Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-27820
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered b…
Httpclient
5.4.3+
HIGH 7.5
CVE-2025-26413
Improper Input Validation vulnerability in Apache Kvrocks.
The SETRANGE command didn't check if the `offset` input is a positive integer and use it …
Kvrocks
2.12.0+
CRITICAL 9.8
CVE-2025-29953
Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.
This issue affects Apache ActiveMQ NMS OpenWire Client befor…
Activemq Nms Openwire
2.1.1+
MEDIUM 6.5
CVE-2024-56736
Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat (incubating): before 1.7.0.
Users are rec…
Hertzbeat
1.7.0+
HIGH 8.8
CVE-2025-24859
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after passwor…
Roller
6.1.5+
MEDIUM 6.5
CVE-2025-27391
Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when th…
Artemis
2.40.0+
MEDIUM 6.5
CVE-2025-30677
Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka …
Pulsar
3.0.11 / 3.3.6+
MEDIUM 5.3
CVE-2025-31672
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file forma…
Poi
5.4.0+
HIGH 8.8
CVE-2025-30473
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider.
When using…
Airflow Common Sql Provider
1.24.1+
HIGH 7.5
CVE-2024-53868
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 9.2.0 through …
Traffic Server
9.2.10 / 10.0.5+
MEDIUM 6.1
CVE-2025-30676EPSS 65%
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before…
Ofbiz
18.12.19+
MEDIUM 6.5
CVE-2025-30177
Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions.
This issue affects Apache Camel: from 4.10.0…
Camel
4.8.6 / 4.10.3+
CRITICAL 9.8
CVE-2024-56325EPSS 79%
Authentication Bypass Issue
If the path does not contain / and contain., authentication is not required.
Expected Normal Request and Response Examp…
Pinot
1.3.0+
CRITICAL 9.8
CVE-2025-30065EPSS 41%
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code
Users are reco…
Parquet Java
1.15.1+
MEDIUM 6.5
CVE-2025-29868
Private Data Structure Returned From A Public Method vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.4.2.
If a user use…
Answer
after 1.4.2
HIGH 7.2
CVE-2025-30067
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin.
If an attacker gets access to Kylin's system or project adm…
Kylin
5.0.2+
MEDIUM 6.5
CVE-2024-48944
Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d…
Kylin
5.0.2+
MEDIUM 5.4
CVE-2024-53679
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with…
Vcl
2.5.2+
HIGH 8.8
CVE-2024-53678
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitte…
Vcl
2.5.2+
MEDIUM 5.0
CVE-2025-30474
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS.
The FtpFileObject class can throw an exception when …
Commons Vfs
2.10.0+
HIGH 7.5
CVE-2025-27553
Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0.
The FileObject API in Commons VFS has a 'resolveFile' method that
takes a…
Commons Vfs
2.10.0+
MEDIUM 5.4
CVE-2025-26796
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie.
…
Oozie
Mitigation only
MEDIUM 5.4
CVE-2025-27888
Severity: medium (5.8) / important
Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
Druid
31.0.2+
CRITICAL 9.8
CVE-2024-47552
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): from 2.0.0 before 2.…
Seata
2.2.0+
MEDIUM 6.3
CVE-2025-27018
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
When user trigg…
Apache Airflow Providers Mysql
6.2.0+
MEDIUM 6.5
CVE-2025-27017
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB comp…
Nifi
2.3.0+
MEDIUM 5.6
CVE-2025-27867
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin.
This issu…
Felix Http Webconsole Plugin
1.2.2+
CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…
Tomcat
9.0.99 / 10.1.35+
MEDIUM 5.6
CVE-2025-27636EPSS 81%
Bypass/Injection vulnerability in Apache Camel components under particular conditions.
This issue affects Apache Camel: from 4.10.0 through <= 4.10.…
Camel
3.22.4 / 4.8.5+
MEDIUM 6.3
CVE-2024-56195
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 thro…
Traffic Server
9.2.9 / 10.0.4+