Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2022-28732EPSS 82%
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascrip…
Jspwiki
2.11.3+
MEDIUM 6.1
CVE-2021-44791
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes …
Druid
after 0.22.1
CRITICAL 9.8
CVE-2022-32533
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…
Jetspeed
Mitigation only
MEDIUM 6.1
CVE-2022-34305EPSS 7%
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples…
Tomcat
after 10.0.22
MEDIUM 6.1
CVE-2022-24948
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, whi…
Jspwiki
2.11.2+
MEDIUM 6.1
CVE-2021-45229
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache…
Airflow
after 2.2.3
MEDIUM 6.1
CVE-2021-42357
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request t…
Knox
1.6.1+
MEDIUM 6.1
CVE-2021-36737
The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of th…
Pluto
3.1.1+
MEDIUM 6.1
CVE-2021-36738
The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users sho…
Pluto
3.1.1+
MEDIUM 6.1
CVE-2021-36739
The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) at…
Pluto
Mitigation only
MEDIUM 6.1
CVE-2021-40369
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow th…
Jspwiki
2.11.0+
MEDIUM 5.4
CVE-2021-32609
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a…
Superset
after 1.1
HIGH 7.3
CVE-2021-38295
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB…
Couchdb
3.1.2+
MEDIUM 6.1
CVE-2021-27578
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apac…
Zeppelin
0.9.0+
MEDIUM 6.1
CVE-2021-33192
A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects …
Jena Fuseki
4.1.0+
MEDIUM 6.1
CVE-2021-28359EPSS 14%
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.1…
Airflow
1.10.15 / 2.0.2+
MEDIUM 6.1
CVE-2020-13959EPSS 6%
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attac…
Velocity Tools
3.1+
MEDIUM 5.4
CVE-2021-27907EPSS 86%
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related informatio…
Superset
after 0.38.0
MEDIUM 6.1
CVE-2020-1936
A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
Ambari
2.7.4+
MEDIUM 5.4
CVE-2021-26544
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw t…
Livy
Patch available
MEDIUM 6.1
CVE-2020-13947EPSS 79%
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of A…
Activemq
5.15.14 / 5.16.1+
MEDIUM 6.1
CVE-2020-17515EPSS 16%
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prio…
Airflow
1.10.15 / 2.0.2+
MEDIUM 6.1
CVE-2020-13954EPSS 43%
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a r…
Cxf
3.3.8 / 3.4.1+
MEDIUM 6.1
CVE-2020-13944EPSS 25%
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
Airflow
1.10.15 / 2.0.2+
MEDIUM 6.1
CVE-2020-13928
Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of th…
Atlas
2.1.0+
MEDIUM 6.1
CVE-2020-13932
In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vuln…
Artemis
after 2.13.0
MEDIUM 6.1
CVE-2020-9485
An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.
Airflow
after 1.10.10
MEDIUM 5.4
CVE-2020-11983
An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handl…
Airflow
after 1.10.10
MEDIUM 6.1
CVE-2020-9496EPSS 99%
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
Ofbiz
No fix yet
MEDIUM 6.1
CVE-2020-1941EPSS 6%
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Activemq
after 8.2.2