Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2013-2249EPSS 14%
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considerin…
HTTP Server
after 2.4.4
CRITICAL 9.8
CVE-2013-2251 KEVEPSS 100%
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi…
Archiva
1.3.8+
MEDIUM 5.8
CVE-2013-2248EPSS 95%
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond…
Struts
Mitigation only
HIGH 9.3
CVE-2013-2134EPSS 70%
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly …
Struts
2.3.14.3+
HIGH 9.3
CVE-2013-2135EPSS 14%
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" an…
Struts
2.3.14.3+
HIGH 10.0
CVE-2013-1777EPSS 10%
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o…
Geronimo
Patch available
HIGH 7.5
CVE-2013-1768EPSS 10%
The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d…
Openjpa
Mitigation only
HIGH 9.3
CVE-2013-1965EPSS 94%
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a cr…
Struts
2.3.14.1+
HIGH 9.3
CVE-2013-1966EPSS 74%
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …
Struts
2.3.14.1+
HIGH 8.1
CVE-2013-2115EPSS 75%
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …
Struts
after 2.3.14.1
MEDIUM 5.1
CVE-2013-1862EPSS 25%
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable char…
HTTP Server
2.0.65 / 2.2.25+
MEDIUM 6.8
CVE-2013-2067EPSS 7%
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x befor…
Tomcat
Patch available
MEDIUM 5.0
CVE-2012-3544EPSS 11%
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attac…
Tomcat
Patch available
MEDIUM 5.0
CVE-2013-1847EPSS 51%
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of se…
Subversion
Mitigation only
MEDIUM 5.0
CVE-2013-1884EPSS 51%
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault…
Subversion
Mitigation only
MEDIUM 6.4
CVE-2013-3060EPSS 6%
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau…
Activemq
after 5.7.0
MEDIUM 5.0
CVE-2012-6551EPSS 8%
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of servic…
Activemq
after 5.7.0
MEDIUM 5.8
CVE-2013-0253
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof …
Maven
Patch available
MEDIUM 5.0
CVE-2012-4458EPSS 7%
The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via …
Qpid
after 0.20
MEDIUM 5.0
CVE-2012-4459EPSS 9%
Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of s…
Qpid
after 0.20
MEDIUM 5.0
CVE-2012-4460
The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial o…
Qpid
after 0.20
MEDIUM 6.8
CVE-2012-4446
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t…
Qpid
after 0.20
MEDIUM 5.8
CVE-2012-5633EPSS 8%
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu…
Cxf
after 2.5.7
MEDIUM 5.0
CVE-2013-0239
Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att…
Cxf
after 2.5.8
HIGH 10.0
CVE-2012-2379
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 pol…
Cxf
Patch available
MEDIUM 5.0
CVE-2012-4557EPSS 17%
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-pr…
HTTP Server
Patch available
MEDIUM 5.0
CVE-2012-5568EPSS 10%
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowlo…
Tomcat
after 7.0.105
MEDIUM 5.0
CVE-2012-5885EPSS 9%
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2012-5886EPSS 9%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2012-5887EPSS 12%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly…
Tomcat
5.5.36 / 6.0.36+