Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-24853
A carefully crafted request when creating a header link using the
wiki markup syntax, which could allow the attacker to execute javascript
in the v…
Jspwiki
2.12.3+
MEDIUM 6.5
CVE-2025-54656
** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts.
This issue affects Apache Struts Extras: bef…
Struts Extras
2.0+
MEDIUM 6.3
CVE-2025-54090
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".
Users are recommended to upgrade to version 2…
HTTP Server
Patch available
HIGH 8.8
CVE-2025-50151
File access paths in configuration files uploaded by users with administrator access are not validated.
This issue affects Apache Jena version up to…
Jena
5.5.0+
HIGH 7.5
CVE-2025-49656
Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to…
Jena
5.5.0+
MEDIUM 5.6
CVE-2025-48795
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary …
Cxf
Mitigation only
HIGH 8.8
CVE-2025-53689
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to …
Jackrabbit
2.20.17+
HIGH 7.5
CVE-2024-41169
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files…
Zeppelin
0.12.0+
MEDIUM 5.3
CVE-2025-48924
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to …
Commons Lang
2.6 / 3.18.0+
HIGH 7.5
CVE-2025-53506
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the …
Tomcat
after 11.0.8
HIGH 7.5
CVE-2025-52434
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native …
Tomcat
9.0.107+
HIGH 7.5
CVE-2025-52520
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size li…
Tomcat
9.0.107 / 10.1.43+
HIGH 7.5
CVE-2025-49630
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untruste…
HTTP Server
2.4.64+
HIGH 7.5
CVE-2025-53020
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63…
HTTP Server
2.4.64+
HIGH 7.4
CVE-2025-49812
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker…
HTTP Server
2.4.64+
CRITICAL 9.1
CVE-2025-23048
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 …
HTTP Server
2.4.64+
HIGH 7.5
CVE-2024-43394
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via
mod_rewrite or …
HTTP Server
2.4.64+
HIGH 7.5
CVE-2024-47252
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape c…
HTTP Server
2.4.64+
HIGH 7.5
CVE-2024-42516
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hos…
HTTP Server
2.4.64+
HIGH 7.5
CVE-2024-43204
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an…
HTTP Server
2.4.64+
HIGH 7.8
CVE-2025-27446
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner).
Local listening file permissions in APISIX…
Apisix
after 0.5
MEDIUM 5.3
CVE-2025-46647
A vulnerability of plugin openid-connect in Apache APISIX.
This vulnerability will only have an impact if all of the following conditions are met:
1…
Apisix
3.12.0+
HIGH 7.5
CVE-2024-35164
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols lik…
Guacamole
1.6.0+
CRITICAL 9.8
CVE-2025-32897
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This security vulnerability is the same as CVE-2024-47552, but the ver…
Seata
2.3.0+
CRITICAL 9.8
CVE-2025-50213
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.
This is…
Apache Airflow Providers Snowflake
6.4.0+
MEDIUM 6.5
CVE-2025-32896
# Summary
Unauthorized users can perform Arbitrary File Read and Deserialization
attack by submit job using restful api-v1.
# Details
Unauthorized …
Seatunnel
2.3.11+
HIGH 7.5
CVE-2025-49763
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.
…
Traffic Server
9.2.11 / 10.0.6+
HIGH 7.5
CVE-2025-31698
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol.
Users can use a new setting (proxy.…
Traffic Server
9.2.11 / 10.0.6+
HIGH 8.4
CVE-2025-49124
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe wit…
Tomcat
9.0.106 / 10.1.42+
HIGH 7.5
CVE-2025-48976EPSS 68%
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects …
Commons Fileupload
1.6+