Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-40898
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF…
HTTP Server
2.4.62+
HIGH 7.5
CVE-2024-38472EPSS 69%
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content
Users …
HTTP Server
2.4.60+
HIGH 7.5
CVE-2024-36471
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imp…
Allura
1.17.0+
MEDIUM 5.3
CVE-2024-27347
Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0.
Use…
Hugegraph Hubble
1.3.0+
HIGH 7.3
CVE-2024-29007
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi…
Cloudstack
4.18.1.1+
CRITICAL 9.3
CVE-2024-28752
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att…
Cxf
3.5.8 / 3.6.3+
HIGH 7.5
CVE-2023-44313
Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec…
Servicecomb
2.2.0+
HIGH 7.2
CVE-2023-51441
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss…
Axis
after 1.3
CRITICAL 9.8
CVE-2023-51467EPSS 96%
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
Ofbiz
18.12.11+
HIGH 7.5
CVE-2023-50968EPSS 63%
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.
Th…
Ofbiz
18.12.11+
MEDIUM 6.5
CVE-2023-25753
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manip…
Shenyu
Mitigation only
MEDIUM 5.4
CVE-2023-36388
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib…
Superset
after 2.1.0
HIGH 8.1
CVE-2023-37379
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…
Airflow
2.7.0+
HIGH 7.1
CVE-2022-44729
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik…
Xml Graphics Batik
after 1.16
MEDIUM 6.5
CVE-2023-25504
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu…
Superset
after 2.0.1
HIGH 8.1
CVE-2023-25195
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract.
Authorized users with limited permissions can gain ac…
Fineract
after 1.8.3
CRITICAL 9.8
CVE-2022-46364
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…
Cxf
3.4.10 / 3.5.5+
HIGH 7.5
CVE-2022-41704
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri…
Batik
1.16+
HIGH 7.5
CVE-2022-42890
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML …
Batik
1.16+
HIGH 7.5
CVE-2022-40146EPSS 6%
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec…
Batik
Mitigation only
MEDIUM 5.3
CVE-2022-38398
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a…
Batik
Mitigation only
MEDIUM 5.3
CVE-2022-38648
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A…
Batik
Mitigation only
MEDIUM 6.1
CVE-2022-24969
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check whic…
Dubbo
2.6.12 / 2.7.15+
HIGH 7.5
CVE-2022-23206
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted…
Traffic Control
5.1.6 / 6.1.0+
HIGH 7.5
CVE-2021-27738
All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se…
Kylin
3.1.2+
MEDIUM 6.1
CVE-2021-25640
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or S…
Dubbo
2.6.9 / 2.7.9+
CRITICAL 9.8
CVE-2021-27905EPSS 93%
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter …
Solr
8.8.2+
HIGH 7.5
CVE-2021-22696EPSS 7%
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…
Cxf
3.3.10 / 3.4.3+
HIGH 8.6
CVE-2021-21349EPSS 47%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21342EPSS 50%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …
Activemq
1.4.16 / 5.5+