Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.4
CVE-2019-10091
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c…
Geode
Mitigation only
CRITICAL 10.0
CVE-2020-1953EPSS 7%
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…
Commons Configuration
Mitigation only
CRITICAL 9.8
CVE-2020-1947EPSS 34%
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …
Shardingsphere
Mitigation only
MEDIUM 6.5
CVE-2020-1932
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retr…
Superset
Mitigation only
MEDIUM 5.3
CVE-2020-1928
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose…
Nifi
Mitigation only
HIGH 7.5
CVE-2014-0212
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
Qpid Cpp
Mitigation only
HIGH 8.8
CVE-2012-1592EPSS 29%
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit…
Struts
Mitigation only
HIGH 7.8
CVE-2011-2177
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
Openoffice
Mitigation only
CRITICAL 9.8
CVE-2019-12409EPSS 22%
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…
Solr
No fix yet
MEDIUM 6.1
CVE-2019-10070
Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
Atlas
Mitigation only
MEDIUM 6.5
CVE-2009-5004
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
Qpid Cpp
Mitigation only
HIGH 7.5
CVE-2012-2945
Hadoop 1.0.3 contains a symlink vulnerability.
Hadoop
No fix yet
HIGH 7.5
CVE-2019-0231
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the cl…
Mina
Mitigation only
CRITICAL 9.8
CVE-2019-12405
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…
Traffic Control
Mitigation only
MEDIUM 6.1
CVE-2019-0234
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu…
Roller
Mitigation only
HIGH 7.5
CVE-2018-17201
Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note th…
Commons Imaging
Mitigation only
HIGH 7.5
CVE-2018-17202
Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be use…
Commons Imaging
Mitigation only
MEDIUM 6.1
CVE-2019-0186EPSS 21%
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uni…
Pluto
No fix yet
CRITICAL 9.8
CVE-2019-0228EPSS 9%
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…
Pdfbox
Mitigation only
HIGH 7.5
CVE-2019-0215EPSS 11%
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a…
HTTP Server
Mitigation only
CRITICAL 9.8
CVE-2019-0187
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a…
Jmeter
Mitigation only
HIGH 7.5
CVE-2019-0190EPSS 59%
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to e…
HTTP Server
Mitigation only
MEDIUM 5.3
CVE-2018-17189EPSS 20%
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unn…
HTTP Server
Mitigation only
CRITICAL 9.8
CVE-2018-17191EPSS 8%
Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the n…
Netbeans
Mitigation only
CRITICAL 9.8
CVE-2018-17190EPSS 9%
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos…
Spark
Mitigation only
HIGH 7.8
CVE-2018-14889
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
Couchdb
Mitigation only
MEDIUM 6.1
CVE-2016-4975EPSS 20%
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 …
HTTP Server
Mitigation only
HIGH 7.5
CVE-2018-8011EPSS 56%
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This coul…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2018-1306EPSS 44%
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive i…
Pluto
No fix yet
HIGH 7.5
CVE-2018-10583EPSS 79%
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co…
Openoffice
No fix yet