Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-22696EPSS 7%
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…
Cxf
3.3.10 / 3.4.3+
MEDIUM 5.5
CVE-2021-28657
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade …
Tika
after 17.12
HIGH 8.8
CVE-2021-26919EPSS 23%
Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissio…
Druid
0.20.2+
CRITICAL 9.8
CVE-2020-1946EPSS 6%
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …
Spamassassin
3.4.5+
CRITICAL 9.8
CVE-2021-21347EPSS 14%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21350EPSS 15%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21351EPSS 82%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…
Activemq
1.4.16 / 5.5+
HIGH 8.6
CVE-2021-21349EPSS 47%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
HIGH 7.5
CVE-2021-21348EPSS 14%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.9
CVE-2021-21345EPSS 72%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21344EPSS 76%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21346EPSS 76%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21342EPSS 50%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …
Activemq
1.4.16 / 5.5+
HIGH 7.5
CVE-2021-21341EPSS 78%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo…
Activemq
1.4.16 / 5.5+
HIGH 7.5
CVE-2021-21343EPSS 47%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-26295EPSS 98%
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF…
Ofbiz
17.12.06+
MEDIUM 5.5
CVE-2021-27807
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x ver…
Pdfbox
after 14.3.0
MEDIUM 5.5
CVE-2021-27906
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2…
Pdfbox
after 2.0.22
HIGH 7.5
CVE-2020-17525EPSS 40%
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a c…
Subversion
1.10.7 / 1.14.1+
HIGH 7.5
CVE-2020-13924
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to …
Ambari
after 2.6.2.2
MEDIUM 5.9
CVE-2020-1926
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow rec…
Hive
2.3.8+
HIGH 7.5
CVE-2021-27576
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache O…
Openmeetings
6.0.0+
HIGH 8.8
CVE-2020-13936EPSS 23%
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as th…
Velocity Engine
2.3+
MEDIUM 6.1
CVE-2020-13959EPSS 6%
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attac…
Velocity Tools
3.1+
MEDIUM 5.4
CVE-2021-27907EPSS 86%
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related informatio…
Superset
after 0.38.0
MEDIUM 6.1
CVE-2020-1936
A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
Ambari
2.7.4+
MEDIUM 5.5
CVE-2020-9479
When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache A…
Asterixdb
0.9.5+
HIGH 7.0
CVE-2021-25329EPSS 9%
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with…
Tomcat
21.3.0+
HIGH 7.5
CVE-2021-25122EPSS 18%
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate re…
Tomcat
21.3.0+
MEDIUM 5.3
CVE-2020-27223EPSS 78%
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers …
Nifi
9.4.36+