Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2020-9487
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to c…
Nifi
after 1.11.4
HIGH 7.5
CVE-2020-9491
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors …
Nifi
after 1.11.4
HIGH 7.5
CVE-2020-11979EPSS 8%
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to …
Ant
6.8.0+
MEDIUM 5.5
CVE-2020-13940
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted admini…
Nifi
after 1.11.4
HIGH 8.1
CVE-2020-13952
In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines …
Superset
0.37.2+
HIGH 7.5
CVE-2020-13951EPSS 70%
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
Openmeetings
after 5.0.0
MEDIUM 5.3
CVE-2020-13953
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
Tapestry
5.6.4 / 5.7.2+
HIGH 7.5
CVE-2018-11765EPSS 5%
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerbe…
Hadoop
after 2.9.2
MEDIUM 6.1
CVE-2020-13944EPSS 25%
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
Airflow
1.10.15 / 2.0.2+
HIGH 8.8
CVE-2020-13948
While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text…
Superset
0.37.1+
MEDIUM 6.1
CVE-2020-13928
Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of th…
Atlas
2.1.0+
HIGH 7.2
CVE-2020-11977
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Se…
Syncope
2.1.7+
CRITICAL 9.8
CVE-2019-0230EPSS 97%
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Struts
after 8.0.23
HIGH 7.5
CVE-2019-0233EPSS 68%
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Struts
after 8.0.23
HIGH 7.5
CVE-2020-11991EPSS 72%
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc…
Cocoon
after 2.1.12
CRITICAL 9.8
CVE-2020-11998EPSS 51%
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map …
Activemq
after 8.5.0
MEDIUM 5.9
CVE-2020-13920
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to con…
Activemq
5.15.12+
CRITICAL 9.8
CVE-2020-11986EPSS 10%
To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build…
Netbeans
after 12.0
MEDIUM 5.9
CVE-2020-13946
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Ap…
Cassandra
2.1.22 / 2.2.18+
HIGH 7.5
CVE-2020-13933EPSS 48%
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
Shiro
1.6.0+
HIGH 8.8
CVE-2020-13941
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org…
Solr
8.6.0+
HIGH 7.5
CVE-2020-11976
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive in…
Fortress
7.17.0 / 8.9.0+
HIGH 7.5
CVE-2020-9490EPSS 90%
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash whe…
HTTP Server
2.4.46+
CRITICAL 9.8
CVE-2020-11984EPSS 90%
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
HTTP Server
after 8.2.2
HIGH 7.5
CVE-2020-11993EPSS 59%
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging stateme…
HTTP Server
2.4.44+
MEDIUM 5.3
CVE-2020-11985EPSS 7%
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rule…
HTTP Server
after 2.4.23
CRITICAL 9.8
CVE-2020-13921EPSS 33%
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
Skywalking
Patch available
MEDIUM 6.1
CVE-2020-13932
In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vuln…
Artemis
after 2.13.0
MEDIUM 6.1
CVE-2020-9485
An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.
Airflow
after 1.10.10
CRITICAL 9.8
CVE-2020-11981EPSS 37%
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ…
Airflow
after 1.10.10