Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-11982EPSS 7%
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) …
Airflow
after 1.10.10
HIGH 8.8
CVE-2020-11978 KEVEPSS 99%
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…
Airflow
1.10.11+
MEDIUM 5.4
CVE-2020-11983
An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handl…
Airflow
after 1.10.10
MEDIUM 6.1
CVE-2020-9496EPSS 99%
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
Ofbiz
No fix yet
MEDIUM 5.3
CVE-2020-13923EPSS 5%
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
Ofbiz
17.12.04+
HIGH 7.5
CVE-2020-13934EPSS 64%
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after…
Tomcat
after 9.0.36
HIGH 7.5
CVE-2020-13935EPSS 87%
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and …
Tomcat
after 9.0.36
CRITICAL 9.8
CVE-2020-1948EPSS 16%
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met…
Dubbo
after 2.7.6
CRITICAL 9.8
CVE-2020-13925EPSS 20%
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…
Kylin
3.1.0+
CRITICAL 9.8
CVE-2020-13926
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…
Kylin
3.1.0+
HIGH 7.5
CVE-2020-11994
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
Camel
after 8.5.0
MEDIUM 6.7
CVE-2020-9498
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a m…
Guacamole
after 1.1.0
HIGH 7.5
CVE-2020-9483EPSS 35%
**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability…
Skywalking
after 6.6.0
HIGH 7.8
CVE-2020-8022
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE …
Tomcat
8.0.53-29.32.1 / 9.0.35-3.39.1+
HIGH 7.5
CVE-2020-11996EPSS 27%
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger hi…
Tomcat
after 20.12
MEDIUM 5.5
CVE-2020-10727
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in t…
Artemis
after 2.12.0
HIGH 7.5
CVE-2020-9494
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the …
Traffic Server
after 8.0.7
CRITICAL 9.8
CVE-2020-9480EPSS 29%
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…
Spark
after 2.4.5
CRITICAL 9.8
CVE-2020-11989EPSS 24%
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Shiro
1.5.3+
MEDIUM 5.3
CVE-2020-9495EPSS 8%
Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP…
Archiva
2.2.5+
CRITICAL 9.8
CVE-2020-11969
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP…
Tomee
after 8.0.1
MEDIUM 6.3
CVE-2020-11980
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…
Karaf
4.2.9+
CRITICAL 9.8
CVE-2020-11975EPSS 30%
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code wi…
Unomi
1.5.1+
CRITICAL 9.1
CVE-2020-1963
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fi…
Ignite
after 2.8.0
HIGH 8.8
CVE-2020-1956 KEVEPSS 97%
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …
Kylin
after 2.6.5
CRITICAL 9.8
CVE-2018-21234EPSS 8%
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
Hive
5.0.4+
HIGH 7.0
CVE-2020-9484EPSS 57%
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to contr…
Tomcat
7.0.108 / 8.5.63+
CRITICAL 9.8
CVE-2020-1955
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_e…
Couchdb
Mitigation only
CRITICAL 9.8
CVE-2020-11972EPSS 6%
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users…
Camel
after 8.2.2
CRITICAL 9.8
CVE-2020-11973EPSS 7%
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh…
Camel
after 8.5.0