Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2016-0710EPSS 52%
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL co…
Jetspeed
after 2.3.0
HIGH 7.2
CVE-2016-0709EPSS 77%
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticate…
Jetspeed
after 2.3.0
MEDIUM 6.1
CVE-2016-0734EPSS 9%
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for rem…
Activemq
Mitigation only
HIGH 8.8
CVE-2016-0714EPSS 13%
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s…
Tomcat
Mitigation only
HIGH 8.8
CVE-2015-5351EPSS 10%
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a…
Tomcat
No fix yet
HIGH 8.1
CVE-2015-5346EPSS 11%
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are us…
Tomcat
No fix yet
MEDIUM 6.1
CVE-2015-8797
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows rem…
Solr
after 5.3
MEDIUM 6.1
CVE-2015-8796
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers…
Solr
after 5.2.1
MEDIUM 6.1
CVE-2015-8795
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script o…
Solr
after 5.0
HIGH 7.5
CVE-2016-0956EPSS 46%
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen…
Sling
Patch available
CRITICAL 9.8
CVE-2015-3252
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain ac…
Cloudstack
after 4.5.1
CRITICAL 9.8
CVE-2015-5344EPSS 7%
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted…
Camel
after 2.15.4
HIGH 8.3
CVE-2015-7521EPSS 6%
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, …
Hive
No fix yet
HIGH 8.6
CVE-2015-5259EPSS 57%
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…
Subversion
Mitigation only
HIGH 8.4
CVE-2015-7430
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to…
Hadoop
Mitigation only
HIGH 7.3
CVE-2015-1836EPSS 7%
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o…
Hbase
Mitigation only
HIGH 7.3
CVE-2015-1772EPSS 7%
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.…
Hive
Mitigation only
CRITICAL 9.8
CVE-2015-6420EPSS 18%
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and…
Commons Collections
3.2.2+
MEDIUM 5.0
CVE-2015-8320
Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge h…
Cordova
after 3.6.4
MEDIUM 6.8
CVE-2015-5212EPSS 9%
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the docu…
Openoffice
after 4.4.4
MEDIUM 5.8
CVE-2015-5210
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…
Ambari
after 2.1.1
MEDIUM 6.5
CVE-2015-3270
Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl…
Ambari
Mitigation only
MEDIUM 5.5
CVE-2015-1775
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users…
Ambari
Mitigation only
HIGH 7.5
CVE-2014-3612EPSS 7%
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att…
Activemq
Mitigation only
HIGH 7.8
CVE-2014-1972EPSS 10%
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attac…
Tapestry
after 5.3.5
MEDIUM 5.0
CVE-2015-1830EPSS 84%
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows …
Activemq
No fix yet
HIGH 7.5
CVE-2014-3576EPSS 13%
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of s…
Activemq
after 5.10.0
CRITICAL 9.8
CVE-2015-3253EPSS 41%
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause…
Groovy
Patch available
MEDIUM 5.0
CVE-2015-3184EPSS 11%
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous a…
Subversion
after 7.2.1
MEDIUM 5.0
CVE-2015-3183EPSS 73%
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attacke…
HTTP Server
2.2.31 / 2.4.16+