Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-31866
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.
The attackers can execute shell scripts or malicious code by overriding co…
Zeppelin
0.11.1+
MEDIUM 6.5
CVE-2024-31865
Improper Input Validation vulnerability in Apache Zeppelin.
The attackers can call updating cron API with invalid or improper privileges so that the…
Zeppelin
0.11.1+
MEDIUM 6.1
CVE-2024-31868
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.
The attackers can modify helium.json and exposure XSS attacks to normal us…
Zeppelin
0.11.1+
MEDIUM 5.3
CVE-2024-31863
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 bef…
Zeppelin
Mitigation only
MEDIUM 5.3
CVE-2022-47894
Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0.
As this project is …
Zeppelin
0.11.0+
MEDIUM 5.3
CVE-2024-31862
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.…
Zeppelin
0.11.0+
MEDIUM 5.4
CVE-2021-28656
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue aff…
Zeppelin
after 0.9.0
MEDIUM 6.5
CVE-2024-31860
Improper Input Validation vulnerability in Apache Zeppelin.
By adding relative path indicators(E.g ..), attackers can see the contents for any files…
Zeppelin
0.11.0+
HIGH 7.5
CVE-2024-24746
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.
Specially crafted GATT operation can cause infinite loop in …
Nimble
1.7.0+
HIGH 7.5
CVE-2024-27316EPSS 91%
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do…
HTTP Server
2.4.59+
HIGH 7.3
CVE-2023-38709
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects…
HTTP Server
2.4.59 / 14.6+
MEDIUM 6.3
CVE-2024-24795
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applicat…
HTTP Server
2.4.59 / 14.6+
MEDIUM 6.4
CVE-2024-29008
A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to…
Cloudstack
4.18.1.1+
CRITICAL 9.8
CVE-2024-29006
By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead t…
Cloudstack
4.18.1.1+
HIGH 7.3
CVE-2024-29007
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of followi…
Cloudstack
4.18.1.1+
MEDIUM 6.4
CVE-2024-29834
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u…
Pulsar
3.0.4 / 3.2.2+
CRITICAL 9.8
CVE-2024-23538
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…
Fineract
1.9.0+
CRITICAL 9.8
CVE-2024-23539
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…
Fineract
1.9.0+
HIGH 8.8
CVE-2024-23537
Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.
Users are recommended to upgrade to versi…
Fineract
1.9.0+
MEDIUM 5.3
CVE-2024-29735
Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3.
Airflow's local fil…
Airflow
after 2.8.4
CRITICAL 9.8
CVE-2024-27438
Download of Code Without Integrity Check vulnerability in Apache Doris.
The jdbc driver files used for JDBC catalog is not checked and may resulting …
Doris
2.0.5+
MEDIUM 5.3
CVE-2024-26307
Possible race condition vulnerability in Apache Doris.
Some of code using `chmod()` method. This method run the risk of someone renaming the file out…
Doris
1.2.8 / 2.0.4+
HIGH 7.3
CVE-2024-29131
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are…
Commons Configuration
2.10.1+
MEDIUM 5.4
CVE-2024-29133
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are…
Commons Configuration
2.10.1+
MEDIUM 6.5
CVE-2024-27439
An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.
This issue affects Apache Wick…
Wicket
9.17.0+
MEDIUM 6.5
CVE-2024-24683
Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0.
Users are recommended to upgrade to…
Hop Engine
2.8.0+
CRITICAL 9.3
CVE-2024-28752
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att…
Cxf
3.5.8 / 3.6.3+
MEDIUM 5.3
CVE-2024-23944
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by…
Zookeeper
3.8.4 / 3.9.2+
HIGH 8.1
CVE-2024-28746
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such…
Airflow
2.8.3+
HIGH 7.5
CVE-2024-24549EPSS 23%
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the requ…
Tomcat
8.5.99 / 9.0.86+