Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2022-38370
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…
Iotdb
Mitigation only
CRITICAL 9.8
CVE-2022-32533
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Sett…
Jetspeed
Mitigation only
HIGH 7.5
CVE-2022-30522EPSS 90%
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m…
HTTP Server
Mitigation only
CRITICAL 9.8
CVE-2022-28890
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…
Jena
Mitigation only
CRITICAL 9.8
CVE-2021-45029EPSS 6%
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Mitigation only
MEDIUM 6.5
CVE-2022-22733EPSS 38%
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco…
Shardingsphere Elasticjob Ui
Mitigation only
HIGH 8.8
CVE-2021-43999
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo…
Guacamole
Mitigation only
CRITICAL 9.8
CVE-2021-45456EPSS 89%
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…
Kylin
Mitigation only
MEDIUM 6.1
CVE-2021-36739
The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) at…
Pluto
Mitigation only
HIGH 7.4
CVE-2021-44549
Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "…
Sling Commons Messaging Mail
Mitigation only
CRITICAL 9.8
CVE-2021-37580EPSS 40%
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue aff…
Shenyu
Mitigation only
HIGH 7.8
CVE-2021-28129
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi…
Openoffice
Mitigation only
CRITICAL 9.8
CVE-2021-41616
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…
Ddlutils
Mitigation only
MEDIUM 5.3
CVE-2021-33190
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external net…
Apisix Dashboard
Mitigation only
HIGH 7.5
CVE-2021-27737
Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
Traffic Server
No fix yet
MEDIUM 6.5
CVE-2021-26559
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur…
Airflow
Mitigation only
MEDIUM 5.3
CVE-2021-26697
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…
Airflow
Mitigation only
HIGH 7.5
CVE-2021-26118
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 …
Artemis
Mitigation only
HIGH 7.0
CVE-2020-17534
There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/J…
Html\/java Api
Mitigation only
MEDIUM 6.5
CVE-2020-13922
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter…
Dolphinscheduler
Mitigation only
CRITICAL 9.8
CVE-2020-11974EPSS 8%
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
Dolphinscheduler
Mitigation only
MEDIUM 6.5
CVE-2020-17520
In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing…
Pulsar Manager
Mitigation only
HIGH 8.8
CVE-2018-11764
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even …
Hadoop
Mitigation only
MEDIUM 5.3
CVE-2020-13937EPSS 78%
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alph…
Kylin
Mitigation only
MEDIUM 6.1
CVE-2020-9496EPSS 99%
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
Ofbiz
No fix yet
CRITICAL 9.8
CVE-2020-1955
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…
Couchdb
Mitigation only
HIGH 8.8
CVE-2019-0235EPSS 33%
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
Ofbiz
No fix yet
HIGH 7.5
CVE-2019-12425
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Ofbiz
Mitigation only
CRITICAL 9.8
CVE-2020-1964
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …
Heron
Mitigation only
MEDIUM 6.5
CVE-2020-1958
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…
Druid
Mitigation only