Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2024-45033
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider.
This issue affects Apache Airflow Fab Provider: before 1.5.2.
When us…
Apache Airflow Providers Fab
1.5.2+
MEDIUM 5.4
CVE-2024-56512
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenc…
Nifi
2.1.0+
CRITICAL 9.8
CVE-2024-52046EPSS 24%
The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process
incoming serialized data but lacks the necessary…
Mina
2.0.27 / 2.1.10+
CRITICAL 9.8
CVE-2024-43441EPSS 69%
Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server.
This issue affects Apache HugeGraph-Server: from 1.0.0 bef…
Hugegraph
1.5.0+
HIGH 8.8
CVE-2024-45387EPSS 42%
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …
Traffic Control
8.0.2+
MEDIUM 5.9
CVE-2024-23945
Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signatu…
Hive
3.3.4 / 3.4.2+
CRITICAL 9.8
CVE-2024-56337EPSS 9%
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, f…
Tomcat
9.0.98 / 10.1.34+
MEDIUM 5.3
CVE-2024-56128
Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation.
Issue Summary:
Apache Kafka's implementation of the Sal…
Kafka
3.7.2+
CRITICAL 9.8
CVE-2024-50379EPSS 44%
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file syste…
Tomcat
9.0.98 / 10.1.34+
MEDIUM 5.3
CVE-2024-54677
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue a…
Tomcat
9.0.98 / 10.1.34+
MEDIUM 6.5
CVE-2024-55633
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed…
Superset
4.1.0+
CRITICAL 9.8
CVE-2024-53677EPSS 78%
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th…
Struts
6.4.0+
CRITICAL 9.8
CVE-2024-53947
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-s…
Superset
4.1.0+
MEDIUM 6.5
CVE-2024-53949
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users …
Superset
4.1.0+
MEDIUM 5.3
CVE-2024-53948
Generation of Error Message Containing analytics metadata Information in Apache Superset.
This issue affects Apache Superset: before 4.1.0.
Users a…
Superset
4.1.0+
HIGH 8.3
CVE-2022-41137
Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is un…
Hive
Patch available
HIGH 8.1
CVE-2024-45106
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…
Ozone
Mitigation only
CRITICAL 9.8
CVE-2024-52338
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut…
Arrow
17.0.0+
HIGH 7.5
CVE-2024-51569
Out-of-bounds Read vulnerability in Apache NimBLE.
Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access wh…
Nimble
1.8.0+
MEDIUM 6.3
CVE-2024-47248
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
Specially crafted MESH message could result i…
Nimble
1.8.0+
MEDIUM 5.0
CVE-2024-47249
Improper Validation of Array Index vulnerability in Apache NimBLE.
Lack of input validation for HCI events from controller could result in out-of-bo…
Nimble
1.8.0+
MEDIUM 5.0
CVE-2024-47250
Out-of-bounds Read vulnerability in Apache NimBLE.
Missing proper validation of HCI advertising report could lead to out-of-bound access when parsin…
Nimble
1.8.0+
MEDIUM 6.5
CVE-2018-9481
In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information d…
Traffic Server
7.1.10 / 8.0.7+
MEDIUM 6.5
CVE-2024-31141
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients.
Apache Kafka Clients accep…
Kafka
after 3.6.2
MEDIUM 6.1
CVE-2024-52318
Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommend…
Tomcat
Mitigation only
CRITICAL 9.8
CVE-2024-52316EPSS 6%
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuth…
Tomcat
9.0.96 / 10.1.31+
MEDIUM 6.5
CVE-2024-52317
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests
could…
Tomcat
9.0.96 / 10.1.31+
CRITICAL 9.8
CVE-2024-47208
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.17+
HIGH 8.8
CVE-2024-48962
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…
Ofbiz
18.12.17+
HIGH 8.8
CVE-2024-41151
Deserialization of Untrusted Data vulnerability in Apache HertzBeat.
This vulnerability can only be exploited by authorized attackers.
This issue …
Hertzbeat
1.6.1+