Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-1316
The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traver…
Ode
after 1.3.2
CRITICAL 9.8
CVE-2017-12627EPSS 8%
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…
Xerces C\+\+
3.2.1+
MEDIUM 5.9
CVE-2018-1304EPSS 17%
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 t…
Tomcat
after 9.0.4
MEDIUM 6.5
CVE-2018-1286
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny servi…
Openmeetings
after 4.0.1
HIGH 8.6
CVE-2017-5660
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issu…
Traffic Server
after 6.2.0
HIGH 7.5
CVE-2017-7671
There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can c…
Traffic Server
after 6.2.0
MEDIUM 6.1
CVE-2012-3536
Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a c…
Hupa
0.0.3+
CRITICAL 9.8
CVE-2017-15692
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce…
Geode
1.4.0+
HIGH 7.5
CVE-2017-15693
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t…
Geode
1.4.0+
HIGH 7.5
CVE-2017-15696
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration req…
Geode
after 1.3.0
MEDIUM 6.5
CVE-2018-1305EPSS 14%
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 …
Tomcat
after 8.5.27
HIGH 8.8
CVE-2013-0267
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user…
Vcl
2.3.2+
MEDIUM 6.5
CVE-2015-0203EPSS 9%
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message wi…
Qpid
after 0.30
MEDIUM 6.5
CVE-2009-4267
The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows p…
Juddi
Mitigation only
MEDIUM 6.5
CVE-2016-8750EPSS 5%
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly a…
Karaf
4.0.8+
MEDIUM 6.5
CVE-2017-15712
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici…
Oozie
Mitigation only
CRITICAL 9.8
CVE-2018-1287
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an at…
Jmeter
Mitigation only
MEDIUM 6.5
CVE-2017-15699
A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user mus…
Qpid Dispatch
Patch available
CRITICAL 9.8
CVE-2018-1297EPSS 10%
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …
Jmeter
Mitigation only
HIGH 8.8
CVE-2016-5397EPSS 7%
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe…
Thrift
after 0.9.3
HIGH 7.8
CVE-2016-8742
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…
Couchdb
No fix yet
HIGH 8.1
CVE-2018-1307
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data…
Juddi
after 3.3.4
MEDIUM 5.9
CVE-2018-1298
A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, …
Qpid Broker J
Mitigation only
HIGH 7.5
CVE-2018-1299
In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with A…
Allura
1.8.0+
CRITICAL 9.8
CVE-2016-6813EPSS 6%
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is a…
Cloudstack
after 4.8.1.0
HIGH 7.4
CVE-2017-3160
After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle o…
Cordova
6.1.2+
MEDIUM 5.9
CVE-2017-15698
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h…
Tomcat Native
after 1.2.14
MEDIUM 5.3
CVE-2017-15706EPSS 6%
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 inc…
Tomcat
after 8.5.23
HIGH 7.5
CVE-2017-12626EPSS 10%
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and m…
Poi
3.17+
MEDIUM 5.0
CVE-2017-15703
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den…
Nifi
after 1.4.0