Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-34486 KEVEPSS 83%
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
…
Tomcat
Mitigation only
HIGH 8.8
CVE-2026-34197 KEVEPSS 97%
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apach…
Activemq
5.19.4 / 6.2.3+
CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…
Tomcat
9.0.99 / 10.1.35+
HIGH 7.5
CVE-2024-45195 KEVEPSS 100%
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrad…
Ofbiz
18.12.16+
CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to versi…
Ofbiz
18.12.15+
CRITICAL 9.1
CVE-2024-38475 KEVEPSS 100%
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p…
HTTP Server
2.4.60 / 10.2.1.14-75sv+
CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …
Ofbiz
18.12.13+
CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …
Hugegraph
1.3.0+
CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to…
Activemq
5.15.16 / 5.16.7+
CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of RocketMQ, inclu…
Rocketmq
4.9.6 / 5.1.1+
CRITICAL 9.8
CVE-2023-27524 KEVEPSS 97%
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K…
Superset
after 2.0.1
HIGH 8.8
CVE-2022-33891 KEVEPSS 93%
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks …
Spark
after 3.2.1
CRITICAL 9.8
CVE-2022-24706 KEVEPSS 92%
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.…
Couchdb
3.2.2+
CRITICAL 9.8
CVE-2022-24112 KEVEPSS 96%
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX …
Apisix
2.10.4 / 2.12.1+
CRITICAL 9.0
CVE-2021-45046 KEVEPSS 100%
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at…
Log4j
2.12.2 / 2.16.0+
CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…
Log4j
2.1.0 / 2.3.1+
CRITICAL 9.8
CVE-2021-42013 KEVEPSS 100%
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs…
HTTP Server
9.2.6.0 / 18.1.0.1.0+
CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…
HTTP Server
Patch available
HIGH 7.8
CVE-2021-21315 KEVEPSS 91%
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,…
Cordova
5.3.1+
HIGH 7.5
CVE-2020-17519 KEVEPSS 98%
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t…
Flink
1.11.3+
CRITICAL 9.8
CVE-2020-17530 KEVEPSS 96%
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.…
Struts
2.5.30+
CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…
Airflow
1.10.11+
HIGH 8.8
CVE-2020-11978 KEVEPSS 99%
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…
Airflow
1.10.11+
HIGH 8.8
CVE-2020-1956 KEVEPSS 97%
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …
Kylin
after 2.6.5
CRITICAL 9.8
CVE-2020-1938 KEVEPSS 99%
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as …
Geode
7.0.100 / 8.5.51+
HIGH 7.5
CVE-2019-17558 KEVEPSS 99%
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…
Solr
7.7.3 / 8.4.0+
HIGH 7.2
CVE-2019-0193 KEVEPSS 84%
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…
Solr
7.7.3 / 8.1.2+
HIGH 7.8
CVE-2019-0211 KEVEPSS 65%
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads …
HTTP Server
after 2.4.38
HIGH 8.1
CVE-2018-11776 KEVEPSS 100%
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by u…
Struts
2.3.35 / 2.5.17+
HIGH 8.1
CVE-2017-12617 KEVEPSS 100%
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…
Tomcat
7.0.82 / 8.0.47+