Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Xerces C\+\+ CRITICAL 9.8
CVE-2016-2099EPSS 7%

Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspe…

Fix: after 3.1.3
Fix from $2,300 2016-05-13
Struts CRITICAL 9.8
CVE-2016-3082EPSS 19%

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary …

Patch available
Fix from $2,300 2016-04-26
Ofbiz CRITICAL 9.8
CVE-2016-2170EPSS 13%

Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

Fix: 12.04.06 / 13.07.03+
Fix from $2,300 2016-04-12
Ranger CRITICAL 9.8
CVE-2016-0733

The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by…

Fix: after 0.5.0
Fix from $2,300 2016-04-12
Cloudstack CRITICAL 9.8
CVE-2015-3252

Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain ac…

Fix: after 4.5.1
Fix from $2,300 2016-02-08
Camel CRITICAL 9.8
CVE-2015-5344EPSS 7%

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted…

Fix: after 2.15.4
Fix from $2,300 2016-02-03
Commons Collections CRITICAL 9.8
CVE-2015-6420EPSS 18%

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and…

Fix: 3.2.2+
Fix from $2,300 2015-12-15
Groovy CRITICAL 9.8
CVE-2015-3253EPSS 32%

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause…

Patch available
Fix from $2,300 2015-08-13
Archiva CRITICAL 9.8
CVE-2013-2251 KEVEPSS 100%

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi…

Fix: 1.3.8+
Fix from $2,300 2013-07-20
Struts CRITICAL 9.8
CVE-2012-0391 KEVEPSS 76%

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo…

Fix: 2.2.3.1+
Fix from $2,300 2012-01-08
Cxf CRITICAL 9.8
CVE-2010-2076EPSS 10%

Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUD…

Fix: 2.0.13 / 2.1.10+
Fix from $2,300 2010-08-19
HTTP Server CRITICAL 9.8
CVE-2009-3555EPSS 87%

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache …

Fix: after 3.12.4
Fix from $2,300 2009-11-09
HTTP Server CRITICAL 9.8
CVE-2001-0766EPSS 8%

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characte…

Patch available
Fix from $2,300 2001-10-18