Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-32227
SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the…
Ranger
No fix yet
CRITICAL 9.1
CVE-2026-34191
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…
Apr Util
after 1.6.3
CRITICAL 9.8
CVE-2026-57308
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.
An administrator with adequate…
Syncope
4.0.7 / 4.1.2+
HIGH 8.1
CVE-2026-56287
A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.…
Fineract
1.15.0+
HIGH 8.1
CVE-2026-57821
A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy…
Fineract
1.15.0+
HIGH 8.8
CVE-2026-35152
A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report p…
Fineract
1.15.0+
CRITICAL 9.8
CVE-2026-62390
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…
Kylin
5.0.4+
MEDIUM 5.4
CVE-2025-53648
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
Users are recommended to…
Gravitino
1.0.0+
HIGH 8.1
CVE-2025-66336
Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated int…
Doris Mcp Server
0.6.1+
MEDIUM 5.3
CVE-2025-66335
Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow executio…
Doris Mcp Server
0.6.1+
MEDIUM 6.5
CVE-2026-23969
Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within…
Superset
4.1.2+
MEDIUM 6.5
CVE-2026-23980
Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user wit…
Superset
6.0.0+
MEDIUM 5.3
CVE-2025-66169
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before…
Camel
4.10.8 / 4.14.3+
MEDIUM 5.4
CVE-2025-62728
SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i…
Hive
Mitigation only
HIGH 8.8
CVE-2025-62228
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.…
Flink Cdc
Mitigation only
HIGH 7.6
CVE-2024-48988
SQL Injection vulnerability in Apache StreamPark.
This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.
Users are recommended to upgrade t…
Streampark
2.1.6+
MEDIUM 6.5
CVE-2025-55674
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a…
Superset
5.0.0+
MEDIUM 6.5
CVE-2025-48912
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression'…
Superset
4.1.2+
HIGH 8.8
CVE-2025-30473
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider.
When using…
Airflow Common Sql Provider
1.24.1+
HIGH 8.8
CVE-2024-53678
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitte…
Vcl
2.5.2+
MEDIUM 6.3
CVE-2025-27018
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
When user trigg…
Apache Airflow Providers Mysql
6.2.0+
HIGH 8.8
CVE-2024-32838
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that al…
Fineract
1.10.1+
HIGH 8.8
CVE-2024-45387EPSS 42%
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …
Traffic Control
8.0.2+
CRITICAL 9.8
CVE-2024-53947
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s…
Superset
4.1.0+
CRITICAL 9.8
CVE-2024-42361
Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin…
Hertzbeat
1.6.0+
CRITICAL 9.8
CVE-2024-39887
An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…
Superset
4.0.2+
HIGH 8.1
CVE-2023-52290
In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…
Streampark
2.1.4+
HIGH 8.1
CVE-2024-36263
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarin…
Submarine
Patch available
CRITICAL 9.8
CVE-2024-23538
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…
Fineract
1.9.0+
CRITICAL 9.8
CVE-2024-23539
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…
Fineract
1.9.0+