Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-21962 KEV |
|
[KEV] Vulnerability in Oracle c (CVE-2026-21962)
vulnerability in Oracle c (CVE-2026-21962). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-60363 |
|
Vulnerability in c (CVE-2026-60363)
vulnerability in c (CVE-2026-60363). Successful exploitation can lead to full system takeover.
|
| CVE-2016-8735 KEV |
|
[KEV] Vulnerability in Apache tomcat (CVE-2016-8735)
vulnerability in Apache tomcat (CVE-2016-8735). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-34169 |
|
Vulnerability in apache (CVE-2022-34169)
vulnerability in apache (CVE-2022-34169). Data can be tampered with by attackers.
|
| CVE-2022-25762 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762)
vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.20` or later.
|
| CVE-2018-1273 KEV |
|
[KEV] Code Injection in Vmware tanzu vmware-tanzu (CVE-2018-1273)
code injection in Vmware tanzu vmware-tanzu (CVE-2018-1273). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2017-12617 KEV |
|
[KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12617)
vulnerability in Apache tomcat (CVE-2017-12617). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1938 KEV |
|
[KEV] Privilege Escalation in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `7.0.100` or later.
|
| CVE-2020-13935 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.105` or later.
|
| CVE-2020-13934 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5.56` or later.
|
| CVE-2022-23437 |
|
Vulnerability in apache (CVE-2022-23437)
vulnerability in apache (CVE-2022-23437). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-23305 |
|
SQL Injection in log4j:log4j (CVE-2022-23305)
SQL injection in log4j:log4j (CVE-2022-23305). Successful exploitation can lead to full system takeover.
|
| CVE-2022-23307 |
|
Unsafe Deserialization in apache (CVE-2022-23307)
vulnerability in apache (CVE-2022-23307). Successful exploitation can lead to full system takeover.
|
| CVE-2022-23302 |
|
Unsafe Deserialization in apache (CVE-2022-23302)
vulnerability in apache (CVE-2022-23302). Successful exploitation can lead to full system takeover.
|
| CVE-2021-44832 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.
|
| CVE-2021-45105 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.1` or later.
|
| CVE-2021-4104 |
|
Unsafe Deserialization in apache (CVE-2021-4104)
vulnerability in apache (CVE-2021-4104). Successful exploitation can lead to full system takeover.
|
| CVE-2021-40438 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Apache resf (CVE-2021-40438)
SSRF in Apache resf (CVE-2021-40438). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41164 |
|
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
|
| CVE-2021-41183 |
|
Cross-Site Scripting (XSS) in c (CVE-2021-41183)
cross-site scripting in c (CVE-2021-41183). Data can be tampered with by attackers.
|
| CVE-2021-41184 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41184)
cross-site scripting in jqueryui (CVE-2021-41184). Data can be tampered with by attackers.
|
| CVE-2021-41182 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41182)
cross-site scripting in jqueryui (CVE-2021-41182). Data can be tampered with by attackers. Exploitable via ``altField``.
|
| CVE-2021-40690 |
|
Information Disclosure in apache (CVE-2021-40690)
vulnerability in apache (CVE-2021-40690). Confidential information can be exposed externally.
|
| CVE-2021-36374 |
|
Vulnerability in apache (CVE-2021-36374)
vulnerability in apache (CVE-2021-36374). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-36373 |
|
Vulnerability in apache (CVE-2021-36373)
vulnerability in apache (CVE-2021-36373). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-33037 |
|
Vulnerability in apache (CVE-2021-33037)
vulnerability in apache (CVE-2021-33037). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25122 |
|
Information Disclosure in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.43` or later.
|
| CVE-2021-29425 |
|
Vulnerability in apache (CVE-2021-29425)
vulnerability in apache (CVE-2021-29425). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25329 |
|
Vulnerability in apache (CVE-2021-25329)
vulnerability in apache (CVE-2021-25329). Successful exploitation can lead to full system takeover.
|
| CVE-2021-26117 |
|
Authentication Bypass in apache (CVE-2021-26117)
authentication bypass in apache (CVE-2021-26117). Data can be tampered with by attackers.
|
| CVE-2021-20190 |
|
Unsafe Deserialization in fasterxml (CVE-2021-20190)
vulnerability in fasterxml (CVE-2021-20190). Successful exploitation can lead to full system takeover.
|
| CVE-2021-24122 |
|
Information Disclosure in apache (CVE-2021-24122)
vulnerability in apache (CVE-2021-24122). Confidential information can be exposed externally.
|
| CVE-2020-36183 |
|
Unsafe Deserialization in apache (CVE-2020-36183)
vulnerability in apache (CVE-2020-36183). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36179 |
|
Unsafe Deserialization in apache (CVE-2020-36179)
vulnerability in apache (CVE-2020-36179). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36180 |
|
Unsafe Deserialization in apache (CVE-2020-36180)
vulnerability in apache (CVE-2020-36180). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36182 |
|
Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36185 |
|
Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36186 |
|
Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36187 |
|
Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36184 |
|
Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36181 |
|
Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35728 |
|
Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35491 |
|
Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35490 |
|
Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
|
| CVE-2020-17521 |
|
Vulnerability in apache (CVE-2020-17521)
vulnerability in apache (CVE-2020-17521). Confidential information can be exposed externally.
|
| CVE-2020-25649 |
|
XXE (XML External Entity) in fasterxml (CVE-2020-25649)
vulnerability in fasterxml (CVE-2020-25649). Data can be tampered with by attackers.
|
| CVE-2020-14060 |
|
Unsafe Deserialization in apache (CVE-2020-14060)
vulnerability in apache (CVE-2020-14060). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14062 |
|
Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9484 |
|
Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
|
| CVE-2020-9488 |
|
Vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488)
vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.2` or later.
|