Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-46226
Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2.
Users are recommended to upgrade to v…
Iotdb
1.3.0+
MEDIUM 6.5
CVE-2023-46749
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe…
Shiro
1.13.0+
MEDIUM 6.5
CVE-2023-50290EPSS 68%
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.
The Solr Metrics API publishes all unprotected environment v…
Solr
9.3.0+
HIGH 7.2
CVE-2023-51441
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform poss…
Axis
after 1.3
CRITICAL 9.8
CVE-2023-51784
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, …
Inlong
1.10.0+
HIGH 7.5
CVE-2023-51785
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a…
Inlong
after 1.9.0
HIGH 8.8
CVE-2023-49299
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …
Dolphinscheduler
3.1.9+
HIGH 8.8
CVE-2023-47804
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose.
…
Openoffice
4.1.15+
CRITICAL 9.8
CVE-2023-51467EPSS 96%
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
Ofbiz
18.12.11+
HIGH 7.5
CVE-2023-50968EPSS 63%
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.
Th…
Ofbiz
18.12.11+
HIGH 7.5
CVE-2023-51650
Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized acc…
Hertzbeat
1.4.1+
HIGH 8.8
CVE-2023-51387
Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo…
Hertzbeat
1.4.1+
HIGH 7.5
CVE-2022-39337
Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v…
Hertzbeat
1.2.1+
CRITICAL 9.8
CVE-2023-51656
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.
Users are recommended t…
Iotdb
after 0.13.4
MEDIUM 6.5
CVE-2023-49920
Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. A…
Airflow
after 2.7.3
MEDIUM 6.5
CVE-2023-50783
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to upda…
Airflow
2.8.0+
MEDIUM 5.4
CVE-2023-47265
Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript…
Airflow
after 2.7.3
HIGH 7.5
CVE-2023-37544
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication…
Pulsar
2.10.5 / 2.11.2+
HIGH 8.8
CVE-2023-43826
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user con…
Guacamole
after 1.5.3
HIGH 8.8
CVE-2023-49736
A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup…
Superset
2.1.2 / 3.0.2+
MEDIUM 6.5
CVE-2023-49734
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the…
Superset
2.1.2 / 3.0.2+
MEDIUM 6.5
CVE-2023-46104
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.…
Superset
2.1.3 / 3.0.1+
HIGH 8.2
CVE-2023-41314
The api /api/snapshot and /api/get_log_file would allow unauthenticated access.
It could allow a DoS attack or get arbitrary files from FE node.
Plea…
Doris
2.0.3+
HIGH 7.2
CVE-2023-49898
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of …
Streampark
2.1.2+
CRITICAL 9.8
CVE-2023-29234EPSS 7%
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…
Dubbo
after 3.2.4
CRITICAL 9.8
CVE-2023-46279
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5.
Users are recommended to upgrade to the …
Dubbo
Mitigation only
MEDIUM 6.1
CVE-2023-46750
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.
Mitigation: Update to Apache Sh…
Shiro
1.13.0+
MEDIUM 5.7
CVE-2023-45725
Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the do…
Couchdb
after 3.3.2
CRITICAL 9.8
CVE-2023-50164EPSS 81%
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file whic…
Struts
2.5.33 / 6.3.0.2+
HIGH 7.5
CVE-2023-41835EPSS 6%
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.save…
Struts
2.5.32 / 6.3.0.1+