Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-39676
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot.
This issue affects Apache Pinot: from 0.1 before 1.0.0.
U…
Pinot
1.0.0+
HIGH 7.5
CVE-2024-41178
Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using…
Arrow
after 0.10.1
CRITICAL 9.1
CVE-2024-29070
On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …
Streampark
2.1.4+
MEDIUM 5.4
CVE-2024-38503
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits.
The…
Syncope
3.0.8+
MEDIUM 6.5
CVE-2024-34457
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'…
Streampark
2.1.4+
HIGH 8.8
CVE-2024-23321
For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i…
Rocketmq
5.3.0+
HIGH 8.1
CVE-2024-41107EPSS 18%
The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is en…
Cloudstack
4.18.2.2 / 4.19.1.0+
HIGH 7.5
CVE-2024-41172
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instan…
Cxf
3.6.4 / 4.0.5+
CRITICAL 9.1
CVE-2024-29736
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…
Cxf
3.5.9 / 3.6.4+
HIGH 7.5
CVE-2024-32007
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of…
Cxf
3.5.9 / 3.6.4+
HIGH 8.8
CVE-2024-29178
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …
Streampark
2.1.4+
HIGH 7.5
CVE-2024-40898
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF…
HTTP Server
2.4.62+
MEDIUM 5.3
CVE-2024-40725
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handler…
HTTP Server
Mitigation only
MEDIUM 5.9
CVE-2024-29120
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication…
Streampark
2.1.4+
HIGH 8.8
CVE-2024-31411
Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes.
Such a dangerous type might be an executable file that may lead …
Streampipes
0.95.0+
HIGH 8.8
CVE-2024-39877
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that …
Airflow
2.9.3+
MEDIUM 5.4
CVE-2024-39863
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider…
Airflow
2.9.3+
CRITICAL 9.8
CVE-2024-39887
An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…
Superset
4.0.2+
HIGH 8.1
CVE-2023-52290
In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…
Streampark
2.1.4+
HIGH 8.8
CVE-2023-46801
In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version …
Linkis
1.6.0+
HIGH 8.8
CVE-2023-49566
In Apache Linkis <=1.5.0, due to the lack of effective filtering
of parameters, an attacker configuring malicious
db2
parameters in the DataSourc…
Linkis
1.6.0+
MEDIUM 6.5
CVE-2023-41916
In Apache Linkis =1.4.0, due to the lack of effective filtering
of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSou…
Linkis
1.6.0+
CRITICAL 9.8
CVE-2024-36522
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…
Wicket
8.16.0 / 9.18.0+
MEDIUM 5.4
CVE-2024-37389EPSS 24%
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable…
Nifi
1.27.0+
CRITICAL 9.8
CVE-2024-39864
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio…
Cloudstack
4.18.2.1 / 4.19.0.2+
CRITICAL 9.8
CVE-2024-38346
The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …
Cloudstack
4.18.2.1 / 4.19.0.2+
MEDIUM 6.2
CVE-2024-39884
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and si…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2024-34750
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomc…
Tomcat
9.0.90 / 10.1.25+
HIGH 7.5
CVE-2024-38477
null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.
Users …
HTTP Server
2.4.60+
HIGH 7.5
CVE-2024-39573EPSS 35%
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to…
HTTP Server
2.4.60+