Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2010-2232
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
Derby
Patch available
HIGH 7.8
CVE-2017-12628
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex…
James Server
after 3.0.0
CRITICAL 9.8
CVE-2017-5636
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…
Nifi
Mitigation only
HIGH 7.5
CVE-2017-5635
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin…
Nifi
Mitigation only
MEDIUM 5.4
CVE-2016-8748
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an au…
Nifi
after 1.0.0
HIGH 8.8
CVE-2016-4461EPSS 8%
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva…
Struts
2.3.29+
MEDIUM 6.5
CVE-2016-8734EPSS 6%
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack…
Subversion
Mitigation only
CRITICAL 9.8
CVE-2017-12629EPSS 92%
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li…
Solr
after 7.0.1
MEDIUM 6.5
CVE-2016-6815
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Ranger
Mitigation only
CRITICAL 9.8
CVE-2016-8736
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
Openmeetings
3.1.2+
MEDIUM 6.5
CVE-2017-12623
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f…
Nifi
Mitigation only
HIGH 7.5
CVE-2017-5637EPSS 73%
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead…
Zookeeper
Mitigation only
CRITICAL 9.8
CVE-2014-0030EPSS 17%
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Roller
No fix yet
MEDIUM 6.5
CVE-2017-9792
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt…
Impala
Mitigation only
HIGH 8.1
CVE-2017-12617 KEVEPSS 100%
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…
Tomcat
7.0.82 / 8.0.47+
MEDIUM 6.5
CVE-2017-9797
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send m…
Geode
after 1.2.0
CRITICAL 9.8
CVE-2017-12620
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…
Opennlp
No fix yet
HIGH 8.8
CVE-2016-6806
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. …
Wicket
Mitigation only
MEDIUM 5.3
CVE-2014-0043
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla…
Wicket
Mitigation only
HIGH 7.8
CVE-2016-4434
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En…
Tika
Mitigation only
HIGH 7.5
CVE-2017-7687
When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x befo…
Mesos
after 1.1.2
HIGH 7.5
CVE-2017-9790
When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1…
Mesos
after 1.1.2
CRITICAL 9.8
CVE-2017-12621EPSS 9%
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used …
Commons Jelly
1.0.1+
MEDIUM 6.1
CVE-2015-5169EPSS 8%
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
Struts
after 2.3.16.3
CRITICAL 9.8
CVE-2016-6795EPSS 8%
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for…
Struts
Mitigation only
CRITICAL 9.8
CVE-2017-12611EPSS 87%
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can …
Struts
Patch available
HIGH 7.5
CVE-2017-9793EPSS 9%
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allo…
Struts
Patch available
HIGH 7.5
CVE-2017-9804EPSS 8%
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is us…
Struts
Patch available
MEDIUM 5.9
CVE-2016-8738
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to …
Struts
Patch available
HIGH 8.1
CVE-2017-12615 KEVEPSS 100%
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t…
Tomcat
after 7.0.79