Traffic Server
after 8.0.3
HIGH 7.5
CVE-2019-9512EPSS 83%
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/…
Traffic Server
8.16.1 / 10.16.3+