Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-42537
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-44416
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0.
Users are recommended to upgra…
Ranger
No fix yet
CRITICAL 9.8
CVE-2026-55799
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fi…
Ranger
No fix yet
HIGH 8.8
CVE-2026-50223
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataR…
Ofbiz
24.09.07+
HIGH 8.8
CVE-2026-45505
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…
Activemq
5.19.7 / 6.2.6+
HIGH 8.1
CVE-2026-42588
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…
Activemq
5.19.7 / 6.2.6+
HIGH 8.8
CVE-2026-46586
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vul…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-35086
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz.
This issue affects Apache OFBiz: before 2…
Ofbiz
24.09.06+
MEDIUM 6.1
CVE-2026-31379
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…
Ofbiz
24.09.06+
HIGH 8.1
CVE-2026-35194
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr…
Flink
1.20.4 / 2.0.2+
HIGH 8.8
CVE-2026-25077
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp…
Cloudstack
4.20.3.0 / 4.22.0.1+
HIGH 8.1
CVE-2026-40563
Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas
Apache Atlas exposes a DSL search endpoint that …
Atlas
2.5.0+
HIGH 8.8
CVE-2026-40466
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…
Activemq
5.19.6 / 6.2.5+
HIGH 8.8
CVE-2026-41044
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache…
Activemq
5.19.6 / 6.2.5+
HIGH 8.1
CVE-2025-54550
The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value
from xcom in the way that could be ex…
Airflow
3.2.0+
HIGH 8.8
CVE-2026-34197 KEVEPSS 97%
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apach…
Activemq
5.19.4 / 6.2.3+
CRITICAL 9.8
CVE-2025-59059
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to…
Ranger
2.8.0+
HIGH 8.4
CVE-2024-56373
DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server…
Airflow
2.11.1+
HIGH 7.3
CVE-2025-33042
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro …
Avro
1.11.5+
CRITICAL 9.8
CVE-2025-54466EPSS 15%
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects A…
Ofbiz
24.09.02+
CRITICAL 9.8
CVE-2024-24780
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…
Iotdb
1.3.4+
HIGH 7.2
CVE-2025-30067
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin.
If an attacker gets access to Kylin's system or project adm…
Kylin
5.0.2+
HIGH 8.8
CVE-2024-51941
A remote code injection vulnerability exists in the Ambari Metrics and
AMS Alerts feature, allowing authenticated users to inject and execute
arbit…
Ambari
after 2.7.8
CRITICAL 9.8
CVE-2024-47208
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.17+
HIGH 8.8
CVE-2024-48962
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…
Ofbiz
18.12.17+
CRITICAL 9.8
CVE-2024-45507EPSS 93%
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.16+
CRITICAL 9.8
CVE-2024-43202
Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
We recommend users to upgr…
Dolphinscheduler
3.2.2+
CRITICAL 9.8
CVE-2024-36268
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.10.0 through 1.12…
Inlong
1.13.0+
HIGH 8.8
CVE-2024-29178
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …
Streampark
2.1.4+
HIGH 8.8
CVE-2024-39877
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that …
Airflow
2.9.3+