Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2014-1884EPSS 8%
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allo…
Cordova
after 3.3.0
MEDIUM 5.8
CVE-2013-4310EPSS 7%
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
Struts
Patch available
HIGH 7.5
CVE-2013-1768EPSS 10%
The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d…
Openjpa
Mitigation only
MEDIUM 5.0
CVE-2012-5885EPSS 9%
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…
Tomcat
Mitigation only
HIGH 10.0
CVE-2012-4501EPSS 8%
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…
Cloudstack
Mitigation only
MEDIUM 5.0
CVE-2012-4387EPSS 8%
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processe…
Struts
Patch available
MEDIUM 5.0
CVE-2012-2138EPSS 14%
The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co…
Org.apache.sling.servlets.post
after 2.1.0
MEDIUM 5.0
CVE-2011-1184EPSS 9%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-5062EPSS 8%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-5057EPSS 29%
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req…
Struts
2.3.3+
MEDIUM 6.4
CVE-2012-0393EPSS 37%
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c…
Struts
2.3.1.1+
HIGH 7.5
CVE-2011-3190EPSS 15%
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other …
Tomcat
No fix yet
MEDIUM 5.0
CVE-2011-2729EPSS 7%
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33,…
Tomcat
Patch available
MEDIUM 6.5
CVE-2011-2329
The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration …
Rampart\/c
Patch available
MEDIUM 6.5
CVE-2008-2717
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al…
Apache Webserver
Mitigation only
MEDIUM 6.4
CVE-2007-5342EPSS 5%
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe…
Tomcat
Patch available