Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2022-42466
Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be render…
Isis
2.0.0+
MEDIUM 5.3
CVE-2022-42467
When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to dir…
Isis
2.0.0+
CRITICAL 9.8
CVE-2022-39198
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…
Dubbo
after 3.0.11
CRITICAL 9.8
CVE-2022-42889EPSS 100%
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…
Commons Text
1.10.0 / 7.5.0+
CRITICAL 9.8
CVE-2022-24697EPSS 85%
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can…
Kylin
2.6.6+
CRITICAL 9.8
CVE-2022-40664
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
Shiro
1.10.0+
HIGH 8.1
CVE-2022-41672
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the U…
Airflow
after 2.4.1
MEDIUM 6.5
CVE-2022-40160
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…
Commons Jxpath
after 1.3
MEDIUM 6.5
CVE-2022-40159
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…
Commons Jxpath
after 1.3
MEDIUM 6.5
CVE-2022-24280
Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from…
Pulsar
2.7.5 / 2.8.3+
MEDIUM 5.9
CVE-2022-33681
Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connectio…
Pulsar
2.7.5 / 2.8.4+
MEDIUM 5.9
CVE-2022-33682
TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's J…
Pulsar
2.7.5 / 2.8.4+
MEDIUM 5.9
CVE-2022-33683
Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnec…
Pulsar
2.7.5 / 2.8.4+
CRITICAL 9.8
CVE-2022-26112
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…
Pinot
0.11.0+
HIGH 7.5
CVE-2022-40146EPSS 6%
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affec…
Batik
Mitigation only
MEDIUM 5.3
CVE-2022-38398
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue a…
Batik
Mitigation only
MEDIUM 5.3
CVE-2022-38648
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects A…
Batik
Mitigation only
HIGH 7.5
CVE-2022-40705
An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files …
Soap
Mitigation only
HIGH 7.5
CVE-2022-40604
In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.
Airflow
after 2.3.4
MEDIUM 6.1
CVE-2022-40754
In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
Airflow
after 2.3.4
HIGH 8.8
CVE-2022-40955
In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi…
Inlong
1.3.0+
HIGH 7.5
CVE-2022-34917
A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated…
Kafka
2.8.2 / 3.0.2+
CRITICAL 9.8
CVE-2022-39135
Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe…
Calcite
1.32.0+
HIGH 7.5
CVE-2022-28220
Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, …
James
after 3.6.2
HIGH 8.8
CVE-2022-38369
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Iotdb
No fix yet
HIGH 7.5
CVE-2022-38370
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…
Iotdb
Mitigation only
CRITICAL 9.8
CVE-2022-25371
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in…
Ofbiz
18.12.06+
CRITICAL 9.8
CVE-2022-29063
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier…
Ofbiz
18.12.06+
CRITICAL 9.8
CVE-2022-38054
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
Airflow
after 2.3.3
HIGH 7.5
CVE-2022-25813EPSS 67%
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a …
Ofbiz
18.12.06+