Filter
AND
-Infinity
0

Apache Seata ServerApache Seata (incubating): Deserialization of untrusted Data in jraft mode in Apache Seata Server

First published (updated )

maven/org.apache.tomcat.embed:tomcat-embed-coreApache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

First published (updated )

Apache RangerApache Ranger: Improper Neutralization of Formula Elements in a CSV File

First published (updated )

Apache EventMeshApache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution

First published (updated )

Apache IgniteApache Ignite: Possible RCE when deserializing incoming messages by the server node

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache FineractApache Fineract: SQL injection vulnerabilities in offices API endpoint

First published (updated )

Apache RangerApache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost

First published (updated )

maven/org.apache.openmeetings:openmeetings-parentApache OpenMeetings: Deserialisation of untrusted data in cluster mode

First published (updated )

maven/org.apache.mina:mina-coreApache MINA: MINA applications using unbounded deserialization may allow RCE

First published (updated )

go/github.com/apache/trafficcontrol/v8Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

ArrowApache Arrow R package: Arbitrary code execution when loading a malicious data file

First published (updated )

Apache CloudStackApache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure

First published (updated )

maven/org.apache.seata:seata-coreApache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server

First published (updated )

Apache OFBizApache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE

First published (updated )

Apache OFBizApache OFBiz Forced Browsing Vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

D-Link DAP-2310Buffer Overflow, Code Injection

First published (updated )

Dromara HertzbeatGHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metric/{metricFull}

First published (updated )

pip/apache-airflow-providers-fabApache Airflow Providers FAB: FAB provider 1.2.1 and 1.2.0 did not let user to logout for Airflow

First published (updated )

Apache OFBizApache OFBiz Incorrect Authorization Vulnerability

First published (updated )

maven/org.apache.inlong:tubemq-coreApache InLong TubeMQ Client: Remote Code Execution vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache Traffic ServerApache Traffic Server: Incomplete check for chunked trailer section allows request smuggling

First published (updated )

maven/org.apache.drill.exec:drill-java-execApache Drill: XXE Vulnerability in XML Format Reader

First published (updated )

maven/org.apache.cxf:cxf-rt-rs-service-descriptionApache CXF: SSRF vulnerability via WADL stylesheet parameter

First published (updated )

Apache Http ServerApache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows

First published (updated )

pip/apache-supersetApache Superset: Improper SQL authorisation, parse not checking for specific engine functions

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

CVE-2024-38346Apache CloudStack: Unauthenticated cluster service port leads to remote execution

First published (updated )

CVE-2024-39864Apache CloudStack: Integration API service uses dynamic port when disabled

First published (updated )

Apache HTTP ServerApache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect

First published (updated )

F5 BIG-IP and BIG-IQ Centralized ManagementApache HTTP Server weakness with encoded question marks in backreferences

First published (updated )

maven/org.apache.submarine:submarine-server-coreApache Submarine Server Core: authorization bypass

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203