Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-45505
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating).
This vulnerabili…
Hertzbeat
1.6.1+
HIGH 7.5
CVE-2024-45791
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat: before 1.6.1.
Us…
Hertzbeat
1.6.1+
HIGH 7.5
CVE-2024-45784
Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability al…
Airflow
2.10.3+
CRITICAL 9.1
CVE-2024-50306
Unchecked return value can allow Apache Traffic Server to retain privileges on startup.
This issue affects Apache Traffic Server: from 9.2.0 through…
Traffic Server
9.2.6 / 10.0.2+
HIGH 7.5
CVE-2024-50305
Valid Host header field can cause Apache Traffic Server to crash on some platforms.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2…
Traffic Server
9.2.6+
HIGH 7.5
CVE-2024-38479
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…
Traffic Server
9.2.6+
CRITICAL 9.9
CVE-2024-50386
Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan…
Cloudstack
4.18.2.5 / 4.19.1.3+
CRITICAL 9.1
CVE-2024-51504
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP bas…
Zookeeper
3.9.3+
HIGH 7.5
CVE-2024-38286
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0…
Tomcat
9.0.90 / 10.1.25+
CRITICAL 9.1
CVE-2024-23590
Session Fixation vulnerability in Apache Kylin.
This issue affects Apache Kylin: from 2.0.0 through 4.x.
Users are recommended to upgrade to versio…
Kylin
5.0.0+
HIGH 8.1
CVE-2024-43383
Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator.
This issue affects Apache Lucene.NET's Replicator library: from 4.8…
Lucene.net
Mitigation only
MEDIUM 6.1
CVE-2024-45031
When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored X…
Syncope
3.0.9+
HIGH 8.8
CVE-2024-45693
Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of t…
Cloudstack
4.18.2.4 / 4.19.1.2+
CRITICAL 9.8
CVE-2024-45216EPSS 91%
Improper Authentication vulnerability in Apache Solr.
Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…
Solr
8.11.4 / 9.7.0+
HIGH 8.5
CVE-2024-45219
Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as …
Cloudstack
4.18.2.4 / 4.19.1.2+
HIGH 8.1
CVE-2024-45217
Insecure Default Initialization of Resource vulnerability in Apache Solr.
New ConfigSets that are created via a Restore command, which copy a config…
Solr
8.11.4 / 9.7.0+
HIGH 7.1
CVE-2024-45462
The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of th…
Cloudstack
4.18.2.4 / 4.19.1.2+
MEDIUM 6.3
CVE-2024-45461
The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. …
Cloudstack
4.18.2.4 / 4.19.1.2+
HIGH 8.8
CVE-2023-50780EPSS 17%
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia…
Artemis
2.29.0+
HIGH 7.8
CVE-2024-45720
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead…
Subversion
1.14.4+
HIGH 7.5
CVE-2024-28168
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP.
This issue affects Apache XML Graphics FOP: …
Formatting Objects Processor
Mitigation only
HIGH 7.3
CVE-2024-47561
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgr…
Avro
1.11.4+
HIGH 8.0
CVE-2024-45772
Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.
This issue affects Apache Lucene's replicator module: from 4.4.0 before…
Lucene Replicator
9.12.0+
HIGH 7.5
CVE-2024-47197
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin.
This …
Maven Archetype
Mitigation only
MEDIUM 6.2
CVE-2024-23454
Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the oth…
Hadoop
3.4.0+
MEDIUM 5.3
CVE-2024-40761
Inadequate Encryption Strength vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
Using the MD5 value of a user's ema…
Answer
after 1.3.5
HIGH 7.5
CVE-2024-39928
In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses t…
Linkis
1.6.0+
MEDIUM 5.9
CVE-2024-46544
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configu…
Tomcat Connectors
1.2.50+
HIGH 8.8
CVE-2024-42323EPSS 8%
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).
This vulnerability can only be exploited by authorized attac…
Hertzbeat
1.6.0+
MEDIUM 6.5
CVE-2024-45537
Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se…
Druid
30.0.1+