Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-39456EPSS 53%
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th…
Traffic Server
9.2.3+
HIGH 7.5
CVE-2023-41752
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.…
Traffic Server
8.1.9 / 9.2.3+
MEDIUM 6.1
CVE-2023-45757
Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page.
An attacker that can sen…
Brpc
1.6.1+
CRITICAL 9.8
CVE-2023-43668
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,
some se…
Inlong
after 1.8.0
HIGH 7.5
CVE-2023-43667
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects …
Inlong
after 1.8.0
MEDIUM 6.5
CVE-2023-43666
Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,
General u…
Inlong
after 1.8.0
MEDIUM 6.5
CVE-2023-42780
Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, …
Airflow
2.7.2+
MEDIUM 6.5
CVE-2023-42792
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to …
Airflow
2.7.2+
MEDIUM 6.5
CVE-2023-42663
Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat…
Airflow
2.7.2+
CRITICAL 9.1
CVE-2023-44981
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru…
Zookeeper
3.7.2 / 3.8.3+
HIGH 8.8
CVE-2023-37536
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Xerces C\+\+
9.5.23 / 10.0.10+
MEDIUM 5.3
CVE-2023-45648EPSS 6%
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro…
Tomcat
8.5.94 / 9.0.81+
MEDIUM 5.9
CVE-2023-42794
Incomplete Cleanup vulnerability in Apache Tomcat.
The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5…
Tomcat
8.5.94 / 9.0.81+
MEDIUM 5.3
CVE-2023-42795
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10…
Tomcat
8.5.94 / 9.0.81+
HIGH 7.5
CVE-2023-39410
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of …
Avro
1.11.3+
MEDIUM 6.1
CVE-2023-41834
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject…
Flink Stateful Functions
after 3.2.0
MEDIUM 5.5
CVE-2023-42503
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common…
Commons Compress
1.24.0+
HIGH 7.8
CVE-2023-41267
In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package…
Airflow Hdfs Provider
4.1.1+
HIGH 7.5
CVE-2023-41081
Important: Authentication Bypass CVE-2023-41081
The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration…
Tomcat Connectors
1.2.49+
MEDIUM 6.5
CVE-2023-40712
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, …
Airflow
2.7.1+
MEDIUM 6.6
CVE-2023-37941EPSS 29%
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to …
Superset
after 2.1.0
MEDIUM 6.5
CVE-2023-39265EPSS 84%
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+p…
Superset
after 2.1.0
MEDIUM 5.4
CVE-2023-36387
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test d…
Superset
after 2.1.0
MEDIUM 5.4
CVE-2023-36388
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possib…
Superset
after 2.1.0
CRITICAL 9.8
CVE-2023-40743
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S…
Axis
2023-08-01+
MEDIUM 5.9
CVE-2023-41180
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate…
Nifi Minifi C\+\+
after 0.14.0
HIGH 8.8
CVE-2023-27604
Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, wh…
Airflow Sqoop Provider
4.0.0+
HIGH 8.8
CVE-2023-40195
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo…
Airflow Spark Provider
4.1.3+
MEDIUM 6.1
CVE-2023-41080EPSS 6%
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from…
Tomcat
after 10.1.12
HIGH 8.1
CVE-2023-37379
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…
Airflow
2.7.0+