Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.9
CVE-2018-8023
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2…
Mesos
1.4.2+
MEDIUM 5.5
CVE-2018-8017
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Tika
after 1.18
HIGH 7.5
CVE-2018-11761EPSS 10%
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vuln…
Tika
after 1.18
MEDIUM 5.9
CVE-2018-11762EPSS 5%
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input …
Tika
after 1.18
HIGH 8.8
CVE-2018-11786
In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…
Karaf
4.2.0+
HIGH 8.1
CVE-2018-11787
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…
Karaf
3.0.9 / 4.0.9+
CRITICAL 9.8
CVE-2018-11780EPSS 11%
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
Spamassassin
3.4.2+
HIGH 7.8
CVE-2018-11781
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
Spamassassin
3.4.2+
MEDIUM 5.3
CVE-2017-15705EPSS 8%
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags…
Spamassassin
3.4.2+
MEDIUM 5.3
CVE-2018-8041EPSS 10%
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
Camel
after 2.21.1
HIGH 7.5
CVE-2018-1330
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked H…
Mesos
1.4.2 / 1.5.1+
HIGH 7.4
CVE-2018-11775EPSS 7%
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack bet…
Activemq
5.15.6+
HIGH 7.5
CVE-2018-8022EPSS 7%
A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users …
Traffic Server
after 6.2.2
MEDIUM 5.3
CVE-2018-8040EPSS 7%
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apa…
Traffic Server
after 7.1.3
HIGH 7.5
CVE-2018-1318EPSS 8%
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server …
Traffic Server
after 7.1.3
MEDIUM 6.5
CVE-2018-8004EPSS 6%
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This a…
Traffic Server
after 7.1.3
MEDIUM 5.3
CVE-2018-8005EPSS 7%
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance pro…
Traffic Server
after 7.1.3
CRITICAL 9.8
CVE-2011-2767EPSS 9%
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do…
Mod Perl
after 2.0.10
HIGH 8.8
CVE-2018-8028
An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker …
Sentry
2.0.1+
HIGH 8.1
CVE-2018-11758
This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shippe…
Cayenne
after 3.1.0
HIGH 8.1
CVE-2018-11776 KEVEPSS 100%
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by u…
Struts
2.3.35 / 2.5.17+
MEDIUM 5.5
CVE-2018-11771EPSS 5%
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the c…
Commons Compress
after 1.17.0
MEDIUM 6.1
CVE-2016-4975EPSS 20%
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 …
HTTP Server
Mitigation only
HIGH 7.2
CVE-2018-11769EPSS 8%
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied con…
Couchdb
2.2.0+
MEDIUM 6.1
CVE-2017-12614
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and p…
Airflow
1.9.0+
HIGH 7.5
CVE-2018-1336EPSS 21%
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Se…
Tomcat
after 9.0.7
MEDIUM 5.9
CVE-2018-8037EPSS 12%
If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that cou…
Tomcat
after 9.0.9
MEDIUM 6.1
CVE-2018-8032EPSS 11%
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Axis
after 1.4
HIGH 7.5
CVE-2018-8034EPSS 21%
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0…
Tomcat
after 9.0.9
CRITICAL 9.8
CVE-2018-8027EPSS 6%
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
Camel
after 2.20.3