V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
Filters

All vulnerabilities

5482 / 5482
Preset: exploit×Has exploit×CAPEC: CAPEC-7×Clear all
9.8
CVE-2017-8917CVE
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary…
2017-01-01Pre-auth
EPSS94.5%
pct 99
9.8
CVE-2018-7600DEB KEV
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote …
2018-01-01KEV
EPSS94.5%
pct 99
7.5
CVE-2019-17558DEB KEV
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the Ve…
2019-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2022-46169DEB KEV
Cacti is an open source platform which provides a robust and extensible operational monitoring …
2022-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2024-6670CVE KEV
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unau…
2024-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2019-2725CVE KEV
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent…
2019-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2018-11776DEB KEV
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Executi…
2018-01-01KEV
EPSS94.4%
pct 99
7.5
CVE-2019-7609DEB KEV
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelio…
2019-01-01KEV
EPSS94.4%
pct 99
7.5
CVE-2020-3452CVE KEV
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Softwa…
2020-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2019-0604MSR KEV
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to…
2019-01-01MicrosoftKEV
EPSS94.4%
pct 99
7.5
CVE-2018-0296CVE KEV
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow…
2018-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2022-35914CVE KEV
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allow…
2022-01-01KEV
EPSS94.4%
pct 99
8.1
CVE-2017-12617DEB KEV
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and…
2017-01-01KEV
EPSS94.4%
pct 99
8.1
CVE-2022-47966CVE KEV
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow r…
2022-01-01KEV
EPSS94.4%
pct 99
8.1
CVE-2020-17530DEB KEV
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote …
2020-01-01KEV
EPSS94.4%
pct 99
7.5
CVE-2014-3704DEB
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 doe…
2014-01-01
EPSS94.4%
pct 99
9.8
CVE-2021-44228DEB KEV
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) …
2021-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2023-36845CVE KEV
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX …
2023-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2019-11581CVE KEV
There was a server-side template injection vulnerability in Jira Server and Data Center, in the…
2019-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2023-22527CVE KEV
A template injection vulnerability on older versions of Confluence Data Center and Server allow…
2023-01-01KEV
EPSS94.4%
pct 99
9.3
CVE-2024-4879CVE KEV
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and…
2024-01-01KEV
EPSS94.3%
pct 99
7.5
CVE-2019-7481CVE KEV
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauth…
2019-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2023-22515CVE KEV
Atlassian has been made aware of an issue reported by a handful of customers where external att…
2023-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2013-2251DEB KEV
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expression…
2013-01-01KEV
EPSS94.3%
pct 99
8.1
CVE-2017-9805DEB KEV
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses…
2017-01-01KEV
EPSS94.3%
pct 99
10.0
CVE-2024-3400CVE KEV
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect f…
2024-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2020-13942CVE
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint.…
2020-01-01Pre-auth
EPSS94.3%
pct 99
9.2
CVE-2024-9465CVE KEV
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attac…
2024-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2017-3881CVE KEV
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and…
2017-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2017-5638DEB KEV
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 h…
2017-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2020-10220CVE
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection…
2020-01-01Pre-auth
EPSS94.3%
pct 99
9.8
CVE-2023-34362CVE KEV
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 202…
2023-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2020-11651DEB KEV
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-mast…
2020-01-01KEV
EPSS94.2%
pct 99
8.1
CVE-2017-12615DEB KEV
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting …
2017-01-01KEV
EPSS94.2%
pct 99
8.1
CVE-2017-12611DEB
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expressi…
2017-01-01Pre-auth
EPSS94.2%
pct 99
5.3
CVE-2023-36844CVE KEV
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX …
2023-01-01KEV
EPSS94.2%
pct 99
5.9
CVE-2019-0232DEB
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9…
2019-01-01Pre-auth
EPSS94.2%
pct 99
9.8
CVE-2020-17496CVE KEV
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an…
2020-01-01KEV
EPSS94.2%
pct 99
9.8
CVE-2025-24813ANC KEV
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Informatio…
2025-01-01KEV
EPSS94.1%
pct 99
8.1
CVE-2017-9791DEB KEV
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a ma…
2017-01-01KEV
EPSS94.1%
pct 99
Select a vulnerability on the left to open the preview.