All vulnerabilities
34092 / 34092
Sort
9.8
CVE-2018-7600DEB KEV
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote …
2018-01-01KEV
EPSS94.5%
pct 99
7.5
CVE-2019-17558DEB KEV
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the Ve…
2019-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2022-46169DEB KEV
Cacti is an open source platform which provides a robust and extensible operational monitoring …
2022-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2019-2725CVE KEV
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent…
2019-01-01KEV
EPSS94.5%
pct 99
7.5
CVE-2020-3452CVE KEV
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Softwa…
2020-01-01KEV
EPSS94.5%
pct 99
9.8
CVE-2019-0604MSR KEV
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to…
2019-01-01MicrosoftKEV
EPSS94.4%
pct 99
9.8
CVE-2018-11776DEB KEV
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Executi…
2018-01-01KEV
EPSS94.4%
pct 99
7.5
CVE-2019-7609DEB KEV
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelio…
2019-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2017-7269CVE KEV
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Informat…
2017-01-01KEV
EPSS94.4%
pct 99
10.0
CVE-2020-0796MSR KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block…
2020-01-01MicrosoftKEV
EPSS94.4%
pct 99
9.8
CVE-2020-11651DEB KEV
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-mast…
2020-01-01KEV
EPSS94.4%
pct 99
7.5
CVE-2018-0296CVE KEV
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow…
2018-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2022-35914CVE KEV
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allow…
2022-01-01KEV
EPSS94.4%
pct 99
7.8
CVE-2017-11882MSR KEV
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 20…
2017-01-01MicrosoftKEV
EPSS94.4%
pct 99
8.1
CVE-2022-47966CVE KEV
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow r…
2022-01-01KEV
EPSS94.4%
pct 99
8.1
CVE-2020-17530DEB KEV
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote …
2020-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2021-44228DEB KEV
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) …
2021-01-01KEV
EPSS94.4%
pct 99
8.1
CVE-2017-12617DEB KEV
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and…
2017-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2023-36845CVE KEV
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX …
2023-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2019-11581CVE KEV
There was a server-side template injection vulnerability in Jira Server and Data Center, in the…
2019-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2023-22527CVE KEV
A template injection vulnerability on older versions of Confluence Data Center and Server allow…
2023-01-01KEV
EPSS94.4%
pct 99
9.3
CVE-2024-4879CVE KEV
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and…
2024-01-01KEV
EPSS94.3%
pct 99
7.5
CVE-2023-4966CVE KEV
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Ga…
2023-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2023-22515CVE KEV
Atlassian has been made aware of an issue reported by a handful of customers where external att…
2023-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2013-2251DEB KEV
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expression…
2013-01-01KEV
EPSS94.3%
pct 99
8.1
CVE-2017-9805DEB KEV
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses…
2017-01-01KEV
EPSS94.3%
pct 99
5.3
CVE-2023-36844CVE KEV
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX …
2023-01-01KEV
EPSS94.3%
pct 99
10.0
CVE-2024-3400CVE KEV
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect f…
2024-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2020-13942CVE
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint.…
2020-01-01Pre-auth
EPSS94.3%
pct 99
9.8
CVE-2017-3881CVE KEV
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and…
2017-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2020-9757CVE
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that le…
2020-01-01Pre-auth
EPSS94.3%
pct 99
9.8
CVE-2017-5638DEB KEV
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 h…
2017-01-01KEV
EPSS94.3%
pct 99
6.5
CVE-2020-11652DEB KEV
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-mast…
2020-01-01KEV
EPSS94.3%
pct 99
8.1
CVE-2017-9791DEB KEV
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a ma…
2017-01-01KEV
EPSS94.2%
pct 99
8.1
CVE-2017-12611DEB
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expressi…
2017-01-01Pre-auth
EPSS94.2%
pct 99
8.1
CVE-2017-12615DEB KEV
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting …
2017-01-01KEV
EPSS94.2%
pct 99
9.8
CVE-2025-24813ANC KEV
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Informatio…
2025-01-01KEV
EPSS94.2%
pct 99
9.8
CVE-2020-17496CVE KEV
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an…
2020-01-01KEV
EPSS94.2%
pct 99
9.2
CVE-2024-10915CVE
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It…
2024-01-01Pre-auth
EPSS94.2%
pct 99
3.7
CVE-2017-15715AST
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a …
2017-01-01Pre-auth
EPSS94.1%
pct 99
Select a vulnerability on the left to open the preview.