Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2021-28129
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi…
Openoffice
Mitigation only
CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…
HTTP Server
Patch available
HIGH 7.5
CVE-2021-41524EPSS 25%
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the …
HTTP Server
Patch available
CRITICAL 9.8
CVE-2021-41616
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…
Ddlutils
Mitigation only
MEDIUM 6.5
CVE-2021-36749EPSS 81%
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…
Druid
0.22.0+
HIGH 7.8
CVE-2021-33035EPSS 51%
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When readin…
Openoffice
after 4.1.10
MEDIUM 5.9
CVE-2021-38153EPSS 6%
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attack…
Kafka
2.2.4 / 2.6.3+
HIGH 7.5
CVE-2021-40690EPSS 7%
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is…
Santuario Xml Security For Java
2.1.7 / 2.2.3+
CRITICAL 9.8
CVE-2021-41303EPSS 77%
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users shoul…
Shiro
1.8.0+
CRITICAL 9.8
CVE-2021-39275EPSS 39%
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but t…
HTTP Server
2.4.49+
HIGH 7.5
CVE-2021-34798EPSS 65%
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
HTTP Server
after 5.19.1
HIGH 7.5
CVE-2021-36160EPSS 63%
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Ser…
HTTP Server
2.4.49+
HIGH 7.5
CVE-2021-39239
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex…
Jena
after 4.1.0
HIGH 7.5
CVE-2021-41079EPSS 7%
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured …
Tomcat
8.5.64 / 9.0.44+
CRITICAL 9.8
CVE-2021-40146EPSS 6%
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vuln…
Any23
2.5+
CRITICAL 9.1
CVE-2021-38555
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…
Any23
2.5+
CRITICAL 9.8
CVE-2021-38540EPSS 81%
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …
Airflow
2.1.3+
CRITICAL 9.8
CVE-2021-37579EPSS 7%
The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…
Dubbo
2.7.13 / 3.0.2+
CRITICAL 9.8
CVE-2021-36161
Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean…
Dubbo
2.7.13+
CRITICAL 9.8
CVE-2021-36163
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…
Dubbo
after 3.0.1
HIGH 8.8
CVE-2021-36162
Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the c…
Dubbo
after 3.0.1
MEDIUM 6.1
CVE-2021-27578
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scripts. This issue affects Apac…
Zeppelin
0.9.0+
CRITICAL 9.8
CVE-2019-10095EPSS 6%
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe…
Zeppelin
after 0.9.0
HIGH 7.5
CVE-2020-13929
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This is…
Zeppelin
after 0.9.0
HIGH 7.5
CVE-2021-25958
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table…
Ofbiz
17.12.08+
CRITICAL 9.8
CVE-2021-33191
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th…
Nifi Minifi C\+\+
0.10.0+
HIGH 7.1
CVE-2021-35940
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for thi…
Portable Runtime
Patch available
CRITICAL 9.8
CVE-2021-37608EPSS 6%
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach…
Ofbiz
17.12.08+
HIGH 7.5
CVE-2021-33580
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression…
Roller
6.0.2+
MEDIUM 5.3
CVE-2021-35936
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…
Airflow
2.1.2+