Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-24014
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…
Iotdb
2.0.8+
MEDIUM 6.5
CVE-2026-33582
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
A crafted TIFF ima…
Answer
2.0.1+
MEDIUM 6.5
CVE-2026-34031
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not…
Answer
2.0.1+
HIGH 7.3
CVE-2025-59118
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.03.
Users are recommen…
Ofbiz
24.09.03+
CRITICAL 9.8
CVE-2024-53677EPSS 78%
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th…
Struts
6.4.0+
HIGH 8.8
CVE-2024-31411
Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes.
Such a dangerous type might be an executable file that may lead …
Streampipes
0.95.0+
MEDIUM 5.3
CVE-2024-23946
Possible path traversal in Apache OFBiz allowing file inclusion.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Ofbiz
18.12.12+
CRITICAL 9.1
CVE-2024-22393
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
Pixel Flood Attack b…
Answer
1.2.5+
HIGH 8.8
CVE-2023-50386EPSS 84%
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co…
Solr
8.11.3 / 9.4.1+
CRITICAL 9.8
CVE-2022-45802
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…
Streampark
2.0.0+
CRITICAL 9.8
CVE-2023-27602
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recomme…
Linkis
after 1.3.1
CRITICAL 9.8
CVE-2021-37608EPSS 6%
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach…
Ofbiz
17.12.08+
CRITICAL 9.8
CVE-2021-21347EPSS 14%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21350EPSS 15%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21351EPSS 82%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21344EPSS 76%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21346EPSS 76%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
HIGH 8.8
CVE-2012-1592EPSS 29%
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit…
Struts
Mitigation only
CRITICAL 9.8
CVE-2019-12409EPSS 22%
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…
Solr
No fix yet
HIGH 8.1
CVE-2017-12617 KEVEPSS 100%
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…
Tomcat
7.0.82 / 8.0.47+
HIGH 8.1
CVE-2017-12615 KEVEPSS 100%
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t…
Tomcat
after 7.0.79
CRITICAL 9.8
CVE-2016-3088 KEVEPSS 99%
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol…
Activemq
5.14.0+