Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-12635EPSS 100%
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1…
Couchdb
1.7.0+
CRITICAL 9.8
CVE-2012-4449
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features ar…
Hadoop
after 0.23.3
CRITICAL 9.8
CVE-2013-4366
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a…
Httpclient
Patch available
CRITICAL 9.8
CVE-2014-0073EPSS 8%
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap…
Cordova In App Browser
after 2.9.0
CRITICAL 9.8
CVE-2014-3624
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request…
Traffic Server
Patch available
CRITICAL 9.8
CVE-2015-3249EPSS 5%
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…
Traffic Server
Mitigation only
CRITICAL 9.8
CVE-2014-3579
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…
Activemq Apollo
Mitigation only
CRITICAL 9.8
CVE-2014-3600EPSS 9%
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…
Activemq
Mitigation only
CRITICAL 9.8
CVE-2016-5003EPSS 15%
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…
Ws Xmlrpc
No fix yet
CRITICAL 9.8
CVE-2012-1622EPSS 5%
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
Ofbiz
Mitigation only
CRITICAL 9.8
CVE-2017-5636
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…
Nifi
Mitigation only
CRITICAL 9.8
CVE-2017-12629EPSS 92%
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li…
Solr
after 7.0.1
CRITICAL 9.8
CVE-2016-8736
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
Openmeetings
3.1.2+
CRITICAL 9.8
CVE-2014-0030EPSS 15%
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Roller
No fix yet
CRITICAL 9.8
CVE-2017-12620
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…
Opennlp
No fix yet
CRITICAL 9.8
CVE-2017-12621EPSS 9%
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used …
Commons Jelly
1.0.1+
CRITICAL 9.8
CVE-2016-6795EPSS 8%
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for…
Struts
Mitigation only
CRITICAL 9.8
CVE-2017-12611EPSS 95%
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can …
Struts
Patch available
CRITICAL 9.8
CVE-2015-5168
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a dif…
Traffic Server
No fix yet
CRITICAL 9.8
CVE-2015-5206
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors…
Traffic Server
Mitigation only
CRITICAL 9.8
CVE-2016-3086
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM…
Hadoop
Mitigation only
CRITICAL 9.8
CVE-2016-4460EPSS 5%
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
Pony Mail
Patch available
CRITICAL 9.8
CVE-2017-9800EPSS 18%
A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run …
Subversion
after 1.8.18
CRITICAL 9.1
CVE-2016-5018EPSS 10%
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able …
Tomcat
after 8.5.4
CRITICAL 9.8
CVE-2012-0803
The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa…
Cxf
Patch available
CRITICAL 9.8
CVE-2016-6798
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string…
Sling
after 1.0.10
CRITICAL 10.0
CVE-2017-7664
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
Openmeetings
Mitigation only
CRITICAL 9.8
CVE-2017-7673
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms …
Openmeetings
Mitigation only
CRITICAL 9.1
CVE-2016-6793EPSS 9%
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop…
Wicket
1.5.17 / 6.25.0+
CRITICAL 9.1
CVE-2017-9788EPSS 54%
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…
HTTP Server
after 2.4.26