Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-45384
Padding Oracle vulnerability in Apache Druid extension, druid-pac4j.
This could allow an attacker to manipulate a pac4j session cookie.
This issue a…
Druid
30.0.1+
CRITICAL 9.8
CVE-2024-22399
Deserialization of Untrusted Data vulnerability in Apache Seata.
When developers disable authentication on the Seata-Server and do not use the Seat…
Seata
1.8.1+
HIGH 8.8
CVE-2024-45034
Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the…
Airflow
2.10.1+
HIGH 8.8
CVE-2024-45498
Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with o…
Airflow
Patch available
CRITICAL 9.8
CVE-2024-45507EPSS 93%
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.16+
HIGH 7.5
CVE-2024-45195 KEVEPSS 100%
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrad…
Ofbiz
18.12.16+
MEDIUM 5.5
CVE-2023-49582
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pot…
Portable Runtime
1.7.5+
MEDIUM 6.1
CVE-2024-41937
Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting atta…
Airflow
2.10.0+
HIGH 7.5
CVE-2023-49198
Mysql security vulnerability in Apache SeaTunnel.
Attackers can read files on the MySQL server by modifying the information in the MySQL URL
allow…
Seatunnel
Mitigation only
HIGH 7.5
CVE-2024-22281
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by genera…
Helix
Mitigation only
CRITICAL 9.8
CVE-2024-42361
Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin…
Hertzbeat
1.6.0+
HIGH 8.8
CVE-2024-42362
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/…
Hertzbeat
1.6.0+
CRITICAL 9.8
CVE-2024-43202
Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
We recommend users to upgr…
Dolphinscheduler
3.2.2+
MEDIUM 5.9
CVE-2024-41909
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can inter…
Mina Sshd
after 2.11.0
MEDIUM 5.3
CVE-2024-41888
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
The password …
Answer
1.3.6+
MEDIUM 5.3
CVE-2024-41890
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.3.5.
User sends mu…
Answer
1.3.6+
HIGH 8.1
CVE-2024-30188EPSS 6%
File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files.
This issue affect…
Dolphinscheduler
3.2.2+
HIGH 8.8
CVE-2024-29831
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …
Dolphinscheduler
3.2.2+
HIGH 7.2
CVE-2024-42062
CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register ran…
Cloudstack
4.18.2.3 / 4.19.1.1+
HIGH 7.3
CVE-2024-36448
** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench.
This issue affects Apache IoTDB Workbenc…
Iotdb Workbench
Mitigation only
CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to versi…
Ofbiz
18.12.15+
CRITICAL 9.8
CVE-2024-42447
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.
This issue affects Apache Airflow Providers FAB: 1.2.1 (when used wit…
Apache Airflow Providers Fab
Patch available
CRITICAL 9.8
CVE-2024-36268
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.10.0 through 1.12…
Inlong
1.13.0+
HIGH 8.8
CVE-2024-27181
In Apache Linkis <= 1.5.0,
Privilege Escalation in Basic management services where the attacking user is
a trusted account
allows access to Link…
Linkis
1.6.0+
CRITICAL 9.1
CVE-2023-48396
Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge
any token to log in an…
Seatunnel
Mitigation only
HIGH 8.2
CVE-2024-35296
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests.
This issue affects Apache Traffic…
Traffic Server
8.1.11 / 9.2.5+
HIGH 7.5
CVE-2024-35161
Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead…
Traffic Server
8.1.11 / 9.2.5+
HIGH 7.5
CVE-2023-38522
Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be uti…
Traffic Server
8.1.11 / 9.2.5+
MEDIUM 5.4
CVE-2024-25090
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …
Roller
6.1.3+
HIGH 8.8
CVE-2023-48362
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi…
Drill
1.21.2+