Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2020-1950
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
Tika
after 1.23
MEDIUM 5.5
CVE-2020-1951
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Tika
after 1.23
MEDIUM 6.1
CVE-2019-12416
we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrat…
Deltaspike
after 1.9.2
HIGH 7.4
CVE-2019-10091
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c…
Geode
Mitigation only
CRITICAL 10.0
CVE-2020-1953EPSS 7%
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…
Commons Configuration
Mitigation only
CRITICAL 9.8
CVE-2020-1947EPSS 34%
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …
Shardingsphere
Mitigation only
MEDIUM 5.9
CVE-2011-2487
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbac…
Cxf
1.6.5+
MEDIUM 6.1
CVE-2015-2992EPSS 6%
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Struts
2.3.20+
CRITICAL 9.8
CVE-2020-1938 KEVEPSS 99%
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as …
Geode
7.0.100 / 8.5.51+
HIGH 8.8
CVE-2020-1937
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
Kylin
after 2.6.4
CRITICAL 9.8
CVE-2014-4651
It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc…
Jclouds
1.8.0+
HIGH 7.5
CVE-2020-1942
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the …
Nifi
after 1.11.0
MEDIUM 5.3
CVE-2019-12426
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
Ofbiz
after 16.11.06
HIGH 8.1
CVE-2020-1930EPSS 7%
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur…
Spamassassin
3.4.3+
HIGH 8.1
CVE-2020-1931EPSS 6%
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to…
Spamassassin
3.4.3+
HIGH 7.5
CVE-2020-1940
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive infor…
Jackrabbit Oak
after 1.22.0
MEDIUM 6.5
CVE-2020-1932
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retr…
Superset
Mitigation only
MEDIUM 6.1
CVE-2020-1933
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticate…
Nifi
after 1.10.0
MEDIUM 5.3
CVE-2020-1928
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose…
Nifi
Mitigation only
CRITICAL 9.8
CVE-2019-17570EPSS 49%
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar…
Xml Rpc
Patch available
HIGH 7.5
CVE-2019-12423EPSS 6%
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to ver…
Cxf
3.2.12 / 3.3.5+
MEDIUM 6.1
CVE-2019-17573EPSS 7%
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a r…
Cxf
3.3.5+
HIGH 7.5
CVE-2020-1929
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not res…
Beam
after 2.16.0
CRITICAL 9.8
CVE-2019-0219EPSS 8%
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially craft…
Cordova Inappbrowser
after 3.0.0
HIGH 7.5
CVE-2019-12399
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a conne…
Kafka
after 14.4.0
HIGH 7.5
CVE-2020-1925
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or D…
Olingo
after 4.7.0
CRITICAL 9.8
CVE-2020-5499
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.
Rust Sgx Sdk
after 1.0.8
HIGH 7.5
CVE-2019-17558 KEVEPSS 99%
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…
Solr
7.7.3 / 8.4.0+
HIGH 7.0
CVE-2019-12418
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker witho…
Tomcat
after 9.0.28
HIGH 7.5
CVE-2019-17563EPSS 11%
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker…
Tomcat
after 17.3