Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-68971
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis…
Airflow
3.3.1+
CRITICAL 9.8
CVE-2026-68979
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…
Nifi
2.11.0+
HIGH 8.8
CVE-2026-50622
Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated …
Atlas
2.6.0+
MEDIUM 6.5
CVE-2026-49326
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.
A scan operation in thrift/rest service has 3 steps, open, f…
Hbase
2.5.15 / 2.6.6+
HIGH 7.5
CVE-2026-54475
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic temporary destinations …
Activemq
5.19.8 / 6.2.7+
HIGH 7.2
CVE-2026-44914
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Per…
Nifi
2.10.0+
HIGH 8.8
CVE-2026-39816
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi…
Nifi
2.9.0+
CRITICAL 9.9
CVE-2026-42809
Apache Polaris can issue broad temporary ("vended") storage credentials during
staged
table creation before the effective table location has been val…
Polaris
1.4.1+
HIGH 8.1
CVE-2026-30911
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows…
Airflow
3.1.8+
MEDIUM 6.6
CVE-2026-25903
Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required …
Nifi
2.8.0+
MEDIUM 5.3
CVE-2025-64407
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
HIGH 8.1
CVE-2025-64403
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in…
Openoffice
4.1.16+
HIGH 7.5
CVE-2025-64404
Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft…
Openoffice
4.1.16+
HIGH 7.5
CVE-2025-64405
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
MEDIUM 6.5
CVE-2025-64402
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
HIGH 7.5
CVE-2025-64401
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
MEDIUM 5.4
CVE-2024-56512
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenc…
Nifi
2.1.0+
MEDIUM 6.3
CVE-2024-45461
The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. …
Cloudstack
4.18.2.4 / 4.19.1.2+
MEDIUM 5.3
CVE-2024-23944
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by…
Zookeeper
3.8.4 / 3.9.2+
MEDIUM 5.9
CVE-2024-27906
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not hav…
Airflow
2.8.2+
MEDIUM 6.5
CVE-2023-50944
Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …
Airflow
2.8.1+
HIGH 7.5
CVE-2023-51650
Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized acc…
Hertzbeat
1.4.1+
MEDIUM 6.5
CVE-2023-49620
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), …
Dolphinscheduler
3.1.0+
HIGH 7.8
CVE-2023-26269
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation b…
James
3.7.4+
HIGH 7.5
CVE-2022-38370
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…
Iotdb
Mitigation only
CRITICAL 9.1
CVE-2022-23944EPSS 79%
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Patch available
HIGH 7.5
CVE-2022-23945
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Patch available
CRITICAL 9.1
CVE-2021-39231
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…
Ozone
1.2.0+
HIGH 8.8
CVE-2021-39232
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
Ozone
1.2.0+
HIGH 8.8
CVE-2021-39236
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
Ozone
1.2.0+