Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-61622EPSS 41%
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…
Fory
after 0.12.2
MEDIUM 6.5
CVE-2025-54831
Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connecti…
Airflow
Mitigation only
MEDIUM 5.3
CVE-2025-48459
Deserialization of Untrusted Data vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 2.0.5.
Users are recommended to…
Iotdb
2.0.5+
HIGH 7.5
CVE-2025-48392
A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4.
Users are recommended to…
Iotdb
2.0.5+
MEDIUM 6.5
CVE-2025-59328
A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr…
Fory
0.12.2+
HIGH 8.8
CVE-2025-24404
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.
The attacker needs to have an authenticated accou…
Hertzbeat
1.7.0+
HIGH 8.8
CVE-2025-48208
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .
The attacker nee…
Hertzbeat
1.7.3+
MEDIUM 6.5
CVE-2025-58782
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons.
This issue affects Apache Jackrabbit Co…
Jackrabbit
2.22.2+
CRITICAL 9.8
CVE-2024-43166
Incorrect Default Permissions vulnerability in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
Users are recomme…
Dolphinscheduler
3.2.2+
HIGH 8.8
CVE-2024-43115
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script.
This…
Dolphinscheduler
3.2.2+
HIGH 8.8
CVE-2025-26467
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to s…
Cassandra
3.0.31 / 3.11.18+
HIGH 7.5
CVE-2025-54813
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx.
When using JSONLayout, not all payload bytes are properly escaped. If an at…
Log4cxx
1.5.0+
MEDIUM 5.4
CVE-2025-54812
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx.
When using HTMLLayout, logger names are not properly escaped when writing …
Log4cxx
1.5.0+
HIGH 7.6
CVE-2024-48988
SQL Injection vulnerability in Apache StreamPark.
This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.
Users are recommended to upgrade t…
Streampark
2.1.6+
HIGH 8.4
CVE-2025-54988EPSS 9%
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out…
Tika
3.2.2+
MEDIUM 6.3
CVE-2024-39954
CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse…
Eventmesh
1.12.0+
HIGH 8.8
CVE-2025-53192
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL.
This issue affects Ap…
Commons Ognl
Mitigation only
CRITICAL 9.8
CVE-2025-54466EPSS 15%
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects A…
Ofbiz
24.09.02+
MEDIUM 6.5
CVE-2025-55674
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a…
Superset
5.0.0+
MEDIUM 6.5
CVE-2025-55675
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated use…
Superset
5.0.0+
MEDIUM 5.4
CVE-2025-55672
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit cha…
Superset
5.0.0+
HIGH 7.5
CVE-2025-54472
Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi…
Brpc
1.14.1+
MEDIUM 6.5
CVE-2025-55668
Session Fixation vulnerability in Apache Tomcat via rewrite valve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 t…
Tomcat
9.0.106 / 10.1.42+
HIGH 7.5
CVE-2025-48989
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache …
Tomcat
9.0.108 / 10.1.44+
CRITICAL 9.8
CVE-2025-53606
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): 2.4.0.
Users are recomm…
Seata
Mitigation only
CRITICAL 9.8
CVE-2025-48913
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…
Cxf
3.6.8 / 4.0.9+
MEDIUM 5.3
CVE-2024-51775
Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin.
The attacker could access the Zeppelin server from another origin without …
Zeppelin
0.12.0+
MEDIUM 6.1
CVE-2024-41177
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin.
This issue affects Apache Zeppelin: before 0.12.0.
Users are recomme…
Zeppelin
0.12.0+
MEDIUM 5.3
CVE-2024-52279
Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input.
…
Zeppelin
0.12.0+
MEDIUM 6.1
CVE-2025-24854
A carefully crafted request using the Image plugin could trigger an XSS
vulnerability on Apache JSPWiki, which could allow the attacker to
execute …
Jspwiki
2.12.3+