Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2014-8152EPSS 6%
Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a cr…
Santuario Xml Security For Java
Mitigation only
MEDIUM 5.0
CVE-2014-3583EPSS 11%
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause …
HTTP Server
Mitigation only
MEDIUM 6.8
CVE-2014-7809
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha…
Struts
No fix yet
MEDIUM 5.0
CVE-2014-7807
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, …
Cloudstack
Mitigation only
MEDIUM 5.0
CVE-2014-3627
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster u…
Hadoop
Mitigation only
HIGH 7.5
CVE-2014-0074EPSS 5%
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e…
Shiro
No fix yet
HIGH 10.0
CVE-2014-3525
Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors,…
Traffic Server
No fix yet
MEDIUM 5.0
CVE-2014-3503EPSS 6%
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via…
Syncope
No fix yet
MEDIUM 5.0
CVE-2014-0075EPSS 20%
Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.…
Tomcat
Mitigation only
MEDIUM 5.8
CVE-2014-0116EPSS 7%
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…
Struts
Mitigation only
MEDIUM 5.8
CVE-2013-4286EPSS 17%
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle c…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2013-2055
Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive…
Wicket
Mitigation only
MEDIUM 6.4
CVE-2012-5575EPSS 6%
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowe…
Cxf
Mitigation only
MEDIUM 5.8
CVE-2013-2248EPSS 95%
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond…
Struts
Mitigation only
HIGH 7.5
CVE-2013-1768EPSS 10%
The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d…
Openjpa
Mitigation only
MEDIUM 5.0
CVE-2013-1847EPSS 51%
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of se…
Subversion
Mitigation only
MEDIUM 5.0
CVE-2013-1884EPSS 51%
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault…
Subversion
Mitigation only
MEDIUM 5.0
CVE-2012-5885EPSS 9%
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2012-5886EPSS 9%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2012-2733EPSS 9%
java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not…
Tomcat
Mitigation only
HIGH 10.0
CVE-2012-4501EPSS 8%
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…
Cloudstack
Mitigation only
MEDIUM 6.4
CVE-2012-5351EPSS 5%
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur…
Axis2
Mitigation only
MEDIUM 5.8
CVE-2012-4418EPSS 6%
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
Axis2
No fix yet
MEDIUM 6.8
CVE-2012-4386
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote…
Struts
Mitigation only
HIGH 7.5
CVE-2012-3376
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B…
Hadoop
Mitigation only
HIGH 7.5
CVE-2011-3620EPSS 5%
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin…
Qpid
Mitigation only
MEDIUM 6.5
CVE-2012-1574
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i…
Hadoop
Mitigation only
MEDIUM 5.0
CVE-2012-1089EPSS 5%
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati…
Wicket
Mitigation only
MEDIUM 5.0
CVE-2011-3375EPSS 7%
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2012-0022EPSS 11%
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote…
Tomcat
Mitigation only