Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-12633EPSS 7%
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D…
Camel
2.19.4 / 2.20.1+
CRITICAL 9.8
CVE-2017-12634EPSS 7%
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De…
Camel
2.19.4+
CRITICAL 9.8
CVE-2017-12635EPSS 100%
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1…
Couchdb
1.7.0+
HIGH 7.2
CVE-2017-12636EPSS 90%
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-leve…
Couchdb
1.7.0+
MEDIUM 5.5
CVE-2017-12624
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment he…
Cxf
3.0.16 / 3.1.14+
HIGH 7.8
CVE-2016-6803
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The …
Openoffice
after 4.1.2
HIGH 7.8
CVE-2017-3166
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl…
Hadoop
Mitigation only
CRITICAL 9.8
CVE-2012-4449
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features ar…
Hadoop
after 0.23.3
CRITICAL 9.8
CVE-2013-4366
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a…
Httpclient
Patch available
CRITICAL 9.8
CVE-2014-0073EPSS 8%
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap…
Cordova In App Browser
after 2.9.0
HIGH 7.5
CVE-2014-0072EPSS 8%
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Tran…
Cordova File Transfer
after 2.9.0
MEDIUM 6.1
CVE-2012-5636
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers…
Wicket
Patch available
HIGH 7.5
CVE-2012-0881EPSS 17%
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML servi…
Xerces2 Java
after 2.11.0
HIGH 7.5
CVE-2014-0115EPSS 5%
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…
Storm
Patch available
MEDIUM 6.1
CVE-2009-1198
Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname par…
Juddi
2.0+
MEDIUM 5.3
CVE-2009-1197
Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.
Juddi
Mitigation only
CRITICAL 9.8
CVE-2014-3624
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request…
Traffic Server
Patch available
CRITICAL 9.8
CVE-2015-3249EPSS 5%
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…
Traffic Server
Mitigation only
HIGH 8.8
CVE-2013-4246
libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a…
Subversion
Patch available
HIGH 8.8
CVE-2016-3090EPSS 6%
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL e…
Struts
Mitigation only
HIGH 7.5
CVE-2014-3526
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors invo…
Wicket
1.5.12+
HIGH 7.5
CVE-2015-0224EPSS 15%
qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set. NOTE:…
Qpid
after 0.30
HIGH 7.5
CVE-2015-0226EPSS 6%
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message …
Wss4j
after 1.6.16
CRITICAL 9.8
CVE-2014-3579
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…
Activemq Apollo
Mitigation only
CRITICAL 9.8
CVE-2014-3600EPSS 10%
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…
Activemq
Mitigation only
MEDIUM 5.3
CVE-2015-1835EPSS 6%
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to …
Cordova
after 3.7.1
CRITICAL 9.8
CVE-2016-5003EPSS 15%
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…
Ws Xmlrpc
No fix yet
HIGH 7.8
CVE-2016-5002EPSS 8%
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co…
Xml Rpc
Mitigation only
CRITICAL 9.8
CVE-2012-1622EPSS 5%
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
Ofbiz
Mitigation only
HIGH 7.1
CVE-2017-12613
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, ou…
Portable Runtime
1.7.0+