Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-12615 KEV |
|
[KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12615)
vulnerability in Apache tomcat (CVE-2017-12615). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1938 KEV |
|
[KEV] Privilege Escalation in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `7.0.100` or later.
|
| CVE-2017-9791 KEV |
|
[KEV] Vulnerability in Apache struts-1 (CVE-2017-9791)
vulnerability in Apache struts-1 (CVE-2017-9791). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3088 KEV |
|
[KEV] Vulnerability in Apache activemq (CVE-2016-3088)
vulnerability in Apache activemq (CVE-2016-3088). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-13935 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.105` or later.
|
| CVE-2020-13934 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5.56` or later.
|
| CVE-2022-23913 |
|
Vulnerability in org.apache.activemq:artemis-core-client (CVE-2022-23913)
vulnerability in org.apache.activemq:artemis-core-client (CVE-2022-23913). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.19.1` or later.
|
| CVE-2022-23437 |
|
Vulnerability in apache (CVE-2022-23437)
vulnerability in apache (CVE-2022-23437). Risk of unauthorized operations or information disclosure.
|
| CVE-2006-1547 KEV |
|
[KEV] Vulnerability in Apache struts-1 (CVE-2006-1547)
vulnerability in Apache struts-1 (CVE-2006-1547). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2012-0391 KEV |
|
[KEV] Vulnerability in Apache struts-2 (CVE-2012-0391)
vulnerability in Apache struts-2 (CVE-2012-0391). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-23302 |
|
Unsafe Deserialization in apache (CVE-2022-23302)
vulnerability in apache (CVE-2022-23302). Successful exploitation can lead to full system takeover.
|
| CVE-2022-23307 |
|
Unsafe Deserialization in apache (CVE-2022-23307)
vulnerability in apache (CVE-2022-23307). Successful exploitation can lead to full system takeover.
|
| CVE-2022-23305 |
|
SQL Injection in log4j:log4j (CVE-2022-23305)
SQL injection in log4j:log4j (CVE-2022-23305). Successful exploitation can lead to full system takeover.
|
| CVE-2020-13671 KEV |
|
[KEV] Unrestricted File Upload in drupal (CVE-2020-13671)
vulnerability in drupal (CVE-2020-13671). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11978 KEV |
|
[KEV] OS Command Injection in Apache airflow (CVE-2020-11978)
OS command injection in Apache airflow (CVE-2020-11978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-13927 KEV |
|
[KEV] Vulnerability in Apache airflows-experimental-api (CVE-2020-13927)
vulnerability in Apache airflows-experimental-api (CVE-2020-13927). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-44832 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.
|
| CVE-2021-45105 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.1` or later.
|
| CVE-2021-4104 |
|
Unsafe Deserialization in apache (CVE-2021-4104)
vulnerability in apache (CVE-2021-4104). Successful exploitation can lead to full system takeover.
|
| CVE-2019-0193 KEV |
|
[KEV] Code Injection in Apache solr (CVE-2019-0193)
code injection in Apache solr (CVE-2019-0193). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-44228 KEV |
|
[KEV] Vulnerability in Apache log4j2 (CVE-2021-44228)
vulnerability in Apache log4j2 (CVE-2021-44228). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-40438 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Apache resf (CVE-2021-40438)
SSRF in Apache resf (CVE-2021-40438). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-24713 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2021-24713)
cross-site scripting in wordpress (CVE-2021-24713). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-41164 |
|
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
|
| CVE-2020-25213 KEV |
|
[KEV] Unrestricted File Upload in Wordpress file-manager-plugin (CVE-2020-25213)
vulnerability in Wordpress file-manager-plugin (CVE-2020-25213). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11738 KEV |
|
[KEV] Path Traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738)
path traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-9978 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Wordpress social-warfare-plugin (CVE-2019-9978)
cross-site scripting in Wordpress social-warfare-plugin (CVE-2019-9978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-7600 KEV |
|
[KEV] Vulnerability in drupal (CVE-2018-7600)
vulnerability in drupal (CVE-2018-7600). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-9805 KEV |
|
[KEV] Unsafe Deserialization in Apache struts (CVE-2017-9805)
vulnerability in Apache struts (CVE-2017-9805). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17530 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2020-17530)
vulnerability in Apache struts (CVE-2020-17530). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-5638 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2017-5638)
vulnerability in Apache struts (CVE-2017-5638). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-11776 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2018-11776)
vulnerability in Apache struts (CVE-2018-11776). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42013 KEV |
|
[KEV] Path Traversal in Apache http-server (CVE-2021-42013)
path traversal in Apache http-server (CVE-2021-42013). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41773 KEV |
|
[KEV] Path Traversal in Apache http-server (CVE-2021-41773)
path traversal in Apache http-server (CVE-2021-41773). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0211 KEV |
|
[KEV] Use-After-Free in Apache http-server (CVE-2019-0211)
vulnerability in Apache http-server (CVE-2019-0211). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-4437 KEV |
|
[KEV] Vulnerability in Apache shiro (CVE-2016-4437)
vulnerability in Apache shiro (CVE-2016-4437). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-17558 KEV |
|
[KEV] Vulnerability in Apache solr (CVE-2019-17558)
vulnerability in Apache solr (CVE-2019-17558). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41182 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41182)
cross-site scripting in jqueryui (CVE-2021-41182). Data can be tampered with by attackers. Exploitable via ``altField``.
|
| CVE-2021-41183 |
|
Cross-Site Scripting (XSS) in c (CVE-2021-41183)
cross-site scripting in c (CVE-2021-41183). Data can be tampered with by attackers.
|
| CVE-2021-41184 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41184)
cross-site scripting in jqueryui (CVE-2021-41184). Data can be tampered with by attackers.
|
| CVE-2021-40690 |
|
Information Disclosure in apache (CVE-2021-40690)
vulnerability in apache (CVE-2021-40690). Confidential information can be exposed externally.
|
| CVE-2021-36373 |
|
Vulnerability in apache (CVE-2021-36373)
vulnerability in apache (CVE-2021-36373). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-36374 |
|
Vulnerability in apache (CVE-2021-36374)
vulnerability in apache (CVE-2021-36374). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-33037 |
|
Vulnerability in apache (CVE-2021-33037)
vulnerability in apache (CVE-2021-33037). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25122 |
|
Information Disclosure in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.43` or later.
|
| CVE-2021-29425 |
|
Vulnerability in apache (CVE-2021-29425)
vulnerability in apache (CVE-2021-29425). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-29238 |
|
Vulnerability in nginx (CVE-2020-29238)
vulnerability in nginx (CVE-2020-29238). Confidential information can be exposed externally.
|
| CVE-2021-25329 |
|
Vulnerability in apache (CVE-2021-25329)
vulnerability in apache (CVE-2021-25329). Successful exploitation can lead to full system takeover.
|
| CVE-2021-26117 |
|
Authentication Bypass in apache (CVE-2021-26117)
authentication bypass in apache (CVE-2021-26117). Data can be tampered with by attackers.
|
| CVE-2021-26118 |
|
Vulnerability in org.apache.activemq:artemis-openwire-protocol (CVE-2021-26118)
vulnerability in org.apache.activemq:artemis-openwire-protocol (CVE-2021-26118). Data can be tampered with by attackers. Mitigation: upgrade to `2.16.0` or later.
|