Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2015-5241
After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect…
Juddi
Mitigation only
HIGH 7.5
CVE-2016-8741EPSS 6%
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices…
Qpid Broker J
Mitigation only
MEDIUM 6.5
CVE-2017-5655
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary file…
Ambari
Mitigation only
HIGH 7.5
CVE-2017-5654
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on …
Ambari
Mitigation only
MEDIUM 5.9
CVE-2016-4467
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname m…
Qpid Proton
Mitigation only
CRITICAL 9.1
CVE-2017-5648EPSS 13%
While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0…
Tomcat
Mitigation only
HIGH 7.5
CVE-2017-5647EPSS 17%
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.…
Tomcat
Mitigation only
HIGH 7.5
CVE-2017-5650EPSS 8%
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated …
Tomcat
Mitigation only
CRITICAL 9.8
CVE-2017-5642
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
Ambari
Mitigation only
MEDIUM 5.5
CVE-2016-4976
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive informat…
Ambari
Mitigation only
CRITICAL 9.8
CVE-2016-6807
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that …
Ambari
Mitigation only
CRITICAL 9.8
CVE-2016-8749EPSS 11%
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
Camel
No fix yet
MEDIUM 6.5
CVE-2014-0229
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshN…
Hadoop
Mitigation only
HIGH 7.1
CVE-2016-6816EPSS 40%
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reque…
Tomcat
No fix yet
MEDIUM 5.4
CVE-2016-1566
Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by mult…
Guacamole
Mitigation only
CRITICAL 9.8
CVE-2015-3188EPSS 14%
The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.
Storm
No fix yet
MEDIUM 5.3
CVE-2015-3271EPSS 7%
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
Tika
Mitigation only
HIGH 8.8
CVE-2016-5393
In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary comm…
Hadoop
Mitigation only
HIGH 7.8
CVE-2016-6325
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig…
Tomcat
Mitigation only
HIGH 7.8
CVE-2016-5425
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions f…
Tomcat
No fix yet
CRITICAL 9.1
CVE-2015-1832EPSS 12%
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…
Derby
Mitigation only
CRITICAL 9.8
CVE-2016-4436EPSS 7%
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.
Struts
Mitigation only
HIGH 7.8
CVE-2016-1240EPSS 10%
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and …
Tomcat
No fix yet
CRITICAL 9.8
CVE-2016-4464
The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured…
Cxf Fediz
Mitigation only
HIGH 8.8
CVE-2016-6801
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x be…
Jackrabbit
Mitigation only
HIGH 7.5
CVE-2016-6802EPSS 10%
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Shiro
No fix yet
HIGH 8.8
CVE-2016-0760
Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re…
Sentry
Mitigation only
MEDIUM 5.4
CVE-2016-0782EPSS 6%
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users…
Activemq
No fix yet
MEDIUM 5.3
CVE-2016-4465EPSS 10%
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n…
Struts
Mitigation only
CRITICAL 9.8
CVE-2016-4438EPSS 17%
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
Struts
Mitigation only