Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-48988EPSS 57%
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7…
Tomcat
9.0.106 / 10.1.42+
HIGH 7.5
CVE-2025-49125
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than…
Tomcat
9.0.106 / 10.1.42+
CRITICAL 9.8
CVE-2025-47868
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that…
Nuttx
12.9.0+
CRITICAL 9.8
CVE-2025-47869
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc applic…
Nuttx
12.9.0+
HIGH 8.8
CVE-2025-47713
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…
Cloudstack
4.19.3.0 / 4.20.1.0+
HIGH 8.8
CVE-2025-47849
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…
Cloudstack
4.19.3.0 / 4.20.1.0+
HIGH 8.1
CVE-2025-26521
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of…
Cloudstack
4.19.3.0 / 4.20.1.0+
HIGH 8.8
CVE-2025-27818
A possible security vulnerability has been identified in Apache Kafka.
This requires access to a alterConfig to the cluster resource, or Kafka Connec…
Kafka
3.9.1+
HIGH 7.5
CVE-2025-27817EPSS 65%
A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for …
Kafka
3.9.1+
HIGH 7.5
CVE-2025-27819
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…
Kafka
after 3.3.2
CRITICAL 9.8
CVE-2025-27531
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 before 2.1.0,
this issue would al…
Inlong
2.1.0+
MEDIUM 6.5
CVE-2025-46548
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied.
Users that rely on authen…
Pekko Management
1.6.1+
MEDIUM 6.5
CVE-2025-48912
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression'…
Superset
4.1.2+
HIGH 7.3
CVE-2025-46701
Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that app…
Tomcat
9.0.105 / 10.1.41+
HIGH 8.8
CVE-2025-48734
Improper Access Control vulnerability in Apache Commons.
A special BeanIntrospector class was added in version 1.9.2. This can be used to stop att…
Commons Beanutils
1.11.0+
CRITICAL 9.1
CVE-2025-27528
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability …
Inlong
2.2.0+
MEDIUM 6.5
CVE-2025-27522
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is…
Inlong
2.2.0+
MEDIUM 6.5
CVE-2025-27526
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability wh…
Inlong
2.2.0+
CRITICAL 9.8
CVE-2025-35003
Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache Nut…
Nuttx
12.9.0+
CRITICAL 9.8
CVE-2025-47436
Heap-based Buffer Overflow vulnerability in Apache ORC.
A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially …
Orc
1.8.9 / 1.9.6+
HIGH 7.5
CVE-2025-26864
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of…
Iotdb
1.3.4+
HIGH 7.5
CVE-2025-26795
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive…
Iotdb
1.3.4 / 2.0.2+
CRITICAL 9.8
CVE-2024-24780
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…
Iotdb
1.3.4+
HIGH 8.8
CVE-2025-27696
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read…
Superset
4.1.2+
MEDIUM 6.5
CVE-2025-46392
Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.
There are a number of issues in Apache Commons Configuration 1.…
Commons Configuration
2.0+
HIGH 7.5
CVE-2025-27533EPSS 9%
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.
During unmarshalling of OpenWire commands the size value of buffers wa…
Activemq
5.16.8 / 5.17.7+
HIGH 8.1
CVE-2025-46762
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code.
While 1.15.1 i…
Parquet
1.15.2+
HIGH 7.5
CVE-2025-3891
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service …
HTTP Server
Patch available
CRITICAL 9.8
CVE-2025-31651
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, i…
Tomcat
9.0.104 / 10.1.40+
HIGH 7.5
CVE-2025-31650EPSS 60%
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clea…
Tomcat
9.0.104 / 10.1.40+