Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-45458
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by thi…
Kylin
3.1.3+
MEDIUM 6.5
CVE-2021-36774
Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmi…
Kylin
after 3.1.2
HIGH 7.5
CVE-2021-27738
All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any se…
Kylin
3.1.2+
MEDIUM 6.1
CVE-2021-36737
The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of th…
Pluto
3.1.1+
MEDIUM 6.1
CVE-2021-36738
The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users sho…
Pluto
3.1.1+
MEDIUM 6.1
CVE-2021-36739
The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) at…
Pluto
Mitigation only
CRITICAL 9.1
CVE-2021-40525
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writ…
James
3.6.2+
HIGH 7.5
CVE-2021-34797
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with …
Geode
after 1.13.4
HIGH 7.5
CVE-2021-40110
In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnera…
James
3.6.1+
MEDIUM 6.5
CVE-2021-40111
In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP command could be used to trigger i…
James
3.6.1+
MEDIUM 5.9
CVE-2021-38542
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-mi…
James
3.6.1+
MEDIUM 6.6
CVE-2021-44832EPSS 98%
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…
Log4j
2.3.2 / 2.12.4+
CRITICAL 9.8
CVE-2021-45232EPSS 86%
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all…
Apisix Dashboard
2.10.1+
CRITICAL 9.8
CVE-2021-44548EPSS 5%
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…
Solr
8.11.1+
CRITICAL 9.8
CVE-2021-44790EPSS 97%
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache http…
HTTP Server
2.4.52 / 5.20.0+
HIGH 8.2
CVE-2021-44224EPSS 82%
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixi…
HTTP Server
2.4.52 / 5.20.0+
HIGH 7.5
CVE-2021-41561
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apac…
Parquet Java
1.11.2 / 1.12.2+
HIGH 8.8
CVE-2021-43083
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport.…
Plc4x
0.9.1+
MEDIUM 5.9
CVE-2021-45105EPSS 100%
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential looku…
Log4j
2.3.1 / 2.7.0+
MEDIUM 6.5
CVE-2021-44145
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious externa…
Nifi
1.15.1+
CRITICAL 9.0
CVE-2021-45046 KEVEPSS 100%
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at…
Log4j
2.12.2 / 2.16.0+
HIGH 7.4
CVE-2021-44549
Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "…
Sling Commons Messaging Mail
Mitigation only
HIGH 7.5
CVE-2021-4104EPSS 81%
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack…
Log4j
Patch available
CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…
Log4j
2.1.0 / 2.3.1+
MEDIUM 5.3
CVE-2021-43410
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are l…
Airavata Django Portal
2021-12-06+
CRITICAL 9.1
CVE-2021-44140EPSS 6%
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…
Jspwiki
2.11.0+
MEDIUM 6.1
CVE-2021-40369
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow th…
Jspwiki
2.11.0+
HIGH 7.5
CVE-2021-43557EPSS 15%
The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without…
Apisix
2.10.2+
CRITICAL 9.1
CVE-2021-39231
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…
Ozone
1.2.0+
CRITICAL 9.1
CVE-2021-39233
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any …
Ozone
1.2.0+