Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2016-2099EPSS 7% Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspe… Xerces C\+\+ after 3.1.3 Fix from $2,3002016-05-13 MEDIUM 5.3 CVE-2015-5207 Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by levera… Cordova after 3.9.1 Fix from $1,6002016-05-09 MEDIUM 6.5 CVE-2016-2168EPSS 21% The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote… Subversion after 1.8.15 Fix from $1,6002016-05-05 MEDIUM 6.8 CVE-2016-2167EPSS 7% The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication… Subversion after 1.8.15 Fix from $1,6002016-05-05 CRITICAL 9.8 CVE-2016-3082EPSS 19% XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary … Struts Patch available Fix from $2,3002016-04-26 HIGH 8.1 CVE-2016-3081EPSS 93% Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec… Struts Patch available Fix from $1,9502016-04-26 MEDIUM 6.2 CVE-2015-1776 Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk… Hadoop Mitigation only Fix from $1,6002016-04-19 HIGH 8.1 CVE-2015-5348EPSS 6% Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in C… Camel No fix yet Fix from $1,9502016-04-15 HIGH 7.6 CVE-2015-5343EPSS 30% Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users t… Subversion 1.8.15 / 1.9.3+ Fix from $1,9502016-04-14 MEDIUM 6.1 CVE-2015-7520EPSS 5% Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15… Wicket 1.5.15 / 6.22.0+ Fix from $1,6002016-04-12 MEDIUM 6.1 CVE-2015-5347EPSS 8% Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow i… Wicket 1.5.15 / 6.22.0+ Fix from $1,6002016-04-12 MEDIUM 6.1 CVE-2016-4003EPSS 12% Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a singl… Struts after 2.3.24.1 Fix from $1,6002016-04-12 MEDIUM 6.1 CVE-2016-2162EPSS 8% Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to con… Struts Mitigation only Fix from $1,6002016-04-12 HIGH 8.8 CVE-2016-0785EPSS 9% Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva… Struts 2.3.20.3+ Fix from $1,9502016-04-12 CRITICAL 9.8 CVE-2016-2170EPSS 13% Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java o… Ofbiz 12.04.06 / 13.07.03+ Fix from $2,3002016-04-12 MEDIUM 6.5 CVE-2016-2166 The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 i… Qpid Proton after 0.12.0 Fix from $1,6002016-04-12 CRITICAL 9.8 CVE-2016-0733 The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by… Ranger after 0.5.0 Fix from $2,3002016-04-12 MEDIUM 6.5 CVE-2015-5167 The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API. Ranger after 0.5.0 Fix from $1,6002016-04-12 MEDIUM 6.1 CVE-2015-3268EPSS 9% Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 1… Ofbiz Patch available Fix from $1,6002016-04-12 HIGH 7.8 CVE-2015-5349 The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers … Ldap Studio Mitigation only Fix from $1,9502016-04-11 HIGH 8.8 CVE-2016-0735 Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand… Ranger Mitigation only Fix from $1,9502016-04-11 HIGH 7.1 CVE-2015-0266 The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to mod… Ranger after 0.4.0. Fix from $1,9502016-04-11 MEDIUM 6.1 CVE-2015-0265 Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web scrip… Ranger after 0.4.0 Fix from $1,6002016-04-11 HIGH 7.5 CVE-2016-2171EPSS 43% The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to … Jetspeed after 2.3.0 Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-2164EPSS 7% The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the… Openmeetings after 3.1.0 Fix from $1,9502016-04-11 MEDIUM 6.1 CVE-2016-2163EPSS 8% Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the e… Openmeetings after 3.1.0 Fix from $1,6002016-04-11 MEDIUM 6.5 CVE-2016-0784EPSS 56% Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated a… Openmeetings after 3.1.0 Fix from $1,6002016-04-11 HIGH 7.5 CVE-2016-0783EPSS 7% The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attacke… Openmeetings after 3.1.0 Fix from $1,9502016-04-11 MEDIUM 6.1 CVE-2016-0712 Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_… Jetspeed after 2.3.0 Fix from $1,6002016-04-11 MEDIUM 6.1 CVE-2016-0711 Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via… Jetspeed after 2.3.0 Fix from $1,6002016-04-11