Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2017-9796
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut…
Geode
1.3.0+
HIGH 7.5
CVE-2012-3353
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con…
Sling Jcr Contentloader
Mitigation only
HIGH 8.8
CVE-2017-15700
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the…
Sling Authentication Service
Mitigation only
MEDIUM 5.5
CVE-2017-3157
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from …
Openoffice
after 4.1.3
HIGH 7.5
CVE-2014-3526
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors invo…
Wicket
1.5.12+
MEDIUM 6.5
CVE-2017-9797
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send m…
Geode
after 1.2.0
MEDIUM 5.3
CVE-2014-0043
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla…
Wicket
Mitigation only
HIGH 7.5
CVE-2017-12616EPSS 71%
When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs …
Tomcat
Mitigation only
HIGH 7.5
CVE-2015-3250EPSS 5%
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
Directory Ldap Api
after 1.0.0
CRITICAL 9.8
CVE-2016-3086
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM…
Hadoop
Mitigation only
MEDIUM 5.5
CVE-2016-5001
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A lo…
Hadoop
after 2.6.3
HIGH 7.5
CVE-2017-3154
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
Atlas
Mitigation only
HIGH 7.5
CVE-2011-4343EPSS 5%
Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL express…
Myfaces
Patch available
HIGH 7.5
CVE-2017-7683
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.
Openmeetings
Mitigation only
CRITICAL 9.1
CVE-2017-9788EPSS 57%
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…
HTTP Server
after 2.4.26
HIGH 7.5
CVE-2017-7686
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality…
Ignite
Mitigation only
HIGH 7.5
CVE-2016-8741EPSS 6%
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices…
Qpid Broker J
Mitigation only
MEDIUM 6.5
CVE-2017-5655
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary file…
Ambari
Mitigation only
HIGH 7.5
CVE-2017-5647EPSS 17%
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.…
Tomcat
Mitigation only
HIGH 7.5
CVE-2017-5649
Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUST…
Geode
after 1.1.0
MEDIUM 5.5
CVE-2016-4976
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive informat…
Ambari
Mitigation only
HIGH 7.5
CVE-2016-8747EPSS 7%
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11Inpu…
Tomcat
8.5.10+
MEDIUM 5.3
CVE-2015-3271EPSS 7%
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
Tika
Mitigation only
MEDIUM 6.2
CVE-2015-1776
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk…
Hadoop
Mitigation only
MEDIUM 6.5
CVE-2016-2166
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 i…
Qpid Proton
after 0.12.0
HIGH 7.5
CVE-2016-2164EPSS 7%
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the…
Openmeetings
after 3.1.0
HIGH 7.5
CVE-2016-0783EPSS 7%
The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attacke…
Openmeetings
after 3.1.0
HIGH 7.5
CVE-2016-0956EPSS 46%
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen…
Sling
Patch available
MEDIUM 5.0
CVE-2015-3184EPSS 11%
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous a…
Subversion
after 7.2.1
MEDIUM 5.0
CVE-2014-8111EPSS 7%
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to acce…
Tomcat Connectors
after 1.2.40