Filter
AND
-Infinity
0

Apache ActiveMQ NMS OpenWire ClientApache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass

First published (updated )

Apache ParquetApache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata

EPSS
0.09%
First published (updated )

Apache PinotApache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required

First published (updated )

Apache Seata ServerApache Seata (incubating): Deserialization of untrusted Data in jraft mode in Apache Seata Server

First published (updated )

maven/org.apache.tomcat.embed:tomcat-embed-coreApache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache RangerApache Ranger: Improper Neutralization of Formula Elements in a CSV File

First published (updated )

Apache EventMeshApache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution

First published (updated )

Apache IgniteApache Ignite: Possible RCE when deserializing incoming messages by the server node

First published (updated )

Apache FineractApache Fineract: SQL injection vulnerabilities in offices API endpoint

First published (updated )

Apache RangerApache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.apache.openmeetings:openmeetings-parentApache OpenMeetings: Deserialisation of untrusted data in cluster mode

First published (updated )

IBM Operational Decision ManagerApache MINA: MINA applications using unbounded deserialization may allow RCE

First published (updated )

go/github.com/apache/trafficcontrol/v8Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments

First published (updated )

ArrowApache Arrow R package: Arbitrary code execution when loading a malicious data file

First published (updated )

Apache CloudStackApache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.apache.seata:seata-coreApache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server

First published (updated )

Apache OFBizApache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE

First published (updated )

Apache OFBizApache OFBiz Forced Browsing Vulnerability

First published (updated )

D-Link DAP-2310Buffer Overflow, Code Injection

First published (updated )

Dromara HertzbeatGHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metric/{metricFull}

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

pip/apache-airflow-providers-fabApache Airflow Providers FAB: FAB provider 1.2.1 and 1.2.0 did not let user to logout for Airflow

First published (updated )

Apache OFBizApache OFBiz Incorrect Authorization Vulnerability

First published (updated )

maven/org.apache.inlong:tubemq-coreApache InLong TubeMQ Client: Remote Code Execution vulnerability

First published (updated )

Apache Traffic ServerApache Traffic Server: Incomplete check for chunked trailer section allows request smuggling

First published (updated )

maven/org.apache.drill.exec:drill-java-execApache Drill: XXE Vulnerability in XML Format Reader

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.apache.cxf:cxf-rt-rs-service-descriptionApache CXF: SSRF vulnerability via WADL stylesheet parameter

First published (updated )

Apache Http ServerApache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows

First published (updated )

pip/apache-supersetApache Superset: Improper SQL authorisation, parse not checking for specific engine functions

First published (updated )

CVE-2024-38346Apache CloudStack: Unauthenticated cluster service port leads to remote execution

First published (updated )

CVE-2024-39864Apache CloudStack: Integration API service uses dynamic port when disabled

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203