Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-49097
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-49098
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-49099
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key …
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48203
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2024-36522
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…
Wicket
8.16.0 / 9.18.0+
MEDIUM 5.3
CVE-2024-21742
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message.
This can be exploited by an atta…
James Mime4j
after 0.8.9
CRITICAL 9.8
CVE-2023-51388
Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no …
Hertzbeat
1.4.1+
CRITICAL 9.8
CVE-2023-51653
Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec…
Hertzbeat
1.4.1+
CRITICAL 9.8
CVE-2022-46337
A cleverly devised username might bypass LDAP authentication checks. In
LDAP-authenticated Derby installations, this could let an attacker fill
up …
Derby
10.14.3.0 / 10.15.2.1+
HIGH 7.5
CVE-2023-43667
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects …
Inlong
after 1.8.0
MEDIUM 6.1
CVE-2023-41834
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject…
Flink Stateful Functions
after 3.2.0
HIGH 7.2
CVE-2023-33234
Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow …
Apache Airflow Providers Cncf Kubernetes
7.0.0+
HIGH 8.8
CVE-2022-45048
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe…
Ranger
Mitigation only
MEDIUM 5.4
CVE-2022-45801
Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability.
LDAP Injection is an attack used to exploit web based applications
that constru…
Streampark
2.0.0+
CRITICAL 9.8
CVE-2023-25613
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
Kerby Ldap Backend
2.0.3+
HIGH 7.5
CVE-2023-25141
Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct…
Sling Jcr Base
3.1.12+
MEDIUM 5.4
CVE-2022-43720
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the t…
Superset
after 1.5.2
CRITICAL 9.8
CVE-2022-40145
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.
The function …
Karaf
4.3.8 / 4.4.2+
MEDIUM 5.3
CVE-2022-45910
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory …
Manifoldcf
after 2.23
MEDIUM 5.4
CVE-2022-31777
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScri…
Spark
3.2.2+
CRITICAL 9.8
CVE-2022-42468
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…
Flume
after 1.10.1
CRITICAL 9.8
CVE-2022-25167
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…
Flume
1.10.0+
MEDIUM 6.6
CVE-2021-44832EPSS 98%
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…
Log4j
2.3.2 / 2.12.4+
CRITICAL 9.8
CVE-2021-43350
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…
Traffic Control
5.1.4 / 6.0.1+
CRITICAL 9.8
CVE-2021-38294EPSS 84%
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…
Storm
1.2.4 / 2.1.1+
HIGH 7.5
CVE-2021-31164
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
Unomi
1.5.5+
CRITICAL 9.8
CVE-2020-13942EPSS 68%
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…
Unomi
1.5.2+
HIGH 7.5
CVE-2020-11994
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
Camel
after 8.5.0
MEDIUM 5.3
CVE-2020-9495EPSS 8%
Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP…
Archiva
2.2.5+
CRITICAL 9.8
CVE-2020-1961
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e…
Syncope
2.0.15 / 2.1.6+