Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-38474
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by th…
HTTP Server
2.4.60+
CRITICAL 9.8
CVE-2024-38476EPSS 42%
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend a…
HTTP Server
2.4.60+
CRITICAL 9.1
CVE-2024-38475 KEVEPSS 100%
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p…
HTTP Server
2.4.60 / 10.2.1.14-75sv+
HIGH 8.1
CVE-2024-38473EPSS 26%
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, po…
HTTP Server
2.4.60+
HIGH 7.5
CVE-2024-38472EPSS 69%
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content
Users …
HTTP Server
2.4.60+
MEDIUM 5.4
CVE-2024-36387
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, de…
HTTP Server
after 2.4.59
CRITICAL 9.1
CVE-2024-29868EPSS 6%
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery …
Streampipes
after 0.93.0
MEDIUM 6.1
CVE-2024-27136EPSS 59%
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive infor…
Jspwiki
2.12.2+
MEDIUM 5.3
CVE-2024-34693
Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile ena…
Superset
3.1.3 / 4.0.1+
MEDIUM 5.5
CVE-2024-25142
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.
Airflow did not return "Cache-Control" header for dynami…
Airflow
2.9.2+
CRITICAL 9.8
CVE-2024-36265
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.
This issue affects Apache Submarine Server Co…
Submarine
Mitigation only
CRITICAL 9.8
CVE-2024-36264
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.
If the user doesn't explicitly set `submari…
Submarine
Patch available
HIGH 8.1
CVE-2024-36263
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarin…
Submarine
Patch available
HIGH 7.5
CVE-2024-36471
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imp…
Allura
1.17.0+
CRITICAL 9.1
CVE-2024-36104EPSS 87%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…
Ofbiz
18.12.14+
MEDIUM 5.4
CVE-2024-32077
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.
Users a…
Airflow
Patch available
CRITICAL 9.1
CVE-2024-34365
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave.
A…
Karaf Cave
Mitigation only
CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …
Ofbiz
18.12.13+
CRITICAL 9.8
CVE-2024-26579
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,
the attackers can by…
Inlong
1.12.0+
MEDIUM 6.6
CVE-2023-35701
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive.
The vulnerability affects the Hive JDBC driver component and…
Hive
Mitigation only
MEDIUM 6.3
CVE-2024-32638
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue af…
Apisix
Mitigation only
HIGH 8.8
CVE-2024-32114EPSS 7%
In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are loc…
Activemq
6.1.2+
CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …
Hugegraph
1.3.0+
CRITICAL 9.1
CVE-2024-27349
Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0.
User…
Hugegraph
1.3.0+
MEDIUM 5.3
CVE-2024-27347
Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0.
Use…
Hugegraph Hubble
1.3.0+
MEDIUM 6.5
CVE-2024-31391
Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator.
This issue affects all versions of the Apache Solr Opera…
Solr Operator
0.8.1+
HIGH 7.4
CVE-2024-27309
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.
Two preconditi…
Kafka
after 3.6.1
HIGH 7.5
CVE-2024-31309EPSS 95%
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0…
Traffic Server
8.1.10 / 9.2.4+
MEDIUM 6.5
CVE-2024-31867
Improper Input Validation vulnerability in Apache Zeppelin.
The attackers can execute malicious queries by setting improper configuration properties…
Zeppelin
0.11.1+
CRITICAL 9.8
CVE-2024-31864
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.
The attacker can inject sensitive configuration or malic…
Zeppelin
0.11.1+