Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.3
CVE-2024-56196
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3.
Users are rec…
Traffic Server
10.0.4+
MEDIUM 6.3
CVE-2024-38311
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…
Traffic Server
9.2.9 / 10.0.4+
CRITICAL 9.8
CVE-2024-55532
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0.
Users are recommended to upgrade…
Ranger
2.6.0+
MEDIUM 6.5
CVE-2024-24778
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know.
This i…
Streampipes
0.97.0+
CRITICAL 9.8
CVE-2024-56180
CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo…
Eventmesh
1.11.0+
CRITICAL 9.0
CVE-2024-52577
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili…
Ignite
2.17.0+
HIGH 7.1
CVE-2024-46910
An authenticated user can perform XSS and potentially impersonate another user.
This issue affects Apache Atlas versions 2.3.0 and earlier.
Users a…
Atlas
2.4.0+
HIGH 8.8
CVE-2024-32838
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that al…
Fineract
1.10.1+
MEDIUM 6.1
CVE-2025-25247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.
This issue affects Ap…
Felix Webconsole
4.9.10 / 5.0.10+
MEDIUM 6.5
CVE-2025-25069
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks.
Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests,
a va…
Kvrocks
2.11.1+
HIGH 8.5
CVE-2022-31764
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue af…
Shardingsphere Elasticjob Ui
3.0.2+
HIGH 7.5
CVE-2024-45626
Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu…
James Server
3.7.6 / 3.8.2+
HIGH 7.5
CVE-2024-37358
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthent…
James Server
3.7.6 / 3.8.2+
MEDIUM 5.4
CVE-2024-48019
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …
Doris
2.1.8 / 3.0.3+
MEDIUM 5.4
CVE-2025-24860
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi…
Cassandra
4.0.16 / 4.1.8+
MEDIUM 5.3
CVE-2024-27137
In Apache Cassandra it is possible for a local attacker without access
to the Apache Cassandra process or configuration files to manipulate
the RMI…
Cassandra
4.0.15 / 4.1.8+
HIGH 8.8
CVE-2025-23015
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to s…
Cassandra
3.0.31 / 3.11.18+
MEDIUM 5.5
CVE-2024-29869
Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set exp…
Hive
4.0.1+
MEDIUM 6.5
CVE-2024-23953
Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary mes…
Hive
4.0.0+
HIGH 7.5
CVE-2025-24783
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon.
This issue affects…
Cocoon
Mitigation only
MEDIUM 5.5
CVE-2025-24814
Core creation allows users to replace "trusted" configset files with arbitrary configuration
Solr instances that (1) use the "FileSystemConfigSetSer…
Solr
9.8.0+
MEDIUM 5.4
CVE-2024-52012EPSS 47%
Relative Path Traversal vulnerability in Apache Solr.
Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a …
Solr
9.8.0+
MEDIUM 6.5
CVE-2024-53299
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.…
Wicket
9.19.0 / 10.3.0+
CRITICAL 9.1
CVE-2024-45479
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger…
Ranger
2.5.0+
HIGH 8.8
CVE-2024-51941
A remote code injection vulnerability exists in the Ambari Metrics and
AMS Alerts feature, allowing authenticated users to inject and execute
arbit…
Ambari
after 2.7.8
HIGH 8.8
CVE-2025-23196
A code injection vulnerability exists in the Ambari Alert Definition
feature, allowing authenticated users to inject and execute arbitrary
shell co…
Ambari
2.7.9+
HIGH 7.5
CVE-2025-23195
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie
project, allowing an attacker to inject malicious XML entities. This
vulnerab…
Ambari
2.7.9+
HIGH 7.5
CVE-2025-23184
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutput…
Cxf
3.5.10 / 3.6.5+
MEDIUM 5.9
CVE-2024-45627
In Apache Linkis <1.7.0, due to the lack of effective filtering
of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSou…
Linkis
1.7.0+
CRITICAL 9.8
CVE-2024-54676EPSS 65%
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions …
Openmeetings
8.0.0+