Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-8015
In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug …
Orc
after 1.4.3
CRITICAL 9.8
CVE-2018-8014EPSS 22%
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are ins…
Tomcat
after 9.0.8
MEDIUM 5.3
CVE-2018-1313
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose lo…
Derby
after 10.14.1.0
MEDIUM 5.3
CVE-2018-8003
Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request whic…
Ambari
after 2.6.1
HIGH 7.5
CVE-2018-10583EPSS 79%
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co…
Openoffice
No fix yet
MEDIUM 6.5
CVE-2017-15691EPSS 9%
In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache ui…
Uimaj
2.2.2 / 2.4.0+
HIGH 8.1
CVE-2018-1335EPSS 94%
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the com…
Tika
1.18+
MEDIUM 5.5
CVE-2018-1338
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Tika
1.18+
MEDIUM 5.5
CVE-2018-1339
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Tika
1.18+
CRITICAL 9.8
CVE-2018-1290
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para…
Fineract
Mitigation only
HIGH 8.8
CVE-2018-1289
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain…
Fineract
Mitigation only
HIGH 8.1
CVE-2018-1291
Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with …
Fineract
Mitigation only
HIGH 8.1
CVE-2018-1292
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u…
Fineract
Mitigation only
HIGH 7.5
CVE-2018-1308EPSS 21%
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` …
Solr
after 7.2.1
CRITICAL 9.1
CVE-2018-1282EPSS 6%
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup th…
Hive
after 2.3.2
CRITICAL 9.8
CVE-2018-1295EPSS 6%
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i…
Ignite
after 2.3.0
HIGH 7.5
CVE-2018-1327EPSS 9%
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with special…
Struts
after 2.5.14.1
CRITICAL 9.8
CVE-2018-1312EPSS 16%
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…
HTTP Server
Mitigation only
HIGH 8.1
CVE-2017-15715EPSS 86%
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than…
HTTP Server
after 2.4.29
HIGH 7.5
CVE-2017-15710EPSS 18%
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La…
HTTP Server
No fix yet
HIGH 7.5
CVE-2018-1303EPSS 70%
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing…
HTTP Server
after 2.4.29
MEDIUM 5.9
CVE-2018-1301EPSS 15%
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is re…
HTTP Server
after 2.4.29
MEDIUM 5.9
CVE-2018-1302EPSS 13%
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially…
HTTP Server
after 2.4.29
MEDIUM 5.3
CVE-2018-1283EPSS 10%
In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a r…
HTTP Server
after 2.4.29
HIGH 7.5
CVE-2018-1294
If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input co…
Commons Email
after 1.4
HIGH 7.2
CVE-2018-1321EPSS 18%
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and …
Syncope
1.2.11 / 2.0.8+
MEDIUM 5.5
CVE-2018-1324
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and Z…
Commons Compress
after 8.0.27
MEDIUM 6.1
CVE-2018-1319
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted…
Allura
after 1.8.0
HIGH 7.5
CVE-2018-1323EPSS 46%
The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-…
Tomcat Jk Connector
after 1.2.42
HIGH 7.5
CVE-2017-12174EPSS 6%
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when rec…
Artemis
2.4.0+