Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2016-3089
Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script …
Openmeetings
after 3.1.1
MEDIUM 5.4
CVE-2016-0782EPSS 6%
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users…
Activemq
No fix yet
MEDIUM 6.1
CVE-2015-7520EPSS 5%
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15…
Wicket
1.5.15 / 6.22.0+
MEDIUM 6.1
CVE-2015-5347EPSS 8%
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow i…
Wicket
1.5.15 / 6.22.0+
MEDIUM 6.1
CVE-2016-4003EPSS 12%
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a singl…
Struts
after 2.3.24.1
MEDIUM 6.1
CVE-2016-2162EPSS 8%
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to con…
Struts
Mitigation only
MEDIUM 6.1
CVE-2015-3268EPSS 9%
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 1…
Ofbiz
Patch available
MEDIUM 6.1
CVE-2015-0265
Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web scrip…
Ranger
after 0.4.0
MEDIUM 6.1
CVE-2016-2163EPSS 8%
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the e…
Openmeetings
after 3.1.0
MEDIUM 6.1
CVE-2016-0712
Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_…
Jetspeed
after 2.3.0
MEDIUM 6.1
CVE-2016-0711
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via…
Jetspeed
after 2.3.0
MEDIUM 6.1
CVE-2015-8797
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows rem…
Solr
after 5.3
MEDIUM 6.1
CVE-2015-8796
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers…
Solr
after 5.2.1
MEDIUM 6.1
CVE-2015-8795
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script o…
Solr
after 5.0
MEDIUM 6.8
CVE-2010-4408
Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password …
Archiva
Mitigation only
MEDIUM 6.1
CVE-2007-4465EPSS 26%
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is no…
HTTP Server
2.0.61 / 2.2.6+