Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2024-39864
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio…
Cloudstack
4.18.2.1 / 4.19.0.2+
CRITICAL 9.8
CVE-2024-38346
The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …
Cloudstack
4.18.2.1 / 4.19.0.2+
MEDIUM 6.6
CVE-2023-35701
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive.
The vulnerability affects the Hive JDBC driver component and…
Hive
Mitigation only
CRITICAL 9.8
CVE-2024-31864
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.
The attacker can inject sensitive configuration or malic…
Zeppelin
0.11.1+
HIGH 8.8
CVE-2023-50379
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cl…
Ambari
2.7.8+
HIGH 7.5
CVE-2023-51770
Arbitrary File Read Vulnerability in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.1.
We recommend users to upgr…
Dolphinscheduler
3.2.1+
CRITICAL 9.8
CVE-2023-49109
Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.1.
We recommend users to upgr…
Dolphinscheduler
3.2.1+
CRITICAL 9.8
CVE-2023-46226
Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2.
Users are recommended to upgrade to v…
Iotdb
1.3.0+
CRITICAL 9.8
CVE-2023-51784
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, …
Inlong
1.10.0+
HIGH 8.8
CVE-2023-51387
Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo…
Hertzbeat
1.4.1+
CRITICAL 9.8
CVE-2023-49070EPSS 95%
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present.
This issue affects Apache OFBiz: before 18.12.10.
Us…
Ofbiz
18.12.10+
HIGH 8.8
CVE-2023-36542
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an …
Nifi
after 1.22.0
CRITICAL 9.8
CVE-2023-37582EPSS 90%
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version …
Rocketmq
after 5.1.1
HIGH 8.8
CVE-2023-34468EPSS 64%
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user …
Nifi
1.22.0+
CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of RocketMQ, inclu…
Rocketmq
4.9.6 / 5.1.1+
CRITICAL 9.8
CVE-2023-28706
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects…
Airflow Hive Provider
6.0.0+
HIGH 7.8
CVE-2022-38745
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro…
Openoffice
4.1.14+
HIGH 8.8
CVE-2022-40127EPSS 86%
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually …
Airflow
2.4.0+
CRITICAL 9.8
CVE-2022-42889EPSS 100%
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…
Commons Text
1.10.0 / 7.5.0+
CRITICAL 9.8
CVE-2022-26112
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…
Pinot
0.11.0+
HIGH 7.5
CVE-2022-25813EPSS 67%
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a …
Ofbiz
18.12.06+
CRITICAL 9.1
CVE-2021-44521EPSS 55%
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…
Cassandra
3.0.26 / 3.11.12+
CRITICAL 9.8
CVE-2021-45029EPSS 6%
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Mitigation only
CRITICAL 9.9
CVE-2021-21345EPSS 72%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
HIGH 7.2
CVE-2019-0193 KEVEPSS 84%
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…
Solr
7.7.3 / 8.1.2+
CRITICAL 9.8
CVE-2018-11780EPSS 11%
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
Spamassassin
3.4.2+
HIGH 7.8
CVE-2018-11781
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
Spamassassin
3.4.2+
CRITICAL 9.8
CVE-2011-2767EPSS 9%
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do…
Mod Perl
after 2.0.10
HIGH 7.2
CVE-2015-0249
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…
Roller
Mitigation only
CRITICAL 9.8
CVE-2014-3582
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo…
Ambari
after 2.2.2