Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2018-1290
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para…
Fineract
Mitigation only
HIGH 8.8
CVE-2018-1289
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain…
Fineract
Mitigation only
HIGH 8.1
CVE-2018-1291
Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with …
Fineract
Mitigation only
HIGH 8.1
CVE-2018-1292
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u…
Fineract
Mitigation only
CRITICAL 9.8
CVE-2018-1312EPSS 16%
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2017-15710EPSS 18%
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La…
HTTP Server
No fix yet
MEDIUM 6.5
CVE-2009-4267
The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows p…
Juddi
Mitigation only
MEDIUM 6.5
CVE-2017-15712
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici…
Oozie
Mitigation only
CRITICAL 9.8
CVE-2018-1287
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an at…
Jmeter
Mitigation only
CRITICAL 9.8
CVE-2018-1297EPSS 10%
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …
Jmeter
Mitigation only
HIGH 7.8
CVE-2016-8742
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…
Couchdb
No fix yet
MEDIUM 5.9
CVE-2018-1298
A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, …
Qpid Broker J
Mitigation only
CRITICAL 9.8
CVE-2017-15718
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Application…
Hadoop
Mitigation only
HIGH 7.5
CVE-2012-3353
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con…
Sling Jcr Contentloader
Mitigation only
CRITICAL 9.8
CVE-2017-15714
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code …
Ofbiz
No fix yet
HIGH 8.8
CVE-2017-15700
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the…
Sling Authentication Service
Mitigation only
HIGH 8.8
CVE-2017-5663
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissio…
Fineract
Mitigation only
CRITICAL 9.8
CVE-2017-15708EPSS 18%
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases…
Synapse
Mitigation only
HIGH 7.8
CVE-2017-3166
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl…
Hadoop
Mitigation only
MEDIUM 5.3
CVE-2009-1197
Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.
Juddi
Mitigation only
CRITICAL 9.8
CVE-2015-3249EPSS 5%
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…
Traffic Server
Mitigation only
HIGH 8.8
CVE-2016-3090EPSS 6%
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL e…
Struts
Mitigation only
CRITICAL 9.8
CVE-2014-3579
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…
Activemq Apollo
Mitigation only
CRITICAL 9.8
CVE-2014-3600EPSS 10%
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…
Activemq
Mitigation only
CRITICAL 9.8
CVE-2016-5003EPSS 15%
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…
Ws Xmlrpc
No fix yet
HIGH 7.8
CVE-2016-5002EPSS 8%
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co…
Xml Rpc
Mitigation only
CRITICAL 9.8
CVE-2012-1622EPSS 5%
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
Ofbiz
Mitigation only
CRITICAL 9.8
CVE-2017-5636
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…
Nifi
Mitigation only
HIGH 7.5
CVE-2017-5635
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin…
Nifi
Mitigation only
MEDIUM 6.5
CVE-2016-8734EPSS 6%
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack…
Subversion
Mitigation only