Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-8029
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary …
Hadoop
after 3.1.0
MEDIUM 6.1
CVE-2019-0221EPSS 46%
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is…
Tomcat
after 9.0.17
HIGH 7.5
CVE-2019-0188EPSS 10%
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib lib…
Camel
2.24.0+
CRITICAL 9.8
CVE-2018-17198
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S…
Roller
after 5.1.2
MEDIUM 5.9
CVE-2019-0201EPSS 10%
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when…
Activemq
18.1.3.1.0 / 19.1.0.0.1+
MEDIUM 6.1
CVE-2019-10076
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacki…
Jspwiki
after 2.11.0
MEDIUM 6.1
CVE-2019-10077
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
Jspwiki
after 2.11.0
MEDIUM 6.1
CVE-2019-10078
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijac…
Jspwiki
after 2.11.0
CRITICAL 9.8
CVE-2013-7285EPSS 84%
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary…
Activemq
after 1.4.6
HIGH 7.5
CVE-2018-17201
Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note th…
Commons Imaging
Mitigation only
HIGH 7.5
CVE-2018-17202
Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be use…
Commons Imaging
Mitigation only
HIGH 7.5
CVE-2019-0227EPSS 92%
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits…
Axis
Patch available
MEDIUM 6.1
CVE-2018-8035
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which ru…
Uimaducc
after 2.2.2
MEDIUM 6.5
CVE-2019-0214
In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. E…
Archiva
after 2.2.3
HIGH 7.5
CVE-2019-0194EPSS 8%
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and ea…
Camel
after 2.22.2
MEDIUM 6.5
CVE-2019-0213
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerabili…
Archiva
2.2.4+
MEDIUM 6.1
CVE-2019-0186EPSS 21%
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uni…
Pluto
No fix yet
HIGH 7.4
CVE-2019-0223EPSS 6%
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its languag…
Qpid
after 0.27.0
HIGH 8.8
CVE-2018-1317
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentica…
Zeppelin
0.8.0+
HIGH 8.1
CVE-2017-12619
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reported by "st…
Zeppelin
0.7.3+
MEDIUM 6.1
CVE-2018-1328EPSS 6%
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".
Zeppelin
0.8.0+
MEDIUM 6.1
CVE-2019-0218EPSS 5%
A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.
Pony Mail
after 0.10
CRITICAL 9.8
CVE-2019-0228EPSS 9%
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…
Pdfbox
Mitigation only
HIGH 8.1
CVE-2019-0232EPSS 100%
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93…
Tomcat
after 9.0.17
HIGH 8.8
CVE-2019-0229
A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site reques…
Airflow
after 1.10.2
HIGH 7.5
CVE-2019-0199EPSS 73%
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also…
Tomcat
after 9.0.14
HIGH 7.8
CVE-2019-0211 KEVEPSS 65%
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads …
HTTP Server
after 2.4.38
HIGH 7.5
CVE-2019-0217EPSS 17%
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with val…
HTTP Server
after 2.4.38
HIGH 7.5
CVE-2019-0215EPSS 11%
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2019-0212
In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST ser…
Hbase
after 2.1.3