Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-2099EPSS 7%
Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspe…
Xerces C\+\+
after 3.1.3
MEDIUM 5.3
CVE-2015-5207
Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by levera…
Cordova
after 3.9.1
MEDIUM 6.5
CVE-2016-2168EPSS 21%
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote…
Subversion
after 1.8.15
MEDIUM 6.8
CVE-2016-2167EPSS 7%
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication…
Subversion
after 1.8.15
CRITICAL 9.8
CVE-2016-3082EPSS 19%
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary …
Struts
Patch available
HIGH 8.1
CVE-2016-3081EPSS 93%
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…
Struts
Patch available
MEDIUM 6.2
CVE-2015-1776
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk…
Hadoop
Mitigation only
HIGH 8.1
CVE-2015-5348EPSS 6%
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in C…
Camel
No fix yet
HIGH 7.6
CVE-2015-5343EPSS 30%
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users t…
Subversion
1.8.15 / 1.9.3+
MEDIUM 6.1
CVE-2015-7520EPSS 5%
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15…
Wicket
1.5.15 / 6.22.0+
MEDIUM 6.1
CVE-2015-5347EPSS 8%
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow i…
Wicket
1.5.15 / 6.22.0+
MEDIUM 6.1
CVE-2016-4003EPSS 12%
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a singl…
Struts
after 2.3.24.1
MEDIUM 6.1
CVE-2016-2162EPSS 8%
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to con…
Struts
Mitigation only
HIGH 8.8
CVE-2016-0785EPSS 9%
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva…
Struts
2.3.20.3+
CRITICAL 9.8
CVE-2016-2170EPSS 13%
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java o…
Ofbiz
12.04.06 / 13.07.03+
MEDIUM 6.5
CVE-2016-2166
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 i…
Qpid Proton
after 0.12.0
CRITICAL 9.8
CVE-2016-0733
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by…
Ranger
after 0.5.0
MEDIUM 6.5
CVE-2015-5167
The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.
Ranger
after 0.5.0
MEDIUM 6.1
CVE-2015-3268EPSS 9%
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 1…
Ofbiz
Patch available
HIGH 7.8
CVE-2015-5349
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers …
Ldap Studio
Mitigation only
HIGH 8.8
CVE-2016-0735
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand…
Ranger
Mitigation only
HIGH 7.1
CVE-2015-0266
The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to mod…
Ranger
after 0.4.0.
MEDIUM 6.1
CVE-2015-0265
Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web scrip…
Ranger
after 0.4.0
HIGH 7.5
CVE-2016-2171EPSS 43%
The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to …
Jetspeed
after 2.3.0
HIGH 7.5
CVE-2016-2164EPSS 7%
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the…
Openmeetings
after 3.1.0
MEDIUM 6.1
CVE-2016-2163EPSS 8%
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the e…
Openmeetings
after 3.1.0
MEDIUM 6.5
CVE-2016-0784EPSS 56%
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated a…
Openmeetings
after 3.1.0
HIGH 7.5
CVE-2016-0783EPSS 7%
The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attacke…
Openmeetings
after 3.1.0
MEDIUM 6.1
CVE-2016-0712
Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_…
Jetspeed
after 2.3.0
MEDIUM 6.1
CVE-2016-0711
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via…
Jetspeed
after 2.3.0