Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2021-33036
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar…
Hadoop
2.10.2 / 3.2.3+
HIGH 8.8
CVE-2021-27644
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so…
Dolphinscheduler
1.3.6+
MEDIUM 6.5
CVE-2020-13922
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter…
Dolphinscheduler
Mitigation only
HIGH 8.8
CVE-2013-0267
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user…
Vcl
2.3.2+
HIGH 7.8
CVE-2016-8742
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…
Couchdb
No fix yet
HIGH 7.8
CVE-2016-6804
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that a…
Openoffice
4.1.3+
CRITICAL 9.8
CVE-2014-0073EPSS 8%
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap…
Cordova In App Browser
after 2.9.0
HIGH 8.8
CVE-2016-6811
In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Hadoop
after 2.7.3
MEDIUM 6.5
CVE-2014-0229
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshN…
Hadoop
Mitigation only
CRITICAL 9.8
CVE-2015-3188EPSS 14%
The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.
Storm
No fix yet
HIGH 7.8
CVE-2016-6325
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig…
Tomcat
Mitigation only
MEDIUM 6.5
CVE-2015-5167
The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.
Ranger
after 0.5.0
HIGH 8.8
CVE-2016-0735
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand…
Ranger
Mitigation only
HIGH 7.1
CVE-2015-0266
The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to mod…
Ranger
after 0.4.0.
HIGH 7.5
CVE-2016-2171EPSS 43%
The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to …
Jetspeed
after 2.3.0
HIGH 8.8
CVE-2016-0714EPSS 13%
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s…
Tomcat
Mitigation only
HIGH 8.4
CVE-2015-7430
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to…
Hadoop
Mitigation only
MEDIUM 6.5
CVE-2015-3270
Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl…
Ambari
Mitigation only
HIGH 7.5
CVE-2014-3576EPSS 13%
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of s…
Activemq
after 5.10.0
MEDIUM 5.0
CVE-2015-0227EPSS 8%
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors …
Wss4j
after 1.6.16
MEDIUM 5.0
CVE-2015-0223EPSS 7%
Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related…
Qpid
after 0.30
MEDIUM 5.8
CVE-2014-0116EPSS 7%
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…
Struts
Mitigation only
HIGH 7.5
CVE-2014-0112EPSS 98%
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani…
Struts
2.3.16.2+
HIGH 7.5
CVE-2014-0113EPSS 78%
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method…
Struts
2.3.16.2+
HIGH 7.5
CVE-2014-0107EPSS 14%
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en…
Xalan Java
after 2.7.1
HIGH 7.5
CVE-2014-0050EPSS 83%
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c…
Commons Fileupload
after 1.3
HIGH 7.5
CVE-2014-0002EPSS 33%
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns…
Camel
after 2.11.3
HIGH 7.5
CVE-2014-0003EPSS 7%
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit…
Camel
after 2.11.3
HIGH 7.5
CVE-2014-1881EPSS 11%
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…
Cordova
after 3.3.0
HIGH 7.5
CVE-2014-1882EPSS 12%
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…
Cordova
after 3.3.0