Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2016-3089
Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script …
Openmeetings
after 3.1.1
HIGH 8.8
CVE-2016-0760
Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re…
Sentry
Mitigation only
MEDIUM 5.4
CVE-2016-0782EPSS 6%
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users…
Activemq
No fix yet
MEDIUM 5.5
CVE-2016-5000
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external …
Poi
after 3.13
HIGH 7.8
CVE-2016-1513
The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute…
Openoffice
after 4.1.2
HIGH 8.8
CVE-2016-4469EPSS 8%
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of…
Archiva
after 1.3.9
HIGH 8.1
CVE-2016-5387EPSS 56%
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted clie…
HTTP Server
after 2.4.23
HIGH 7.5
CVE-2016-4974EPSS 6%
Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which …
Amqp 0 X Jms Client
after 6.0.3
HIGH 7.5
CVE-2016-4463EPSS 14%
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
Xerces C\+\+
after 3.1.3
HIGH 7.5
CVE-2016-4979EPSS 19%
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" direc…
HTTP Server
Patch available
MEDIUM 5.9
CVE-2016-1546EPSS 15%
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 con…
HTTP Server
Patch available
MEDIUM 5.3
CVE-2016-4465EPSS 10%
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n…
Struts
Mitigation only
CRITICAL 9.8
CVE-2016-4438EPSS 17%
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
Struts
Mitigation only
HIGH 7.5
CVE-2016-4433EPSS 10%
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted …
Struts
Mitigation only
HIGH 7.5
CVE-2016-4431EPSS 10%
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging …
Struts
Mitigation only
HIGH 8.8
CVE-2016-4430
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac…
Struts
Mitigation only
HIGH 7.5
CVE-2016-3092EPSS 36%
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.…
Tomcat
after 1.3.1
HIGH 8.2
CVE-2016-1182EPSS 26%
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to con…
Struts
Patch available
HIGH 8.1
CVE-2016-1181EPSS 13%
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to …
Struts
Patch available
HIGH 7.5
CVE-2015-0899EPSS 21%
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modi…
Struts
Patch available
HIGH 7.2
CVE-2016-2174
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ…
Ranger
Mitigation only
MEDIUM 6.5
CVE-2016-3085
Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl…
Cloudstack
No fix yet
MEDIUM 5.3
CVE-2016-3093EPSS 8%
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to ca…
Struts
after 3.0.11
CRITICAL 9.8
CVE-2016-3087EPSS 82%
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…
Struts
No fix yet
CRITICAL 9.8
CVE-2016-4437 KEVEPSS 93%
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code…
Aurora
0.18.1 / 1.2.5+
HIGH 8.1
CVE-2015-7611EPSS 69%
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v…
James Server
No fix yet
CRITICAL 9.1
CVE-2016-4432EPSS 8%
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons…
Qpid Broker J
6.0.3+
MEDIUM 5.9
CVE-2016-3094EPSS 8%
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a…
Qpid Broker J
after 6.0.2
CRITICAL 9.8
CVE-2016-3088 KEVEPSS 99%
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol…
Activemq
5.14.0+
HIGH 7.8
CVE-2016-2175
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XM…
Pdfbox
Patch available