Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-40438 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Apache resf (CVE-2021-40438)
SSRF in Apache resf (CVE-2021-40438). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41164 |
|
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
|
| CVE-2021-3572 |
|
Vulnerability in pypa (CVE-2021-3572)
vulnerability in pypa (CVE-2021-3572). Data can be tampered with by attackers.
|
| CVE-2020-2555 KEV |
|
[KEV] Unsafe Deserialization in Oracle multiple-products (CVE-2020-2555)
vulnerability in Oracle multiple-products (CVE-2020-2555). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2012-3152 KEV |
|
[KEV] Vulnerability in Oracle fusion-middleware (CVE-2012-3152)
vulnerability in Oracle fusion-middleware (CVE-2012-3152). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14871 KEV |
|
[KEV] Out-of-Bounds Write in Oracle solaris-and-zettabyte-file-system-zfs (CVE-2020-14871)
out-of-bounds write in Oracle solaris-and-zettabyte-file-system-zfs (CVE-2020-14871). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2015-4852 KEV |
|
[KEV] Unsafe Deserialization in Oracle weblogic-server (CVE-2015-4852)
vulnerability in Oracle weblogic-server (CVE-2015-4852). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14750 KEV |
|
[KEV] Vulnerability in Oracle weblogic-server (CVE-2020-14750)
vulnerability in Oracle weblogic-server (CVE-2020-14750). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14882 KEV |
|
[KEV] Vulnerability in Oracle weblogic-server (CVE-2020-14882)
vulnerability in Oracle weblogic-server (CVE-2020-14882). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14883 KEV |
|
[KEV] Vulnerability in Oracle weblogic-server (CVE-2020-14883)
vulnerability in Oracle weblogic-server (CVE-2020-14883). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41182 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41182)
cross-site scripting in jqueryui (CVE-2021-41182). Data can be tampered with by attackers. Exploitable via ``altField``.
|
| CVE-2021-41183 |
|
Cross-Site Scripting (XSS) in c (CVE-2021-41183)
cross-site scripting in c (CVE-2021-41183). Data can be tampered with by attackers.
|
| CVE-2021-41184 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41184)
cross-site scripting in jqueryui (CVE-2021-41184). Data can be tampered with by attackers.
|
| CVE-2021-35606 |
|
Vulnerability in c (CVE-2021-35606)
vulnerability in c (CVE-2021-35606). Confidential information can be exposed externally.
|
| CVE-2021-41617 |
|
Privilege Escalation in privilege-escalation (CVE-2021-41617)
vulnerability in privilege-escalation (CVE-2021-41617). Successful exploitation can lead to full system takeover.
|
| CVE-2021-40690 |
|
Information Disclosure in apache (CVE-2021-40690)
vulnerability in apache (CVE-2021-40690). Confidential information can be exposed externally.
|
| CVE-2021-2421 |
|
Vulnerability in c (CVE-2021-2421)
vulnerability in c (CVE-2021-2421). Confidential information can be exposed externally.
|
| CVE-2021-2351 |
|
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unau...
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Su...
|
| CVE-2021-22926 |
|
Vulnerability in haxx (CVE-2021-22926)
vulnerability in haxx (CVE-2021-22926). Risk of unauthorized operations or information disclosure. Exploitable via ``CURLOPT_SSLCERT``.
|
| CVE-2021-36373 |
|
Vulnerability in apache (CVE-2021-36373)
vulnerability in apache (CVE-2021-36373). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-36374 |
|
Vulnerability in apache (CVE-2021-36374)
vulnerability in apache (CVE-2021-36374). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-33037 |
|
Vulnerability in apache (CVE-2021-33037)
vulnerability in apache (CVE-2021-33037). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25122 |
|
Information Disclosure in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.43` or later.
|
| CVE-2021-3522 |
|
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
|
| CVE-2021-22897 |
|
Vulnerability in haxx (CVE-2021-22897)
vulnerability in haxx (CVE-2021-22897). Risk of unauthorized operations or information disclosure. Exploitable via ``CURLOPT_SSL_CIPHER_LIST``.
|
| CVE-2021-2316 |
|
Vulnerability in c (CVE-2021-2316)
vulnerability in c (CVE-2021-2316). Confidential information can be exposed externally.
|
| CVE-2021-29425 |
|
Vulnerability in apache (CVE-2021-29425)
vulnerability in apache (CVE-2021-29425). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25329 |
|
Vulnerability in apache (CVE-2021-25329)
vulnerability in apache (CVE-2021-25329). Successful exploitation can lead to full system takeover.
|
| CVE-2021-26117 |
|
Authentication Bypass in apache (CVE-2021-26117)
authentication bypass in apache (CVE-2021-26117). Data can be tampered with by attackers.
|
| CVE-2021-26271 |
|
Vulnerability in ckeditor (CVE-2021-26271)
vulnerability in ckeditor (CVE-2021-26271). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-26272 |
|
Vulnerability in ckeditor (CVE-2021-26272)
vulnerability in ckeditor (CVE-2021-26272). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-8554 |
|
Vulnerability in k8s.io/kubernetes (CVE-2020-8554)
vulnerability in k8s.io/kubernetes (CVE-2020-8554). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-20190 |
|
Unsafe Deserialization in fasterxml (CVE-2021-20190)
vulnerability in fasterxml (CVE-2021-20190). Successful exploitation can lead to full system takeover.
|
| CVE-2021-24122 |
|
Information Disclosure in apache (CVE-2021-24122)
vulnerability in apache (CVE-2021-24122). Confidential information can be exposed externally.
|
| CVE-2020-36183 |
|
Unsafe Deserialization in apache (CVE-2020-36183)
vulnerability in apache (CVE-2020-36183). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36179 |
|
Unsafe Deserialization in apache (CVE-2020-36179)
vulnerability in apache (CVE-2020-36179). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36180 |
|
Unsafe Deserialization in apache (CVE-2020-36180)
vulnerability in apache (CVE-2020-36180). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36182 |
|
Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36184 |
|
Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36185 |
|
Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36186 |
|
Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36187 |
|
Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36188 |
|
Unsafe Deserialization in fasterxml (CVE-2020-36188)
vulnerability in fasterxml (CVE-2020-36188). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36189 |
|
Unsafe Deserialization in fasterxml (CVE-2020-36189)
vulnerability in fasterxml (CVE-2020-36189). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36181 |
|
Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35728 |
|
Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35490 |
|
Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35491 |
|
Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1971 |
|
Vulnerability in dos (CVE-2020-1971)
vulnerability in dos (CVE-2020-1971). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-17521 |
|
Vulnerability in apache (CVE-2020-17521)
vulnerability in apache (CVE-2020-17521). Confidential information can be exposed externally.
|