Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.0
CVE-2014-9593
Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
Cloudstack
after 4.3.1
MEDIUM 5.0
CVE-2013-4295EPSS 12%
The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an externa…
Shindig
Patch available
MEDIUM 5.0
CVE-2011-3375EPSS 7%
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2011-2088EPSS 6%
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive informati…
Struts
Patch available
MEDIUM 5.0
CVE-2010-2791EPSS 8%
mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2010-2068EPSS 16%
mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in cer…
HTTP Server
Patch available
MEDIUM 5.0
CVE-2007-5333EPSS 63%
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5…
Tomcat
after 6.0.14
MEDIUM 5.0
CVE-2007-2353EPSS 28%
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i…
Axis
No fix yet
HIGH 7.8
CVE-2005-4836
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remot…
Tomcat
No fix yet
MEDIUM 5.0
CVE-2005-4849
Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b)…
Derby
after 10.1.1.0