
Apache StreamPipesApache StreamPipes: Resources Permission Escalation

First published (updated )

TomcatRace Condition

First published (updated )

pip/apache-supersetApache Superset: Server arbitrary file read

First published (updated )

CVE-2024-45461Apache CloudStack Quota plugin: Access checks not enforced in Quota

First published (updated )

Oracle UtilitiesApache Ant TAR archive denial of service vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Banking APIsPossible limited path traversal vulnerabily in Apache Commons IO

First published (updated )

IBM Data Virtualization on Cloud Pak for DataXSS

First published (updated )

Oracle UtilitiesApache Ant ZIP, and ZIP based, archive denial of service vulerability

First published (updated )

maven/org.apache.cassandra:cassandra-allApache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions

First published (updated )

maven/org.apache.cassandra:cassandra-allApache Cassandra: unrestricted deserialization of JMX authentication credentials

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache SolrApache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files

First published (updated )

Apache HiveApache Hive: Timing Attack Against Signature in LLAP util

First published (updated )

Trellix ePolicy OrchestratorIncorrect Transfer-Encoding handling with HTTP/1.0

First published (updated )

maven/org.apache.james:apache-mime4j-coreApache James Mime4J: Mime4J DOM header injection

First published (updated )

Apache Commons IOUncontrolled Resource Consumption vulnerability in Apache Commons IO. The…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache KvrocksApache Kvrocks: Cross-Protocol Scripting Vulnerability

First published (updated )

Apache AirflowApache Airflow: Bypass permission verification to read code of other dags

First published (updated )

pip/apache-airflowApache Airflow: DAG Params alllow to embed unchecked Javascript

First published (updated )

Apache SupersetApache Superset: Allows for uncontrolled resource consumption via a ZIP bomb

First published (updated )

Apache StormApache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache SupersetApache Superset: Lack of rate limiting allows for possible denial of service

First published (updated )

pip/apache-supersetApache Superset: Sensitive information disclosure on db connection details

First published (updated )

Apache SupersetApache Superset: Unnecessary read permissions within the Gamma role

First published (updated )

Apache AirflowApache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access)

First published (updated )

pip/apache-airflowApache Airflow: Bypass permission verification to view task instances of other dags

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.apache.santuario:xmlsecApache Santuario: Private Key disclosure in debug-log output

First published (updated )

TomcatApache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests

First published (updated )

redhat/Apache Commons CompressApache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

First published (updated )

Apache Commons CompressApache Commons Compress: Denial of service via CPU consumption for malformed TAR file

First published (updated )

Apache AirflowApache Airflow Dag Runs Broken Access Control Vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.


SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203