Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 9.3
CVE-2014-3524EPSS 15%
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…
Openoffice
4.1.1 / 4.2.6+
HIGH 10.0
CVE-2014-3525
Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors,…
Traffic Server
No fix yet
MEDIUM 5.8
CVE-2014-3577EPSS 9%
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify …
Httpclient
after 4.3.4
MEDIUM 5.0
CVE-2014-3523EPSS 16%
Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when …
HTTP Server
Patch available
MEDIUM 6.8
CVE-2014-0226EPSS 86%
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buff…
HTTP Server
2.2.29 / 2.4.10+
MEDIUM 5.0
CVE-2014-0231EPSS 44%
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of ser…
HTTP Server
2.2.29 / 2.4.10+
MEDIUM 5.0
CVE-2014-3503EPSS 6%
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via…
Syncope
No fix yet
MEDIUM 5.0
CVE-2011-4367EPSS 33%
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allo…
Myfaces
after 2.1.5
MEDIUM 5.0
CVE-2014-0075EPSS 20%
Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2014-0095EPSS 8%
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread c…
Tomcat
Patch available
MEDIUM 5.0
CVE-2013-2758EPSS 6%
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable se…
Cloudstack
Patch available
MEDIUM 5.0
CVE-2013-2756EPSS 6%
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa…
Cloudstack
Patch available
MEDIUM 6.8
CVE-2012-5649EPSS 7%
Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, relat…
Couchdb
after 1.0.3
MEDIUM 5.8
CVE-2014-0116EPSS 7%
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…
Struts
Mitigation only
HIGH 7.5
CVE-2014-0114EPSS 96%
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commo…
Commons Beanutils
after 1.9.1
MEDIUM 5.0
CVE-2013-7372
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.…
Harmony
after 6.0
HIGH 7.5
CVE-2014-0112EPSS 98%
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani…
Struts
2.3.16.2+
HIGH 7.5
CVE-2014-0113EPSS 78%
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method…
Struts
2.3.16.2+
MEDIUM 6.5
CVE-2014-0111
Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Co…
Syncope
1.0.9 / 1.1.7+
HIGH 7.5
CVE-2014-0107EPSS 14%
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en…
Xalan Java
after 2.7.1
MEDIUM 5.0
CVE-2013-5704EPSS 60%
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the…
HTTP Server
Patch available
HIGH 7.5
CVE-2014-0050EPSS 83%
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c…
Commons Fileupload
after 1.3
MEDIUM 5.0
CVE-2014-2668EPSS 22%
Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.
Couchdb
after 1.5.0
HIGH 7.5
CVE-2014-0002EPSS 33%
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns…
Camel
after 2.11.3
HIGH 7.5
CVE-2014-0003EPSS 7%
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit…
Camel
after 2.11.3
MEDIUM 5.0
CVE-2012-5641EPSS 9%
Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1…
Couchdb
after 2.3.2
MEDIUM 5.0
CVE-2013-6438EPSS 27%
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace charac…
HTTP Server
2.2.27 / 2.4.9+
MEDIUM 5.0
CVE-2014-0098EPSS 26%
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a de…
HTTP Server
2.2.27 / 2.4.9+
MEDIUM 5.0
CVE-2014-0094EPSS 100%
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is …
Struts
2.3.16.1+
HIGH 7.5
CVE-2012-6637EPSS 9%
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote a…
Cordova
after 3.3.0