Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-54057
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking.
This issue affects Apache SkyWalki…
Skywalking
10.3.0+
CRITICAL 9.8
CVE-2025-59390
Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…
Druid
35.0.0+
MEDIUM 5.4
CVE-2025-62728
SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability i…
Hive
Mitigation only
HIGH 7.5
CVE-2025-65998
Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default optio…
Syncope
3.0.15 / 4.0.3+
MEDIUM 6.3
CVE-2025-64408EPSS 11%
Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul…
Causeway
3.5.0+
MEDIUM 5.3
CVE-2025-64407
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
HIGH 7.3
CVE-2025-59118
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.03.
Users are recommen…
Ofbiz
24.09.03+
MEDIUM 6.5
CVE-2025-61623
Reflected cross-site scripting vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.03.
Users are recommended to upgrade to…
Ofbiz
24.09.03+
HIGH 8.1
CVE-2025-64403
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in…
Openoffice
4.1.16+
HIGH 7.5
CVE-2025-64404
Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft…
Openoffice
4.1.16+
HIGH 7.5
CVE-2025-64405
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
MEDIUM 6.5
CVE-2025-64402
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
HIGH 7.5
CVE-2025-64401
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document tha…
Openoffice
4.1.16+
MEDIUM 5.4
CVE-2025-58337
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that s…
Doris Mcp Server
0.6.0+
HIGH 7.5
CVE-2025-62232
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…
Apisix
3.14.0+
MEDIUM 5.4
CVE-2025-62402
API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environmen…
Airflow
3.1.1+
MEDIUM 5.3
CVE-2025-61795
Improper Resource Shutdown or Release vulnerability in Apache Tomcat.
If an error occurred (including exceeding limits) during the processing of a m…
Tomcat
9.0.110 / 10.0.27+
CRITICAL 9.6
CVE-2025-55754EPSS 10%
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.
Tomcat did not escape ANSI escape sequences in log mes…
Tomcat
9.0.109 / 10.0.27+
HIGH 7.5
CVE-2025-55752EPSS 67%
Relative Path Traversal vulnerability in Apache Tomcat.
The fix for bug 60013 introduced a regression where the rewritten URL was normalized b…
Tomcat
9.0.109 / 10.0.27+
HIGH 7.2
CVE-2025-57738EPSS 23%
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few …
Syncope
3.0.14 / 4.0.2+
HIGH 8.8
CVE-2025-47410
Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricke…
Geode
1.15.2+
HIGH 7.5
CVE-2025-61581
** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control.
This issue affects Apache Traffic…
Traffic Control
after 8.0.2
CRITICAL 9.8
CVE-2025-54539
A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client.
This issue affects all versions of Apache ActiveMQ …
Activemq Nms Amqp
2.4.0+
MEDIUM 6.5
CVE-2025-55039
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0.
Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure defau…
Spark
3.4.4 / 3.5.2+
MEDIUM 6.1
CVE-2024-44088
Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a…
Geode
1.15.2+
HIGH 7.3
CVE-2025-30001
Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark.
This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.
Users a…
Streampark
2.1.6+
HIGH 8.8
CVE-2025-62228
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name.…
Flink Cdc
Mitigation only
HIGH 7.5
CVE-2025-61734EPSS 18%
Files or Directories Accessible to External Parties vulnerability in Apache Kylin.
You are fine as long as the Kylin's system and project admin acce…
Kylin
5.0.3+
HIGH 7.3
CVE-2025-61735
Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin.
This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as…
Kylin
5.0.3+
HIGH 7.5
CVE-2025-61733
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin.
This issue affects Apache Kylin: from 4.0.0 through 5.0.2.
…
Kylin
5.0.3+