All vulnerabilities
65 / 65
Sort
8.8
CVE-2021-24347CVE
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, ho…
2021-01-01
EPSS80.6%
pct 99
9.8
CVE-2018-9845DEB
Etherpad Lite before 1.6.4 is exploitable for admin access.
2018-01-01Pre-auth
EPSS77.2%
pct 98
5.6
CVE-2025-27636ANC
Bypass/Injection vulnerability in Apache Camel components under particular conditions.
This is…
2025-01-01Pre-auth
EPSS52.1%
pct 97
9.8
CVE-2020-12812CVE KEV
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and…
2020-01-01KEV
EPSS41.9%
pct 97
5.3
CVE-2022-22968DEB
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, th…
2022-01-01Pre-auth
EPSS20.5%
pct 95
6.5
CVE-2021-28323MSR
Windows DNS Information Disclosure Vulnerability
2021-01-01Microsoft
EPSS16.6%
pct 95
7.5
CVE-2007-3365CVE
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions…
2007-01-01Pre-auth
EPSS14.2%
pct 94
9.8
CVE-2001-0766CVE
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass acc…
2001-01-01Pre-auth
EPSS11.1%
pct 93
7.5
CVE-2003-0411CVE
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source…
2003-01-01Pre-auth
EPSS7.1%
pct 91
7.5
CVE-1999-0239CVE
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an …
1999-01-01Pre-auth
EPSS3.7%
pct 88
9.8
CVE-2023-3545CVE
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Window…
2023-01-01Pre-auth
EPSS3.0%
pct 86
7.5
CVE-2004-1083CVE
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manne…
2004-01-01Pre-auth
EPSS1.9%
pct 83
9.8
CVE-2005-0269CVE
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all…
2005-01-01Pre-auth
EPSS1.8%
pct 82
7.5
CVE-2000-0498CVE
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by reques…
2000-01-01Pre-auth
EPSS1.6%
pct 82
9.8
CVE-2002-1820CVE
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with…
2002-01-01Pre-auth
EPSS1.5%
pct 81
5.3
CVE-2024-38820DEB
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. Howev…
2024-01-01Pre-auth
EPSS1.5%
pct 81
7.5
CVE-2000-0499CVE
The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view …
2000-01-01Pre-auth
EPSS1.4%
pct 80
4.3
CVE-2025-4035DEB
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to…
2025-01-01Pre-auth
EPSS1.3%
pct 80
8.1
CVE-2024-55634DEB
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from…
2024-01-01
EPSS1.1%
pct 78
9.8
CVE-2002-2119CVE
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remot…
2002-01-01Pre-auth
EPSS1.1%
pct 78
8.8
CVE-2019-6289CVE
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execu…
2019-01-01
EPSS0.9%
pct 76
5.3
CVE-2018-8337MSR
A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly hand…
2018-01-01Microsoft
EPSS0.9%
pct 75
7.5
CVE-2021-45893CVE
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case…
2021-01-01Pre-auth
EPSS0.8%
pct 74
7.5
CVE-2001-0795CVE
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs…
2001-01-01Pre-auth
EPSS0.7%
pct 73
7.5
CVE-2000-0497CVE
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by req…
2000-01-01Pre-auth
EPSS0.7%
pct 73
9.8
CVE-2004-2214CVE
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions …
2004-01-01Pre-auth
EPSS0.6%
pct 70
9.8
CVE-2024-5699ANC
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not co…
2024-01-01Pre-auth
EPSS0.6%
pct 69
9.8
CVE-2022-29604CVE
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows …
2022-01-01Pre-auth
EPSS0.5%
pct 67
5.5
CVE-2017-8493MSR
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, …
2017-01-01Microsoft
EPSS0.5%
pct 67
7.8
CVE-2001-1238CVE
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters…
2001-01-01
EPSS0.5%
pct 67
9.8
CVE-2004-2154DEB
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows…
2004-01-01Pre-auth
EPSS0.5%
pct 65
7.5
CVE-2002-0485CVE
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments who…
2002-01-01Pre-auth
EPSS0.5%
pct 65
7.5
CVE-2024-23331DEB
Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny…
2024-01-01Pre-auth
EPSS0.5%
pct 65
5.3
CVE-2006-2759DEB
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a …
2006-01-01Pre-auth
EPSS0.4%
pct 61
4.9
CVE-2024-32879DEB
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, d…
2024-01-01
EPSS0.3%
pct 49
9.8
CVE-2025-59944ANC
Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-s…
2025-01-01Pre-auth
EPSS0.3%
pct 48
9.9
CVE-2026-40453ANC
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-va…
2026-01-01
EPSS0.2%
pct 45
6.5
CVE-2021-25920CVE
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creatin…
2021-01-01
EPSS0.2%
pct 45
5.3
CVE-2023-46218ANC
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed ba…
2023-01-01Pre-auth
EPSS0.2%
pct 44
8.3
CVE-2021-39155CVE
Istio is an open source platform for providing a uniform way to integrate microservices, manage…
2021-01-01Pre-auth
EPSS0.2%
pct 38
Select a vulnerability on the left to open the preview.