Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2015-0253EPSS 15%
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows …
HTTP Server
Patch available
HIGH 7.5
CVE-2015-1831EPSS 6%
The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unsp…
Struts
Mitigation only
HIGH 7.8
CVE-2014-0230EPSS 20%
Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishin…
Tomcat
Patch available
MEDIUM 5.0
CVE-2015-0264EPSS 7%
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remo…
Camel
after 2.13.3
MEDIUM 5.0
CVE-2015-0263EPSS 8%
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x befor…
Camel
after 2.13.3
MEDIUM 6.4
CVE-2015-1833EPSS 51%
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before …
Jackrabbit
after 2.0.5
MEDIUM 5.0
CVE-2014-8111EPSS 7%
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to acce…
Tomcat Connectors
after 1.2.40
MEDIUM 5.0
CVE-2015-0248EPSS 12%
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of …
Subversion
Mitigation only
HIGH 7.8
CVE-2015-0202EPSS 8%
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe…
Subversion
Mitigation only
HIGH 7.5
CVE-2015-0225EPSS 7%
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in…
Cassandra
No fix yet
MEDIUM 5.0
CVE-2015-2091
The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is …
Mod Gnutls
after 0.5.1
HIGH 7.5
CVE-2015-0254EPSS 13%
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSL…
Standard Taglibs
after 1.2.1
MEDIUM 5.0
CVE-2015-0228EPSS 19%
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a de…
HTTP Server
after 2.4.12
MEDIUM 6.4
CVE-2014-0227EPSS 21%
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not pr…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2015-0227EPSS 8%
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors …
Wss4j
after 1.6.16
MEDIUM 5.0
CVE-2015-0223EPSS 7%
Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related…
Qpid
after 0.30
MEDIUM 5.0
CVE-2014-8152EPSS 6%
Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a cr…
Santuario Xml Security For Java
Mitigation only
MEDIUM 5.0
CVE-2014-9593
Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
Cloudstack
after 4.3.1
MEDIUM 5.0
CVE-2014-10022EPSS 6%
Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.
Traffic Server
after 5.1.1
MEDIUM 5.0
CVE-2014-3583EPSS 11%
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause …
HTTP Server
Mitigation only
MEDIUM 6.8
CVE-2014-7809
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha…
Struts
No fix yet
MEDIUM 5.0
CVE-2014-7807
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, …
Cloudstack
Mitigation only
MEDIUM 5.0
CVE-2014-3627
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster u…
Hadoop
Mitigation only
MEDIUM 6.4
CVE-2014-3500
Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.
Cordova
after 3.5.0
MEDIUM 5.0
CVE-2014-3584EPSS 7%
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service …
Cxf
after 2.6.10
MEDIUM 5.0
CVE-2014-3623EPSS 9%
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does …
Wss4j
1.6.17 / 2.0.2+
MEDIUM 5.0
CVE-2014-3581EPSS 14%
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote atta…
HTTP Server
Patch available
HIGH 7.5
CVE-2014-0074EPSS 5%
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e…
Shiro
No fix yet
MEDIUM 6.8
CVE-2013-4444EPSS 14%
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JM…
Tomcat
after 7.0.39
MEDIUM 5.8
CVE-2014-3596EPSS 9%
The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Nam…
Axis
after 1.4