Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-51653
Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec…
Hertzbeat
1.4.1+
CRITICAL 9.1
CVE-2024-22393
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1.
Pixel Flood Attack b…
Answer
1.2.5+
MEDIUM 5.9
CVE-2024-26578
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache …
Answer
after 1.2.1
MEDIUM 5.4
CVE-2024-23349
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer:…
Answer
after 1.2.1
CRITICAL 9.1
CVE-2024-25141
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte…
Apache Airflow Providers Mongo
4.0.0+
CRITICAL 9.8
CVE-2024-23114
Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa…
Camel
3.21.4 / 4.0.4+
HIGH 7.8
CVE-2024-22369
Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 b…
Camel
3.21.4 / 4.0.4+
HIGH 7.5
CVE-2023-51770
Arbitrary File Read Vulnerability in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.1.
We recommend users to upgr…
Dolphinscheduler
3.2.1+
HIGH 7.3
CVE-2023-49250
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connectio…
Dolphinscheduler
3.2.1+
MEDIUM 6.5
CVE-2023-50270
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Users are recommended to upgr…
Dolphinscheduler
3.2.1+
CRITICAL 9.8
CVE-2023-49109
Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.1.
We recommend users to upgr…
Dolphinscheduler
3.2.1+
MEDIUM 5.5
CVE-2024-26308
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 b…
Commons Compress
1.26.0+
MEDIUM 5.5
CVE-2024-25710
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 …
Commons Compress
1.26.0+
MEDIUM 6.5
CVE-2024-23952
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset.
Uncontrolled resource consumption can be trig…
Superset
2.1.3 / 3.0.2+
HIGH 8.8
CVE-2023-50386EPSS 84%
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co…
Solr
8.11.3 / 9.4.1+
HIGH 7.5
CVE-2023-50291
Insufficiently Protected Credentials vulnerability in Apache Solr.
This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.…
Solr
8.11.3 / 9.3.0+
HIGH 7.5
CVE-2023-50292
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This iss…
Solr
8.11.3 / 9.4.1+
HIGH 7.5
CVE-2023-50298
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, fr…
Solr
8.11.3 / 9.4.1+
HIGH 7.5
CVE-2024-23452
Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request.
Vulnerability Cause D…
Brpc
1.8.0+
MEDIUM 5.3
CVE-2023-39196
Improper Authentication vulnerability in Apache Ozone.
The vulnerability allows an attacker to download metadata internal to the Storage Container M…
Ozone
after 1.3.0
HIGH 7.4
CVE-2023-51437
Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will …
Pulsar
2.11.3 / 3.0.2+
HIGH 7.5
CVE-2024-23673
Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sli…
Sling Servlets Resolver
2.11.0+
HIGH 7.5
CVE-2023-44312
Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects
Apache ServiceComb Service-Cente…
Servicecomb
2.2.0+
HIGH 7.5
CVE-2023-44313
Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through spec…
Servicecomb
2.2.0+
HIGH 7.5
CVE-2023-29055
In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain…
Kylin
4.0.4+
MEDIUM 6.5
CVE-2023-50944
Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …
Airflow
2.8.1+
MEDIUM 6.5
CVE-2023-51702
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes th…
Airflow
2.6.1 / 7.0.0+
HIGH 7.5
CVE-2023-50943
Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "…
Airflow
2.8.1+
MEDIUM 5.4
CVE-2023-49657
A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on…
Superset
3.0.3+
MEDIUM 5.3
CVE-2024-21733EPSS 14%
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.…
Tomcat
8.5.64 / 9.0.44+