Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-31103
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1…
Inlong
after 1.6.0
MEDIUM 6.5
CVE-2023-31101
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 th…
Inlong
Mitigation only
CRITICAL 9.8
CVE-2023-31062
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.…
Inlong
after 1.6.0
HIGH 7.5
CVE-2023-31064
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from …
Inlong
after 1.6.0
HIGH 7.5
CVE-2023-31206
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1…
Inlong
after 1.6.0
HIGH 7.5
CVE-2023-31453
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…
Inlong
after 1.6.0
HIGH 7.5
CVE-2023-31454
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…
Inlong
after 1.6.0
HIGH 7.5
CVE-2023-31058
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.…
Inlong
after 1.6.0
HIGH 7.5
CVE-2023-28709EPSS 50%
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-d…
Tomcat
after 10.1.7
CRITICAL 9.8
CVE-2022-47937
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted inpu…
Sling Commons Json
after 2.0.20
HIGH 8.1
CVE-2023-29032
An attacker that has gained access to certain private information can use this to act as other user.
Vendor: The Apache Software Foundation
Version…
Openmeetings
7.1.0+
HIGH 7.2
CVE-2023-29246
An attacker who has gained access to an admin account can perform RCE via null-byte injection
Vendor: The Apache Software Foundation
Versions Affec…
Openmeetings
7.1.0+
MEDIUM 5.3
CVE-2023-28936
Attacker can access arbitrary recording/room
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
Openmeetings
7.1.0+
CRITICAL 9.8
CVE-2023-25754
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.
Airflow
2.6.0+
MEDIUM 5.4
CVE-2023-29247
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.
Airflow
2.6.0+
CRITICAL 9.8
CVE-2023-31039
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file.
An attacker tha…
Brpc
1.5.0+
HIGH 8.8
CVE-2023-31038
SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for S…
Log4cxx
1.1.0+
HIGH 8.8
CVE-2022-45048
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe…
Ranger
Mitigation only
HIGH 8.1
CVE-2021-40331
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on …
Ranger
after 2.3.0
MEDIUM 5.3
CVE-2023-26268
Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design d…
Couchdb
3.2.3 / 3.3.2+
HIGH 8.8
CVE-2023-32007EPSS 76%
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut…
Spark
after 3.2.1
CRITICAL 9.1
CVE-2022-46365
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …
Streampark
2.0.0+
CRITICAL 9.8
CVE-2022-45802
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…
Streampark
2.0.0+
MEDIUM 5.4
CVE-2022-45801
Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability.
LDAP Injection is an attack used to exploit web based applications
that constru…
Streampark
2.0.0+
MEDIUM 5.4
CVE-2023-22665
There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to ex…
Jena
after 4.8.0
MEDIUM 6.5
CVE-2023-30776
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue…
Superset
after 2.0.1
CRITICAL 9.8
CVE-2023-27524 KEVEPSS 97%
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_K…
Superset
after 2.0.1
MEDIUM 6.5
CVE-2023-25504
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to condu…
Superset
after 2.0.1
CRITICAL 9.9
CVE-2023-22946
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…
Spark
3.4.0+
CRITICAL 9.8
CVE-2023-30771
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd…
Iotdb Web Workbench
Mitigation only