Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.1
CVE-2013-2088EPSS 31%
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary …
Subversion
after 1.6.21
MEDIUM 5.8
CVE-2013-2248EPSS 95%
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond…
Struts
Mitigation only
MEDIUM 5.0
CVE-2012-3544EPSS 11%
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attac…
Tomcat
Patch available
MEDIUM 5.0
CVE-2012-2733EPSS 9%
java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not…
Tomcat
Mitigation only
MEDIUM 5.8
CVE-2012-5784EPSS 6%
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service impleme…
Activemq
after 5.7.0
MEDIUM 5.8
CVE-2012-5785
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…
Axis2
after 1.6.2
MEDIUM 5.8
CVE-2012-5786
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that …
Cxf
after 2.6.17
HIGH 10.0
CVE-2012-0838EPSS 14%
Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to m…
Struts
after 2.2.3
MEDIUM 5.0
CVE-2012-0840EPSS 43%
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col…
Portable Runtime
after 1.4.5
HIGH 7.8
CVE-2011-5034EPSS 81%
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh…
Geronimo
after 2.2.1
MEDIUM 5.0
CVE-2011-3368EPSS 91%
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u…
HTTP Server
Patch available
MEDIUM 5.0
CVE-2011-1475EPSS 9%
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses…
Tomcat
Patch available
HIGH 7.5
CVE-2010-1632EPSS 22%
Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through …
Axis2
after 1.5.1
MEDIUM 5.0
CVE-2010-1587EPSS 78%
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash …
Activemq
Patch available
MEDIUM 5.0
CVE-2009-0033EPSS 10%
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, a…
Tomcat
Patch available
MEDIUM 5.0
CVE-2008-6504EPSS 36%
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly…
Struts
Patch available
HIGH 7.8
CVE-2008-4482
The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc…
Xerces C\+\+
after 2.8.0
MEDIUM 5.0
CVE-2007-1349EPSS 10%
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expressi…
Mod Perl
1.30+