Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2016-4433EPSS 10%
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted …
Struts
Mitigation only
HIGH 7.5
CVE-2016-4431EPSS 10%
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging …
Struts
Mitigation only
HIGH 8.8
CVE-2016-4430
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac…
Struts
Mitigation only
HIGH 7.2
CVE-2016-2174
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ…
Ranger
Mitigation only
MEDIUM 6.5
CVE-2016-3085
Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl…
Cloudstack
No fix yet
CRITICAL 9.8
CVE-2016-3087EPSS 81%
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…
Struts
No fix yet
HIGH 8.1
CVE-2015-7611EPSS 69%
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v…
James Server
No fix yet
MEDIUM 6.2
CVE-2015-1776
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk…
Hadoop
Mitigation only
HIGH 8.1
CVE-2015-5348EPSS 6%
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in C…
Camel
No fix yet
MEDIUM 6.1
CVE-2016-2162EPSS 8%
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to con…
Struts
Mitigation only
HIGH 7.8
CVE-2015-5349
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers …
Ldap Studio
Mitigation only
HIGH 8.8
CVE-2016-0735
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand…
Ranger
Mitigation only
MEDIUM 6.1
CVE-2016-0734EPSS 9%
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for rem…
Activemq
Mitigation only
HIGH 8.8
CVE-2016-0714EPSS 13%
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s…
Tomcat
Mitigation only
HIGH 8.8
CVE-2015-5351EPSS 10%
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a…
Tomcat
No fix yet
HIGH 8.1
CVE-2015-5346EPSS 11%
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are us…
Tomcat
No fix yet
HIGH 8.3
CVE-2015-7521EPSS 6%
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, …
Hive
No fix yet
HIGH 8.6
CVE-2015-5259EPSS 57%
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…
Subversion
Mitigation only
HIGH 8.4
CVE-2015-7430
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to…
Hadoop
Mitigation only
HIGH 7.3
CVE-2015-1836EPSS 7%
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o…
Hbase
Mitigation only
HIGH 7.3
CVE-2015-1772EPSS 7%
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.…
Hive
Mitigation only
MEDIUM 6.5
CVE-2015-3270
Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl…
Ambari
Mitigation only
MEDIUM 5.5
CVE-2015-1775
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users…
Ambari
Mitigation only
HIGH 7.5
CVE-2014-3612EPSS 7%
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att…
Activemq
Mitigation only
MEDIUM 5.0
CVE-2015-1830EPSS 84%
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows …
Activemq
No fix yet
HIGH 7.5
CVE-2015-1831EPSS 6%
The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unsp…
Struts
Mitigation only
MEDIUM 5.0
CVE-2015-0248EPSS 12%
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of …
Subversion
Mitigation only
HIGH 7.8
CVE-2015-0202EPSS 8%
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe…
Subversion
Mitigation only
HIGH 7.5
CVE-2015-0225EPSS 7%
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in…
Cassandra
No fix yet
MEDIUM 6.4
CVE-2014-0227EPSS 21%
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not pr…
Tomcat
Mitigation only