Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2025-62235
Authentication Bypass by Spoofing vulnerability in Apache NimBLE.
Receiving specially crafted Security Request could lead to removal of original bon…
Nimble
1.9.0+
HIGH 7.5
CVE-2025-52435
J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.
Improper handling of Pause Encryption procedure on Link …
Nimble
1.9.0+
HIGH 7.5
CVE-2025-53477
NULL Pointer Dereference vulnerability in Apache Nimble.
Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL p…
Nimble
1.9.0+
CRITICAL 9.1
CVE-2025-68637
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname verification by default. This insecure configuration
expos…
Uniffle
0.10.0+
MEDIUM 6.5
CVE-2025-68280
Improper Restriction of XML External Entity Reference vulnerability in Apache SIS.
It is possible to write XML files in such a way that, when pars…
Spatial Information System
after 1.5
HIGH 8.8
CVE-2025-66518
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and…
Kyuubi
1.10.3+
HIGH 8.1
CVE-2025-48769
Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer us…
Nuttx
12.11.0+
MEDIUM 6.5
CVE-2025-48768
Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root files…
Nuttx
12.10.0+
HIGH 8.1
CVE-2025-47411EPSS 15%
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th…
Streampipes
0.98.0+
HIGH 8.8
CVE-2025-66524
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Ser…
Nifi
2.7.0+
CRITICAL 9.8
CVE-2025-67895
Edge3 Worker RPC RCE on Airflow 2.
This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on …
Apache Airflow Providers Edge3
2.0.0+
MEDIUM 6.5
CVE-2025-66388
A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redact…
Airflow
3.1.4+
MEDIUM 5.9
CVE-2025-53960
When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An …
Streampark
2.1.7+
CRITICAL 9.8
CVE-2025-54947
In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…
Streampark
2.1.7+
HIGH 7.5
CVE-2025-54981
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, inclu…
Streampark
2.1.7+
CRITICAL 9.1
CVE-2025-58130
Insufficiently Protected Credentials vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver…
Fineract
1.12.1+
HIGH 8.8
CVE-2025-26866
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en…
Hugegraph
1.7.0+
HIGH 8.1
CVE-2025-58137
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.11.0. The issue is …
Fineract
1.12.1+
MEDIUM 6.5
CVE-2025-23408
Weak Password Requirements vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.…
Fineract
1.11.0+
HIGH 8.2
CVE-2025-66675
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts…
Struts
6.8.0 / 7.1.1+
HIGH 8.3
CVE-2025-58098
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to…
HTTP Server
2.4.66+
HIGH 7.5
CVE-2025-59775
Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off allows to po…
HTTP Server
2.4.66+
MEDIUM 6.5
CVE-2025-65082
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache co…
HTTP Server
2.4.66+
MEDIUM 5.4
CVE-2025-66200
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in hta…
HTTP Server
2.4.66+
HIGH 7.5
CVE-2025-55753
An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the bac…
HTTP Server
2.4.66+
CRITICAL 9.8
CVE-2025-66516EPSS 79%
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…
Tika
3.2.2+
HIGH 7.5
CVE-2025-64775
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts…
Struts
6.8.0 / 7.1.1+
HIGH 7.5
CVE-2025-59789
Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash v…
Brpc
1.15.0+
MEDIUM 5.3
CVE-2025-59792
Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0.
…
Kvrocks
2.14.0+
MEDIUM 5.4
CVE-2025-59790
Improper Privilege Management vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0.
Users are recommende…
Kvrocks
2.14.0+