Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2021-32566
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se…
Traffic Server
after 9.0.1
HIGH 7.5
CVE-2021-32567
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se…
Traffic Server
after 9.0.1
HIGH 8.2
CVE-2020-11987EPSS 14%
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf…
Batik
after 1.13
HIGH 8.2
CVE-2020-11988EPSS 7%
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi…
Xmlgraphics Commons
after 2.4
HIGH 8.8
CVE-2020-17532
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The…
Java Chassis
2.1.5+
CRITICAL 9.8
CVE-2020-13942EPSS 68%
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…
Unomi
1.5.2+
HIGH 8.8
CVE-2020-13941
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org…
Solr
8.6.0+
CRITICAL 9.8
CVE-2014-4651
It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc…
Jclouds
1.8.0+
HIGH 7.5
CVE-2019-17555
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w…
Olingo
after 4.6.0
HIGH 8.8
CVE-2016-1000104
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
Mod Fcgid
after 2016-07-07
MEDIUM 6.5
CVE-2009-5004
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
Qpid Cpp
Mitigation only
MEDIUM 6.5
CVE-2018-11782
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only …
Subversion
after 1.11.1
MEDIUM 5.5
CVE-2019-12400
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static poo…
Santuario Xml Security For Java
2.1.4+
CRITICAL 9.8
CVE-2018-11773
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as a…
Virtual Computing Lab
after 2.5
HIGH 8.8
CVE-2017-15720
In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.
Airflow
after 1.8.2
MEDIUM 6.5
CVE-2018-11799
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that result…
Oozie
5.1.0+
HIGH 7.5
CVE-2018-17194
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE …
Nifi
after 1.7.1
HIGH 7.8
CVE-2018-14889
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
Couchdb
Mitigation only
MEDIUM 5.3
CVE-2017-15705EPSS 8%
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags…
Spamassassin
3.4.2+
HIGH 7.5
CVE-2018-1330
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked H…
Mesos
1.4.2 / 1.5.1+
HIGH 7.5
CVE-2018-8022EPSS 7%
A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users …
Traffic Server
after 6.2.2
HIGH 7.5
CVE-2018-1318EPSS 8%
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server …
Traffic Server
after 7.1.3
HIGH 7.2
CVE-2018-8007EPSS 12%
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configura…
Couchdb
after 2.1.1
HIGH 7.5
CVE-2018-8038EPSS 11%
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response…
Cxf Fediz
1.4.4+
HIGH 7.5
CVE-2018-8030
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish mes…
Qpid Broker J
after 7.0.4
HIGH 8.1
CVE-2017-15715EPSS 86%
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than…
HTTP Server
after 2.4.29
HIGH 7.5
CVE-2018-1294
If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input co…
Commons Email
after 1.4
HIGH 7.2
CVE-2018-1321EPSS 18%
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and …
Syncope
1.2.11 / 2.0.8+
HIGH 8.6
CVE-2017-5660
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issu…
Traffic Server
after 6.2.0
HIGH 7.5
CVE-2017-7671
There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can c…
Traffic Server
after 6.2.0