Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-25692
Improper Input Validation vulnerability in the Apache Airflow Google Provider.
This issue affects Apache Airflow Google Provider versions before 8.1…
Apache Airflow Providers Google
8.10.0+
HIGH 7.5
CVE-2023-25956
Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider.
This issue affects Apache Airflow AWS…
Apache Airflow Providers Amazon
7.2.1+
MEDIUM 6.5
CVE-2023-25621
Privilege Escalation vulnerability in Apache Software Foundation Apache Sling.
Any content author is able to create i18n dictionaries in the reposito…
Sling I18n
2.6.2+
CRITICAL 9.8
CVE-2023-25613
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
Kerby Ldap Backend
2.0.3+
HIGH 7.5
CVE-2023-24998EPSS 47%
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin…
Commons Fileupload
1.5+
HIGH 8.8
CVE-2022-42735
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
ShenYu Admin allows low-privilege low-level administrators…
Shenyu
Mitigation only
HIGH 7.5
CVE-2023-25141
Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct…
Sling Jcr Base
3.1.12+
HIGH 7.5
CVE-2023-22832
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references.
Flow configurations that i…
Nifi
after 1.19.1
HIGH 8.8
CVE-2023-25194EPSS 96%
A possible security vulnerability has been identified in Apache Kafka Connect API.
This requires access to a Kafka Connect worker, and the ability to…
Kafka Connect
after 3.3.2
HIGH 8.1
CVE-2022-45786
There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for Postgre…
Age
after 1.1.0
MEDIUM 6.1
CVE-2023-22849
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and pri…
Sling Cms
1.1.6+
CRITICAL 9.8
CVE-2023-24997
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.…
Inlong
after 1.5.0
HIGH 7.5
CVE-2023-24977
Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are ad…
Inlong
after 1.5.0
CRITICAL 9.8
CVE-2022-24963
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a …
Portable Runtime
Mitigation only
CRITICAL 9.8
CVE-2022-28331
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int…
Portable Runtime
after 1.7.0
MEDIUM 6.5
CVE-2022-25147
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond…
Portable Runtime Utility
after 1.6.1
HIGH 8.8
CVE-2022-44645
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…
Linkis
after 1.3.0
HIGH 8.8
CVE-2023-24829
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 bef…
Iotdb
0.13.3+
MEDIUM 6.5
CVE-2022-44644
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files b…
Linkis
after 1.3.0
HIGH 7.5
CVE-2023-24830
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before…
Iotdb
0.13.3+
CRITICAL 9.8
CVE-2023-22884EPSS 11%
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…
Airflow
2.5.1 / 4.0.0+
CRITICAL 9.0
CVE-2022-36760
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to sm…
HTTP Server
2.4.55+
HIGH 7.5
CVE-2006-20001
A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header va…
HTTP Server
2.4.55+
MEDIUM 5.3
CVE-2022-37436EPSS 58%
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorpo…
HTTP Server
2.4.55+
HIGH 8.8
CVE-2022-43719
Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…
Superset
after 1.5.2
MEDIUM 5.4
CVE-2022-41703
A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subquerie…
Superset
after 1.5.2
MEDIUM 5.4
CVE-2022-43717
Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by…
Superset
after 1.5.2
MEDIUM 5.4
CVE-2022-43718
Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with databas…
Superset
after 1.5.2
MEDIUM 5.4
CVE-2022-43720
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the t…
Superset
after 1.5.2
MEDIUM 5.4
CVE-2022-43721
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site wh…
Superset
after 1.5.2