All vulnerabilities
280 / 280
Sort
9.8
CVE-2024-23897DEB KEV
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI comman…
2024-01-01KEV
EPSS100.0%
pct 100
7.5
CVE-2023-44487ANC KEV
The HTTP/2 protocol allows a denial of service (server resource consumption) because request ca…
2023-01-01MicrosoftKEV
EPSS100.0%
pct 100
9.8
CVE-2021-44228DEB KEV
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) …
2021-01-01KEV
EPSS100.0%
pct 100
9.0
CVE-2021-40438AST KEV
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choos…
2021-01-01KEV
EPSS100.0%
pct 100
9.8
CVE-2017-9841DEB KEV
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers t…
2017-01-01KEV
EPSS100.0%
pct 100
9.8
CVE-2017-5638DEB KEV
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 h…
2017-01-01KEV
EPSS100.0%
pct 100
9.8
CVE-2014-6271DEB KEV
GNU Bash through 4.3 processes trailing strings after function definitions in the values of env…
2014-01-01KEV
EPSS100.0%
pct 100
7.5
CVE-2014-0160DEB KEV
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle …
2014-01-01KEV
EPSS100.0%
pct 100
9.8
CVE-2013-2251DEB KEV
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expression…
2013-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2012-1823DEB KEV
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI scrip…
2012-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2018-7600DEB KEV
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote …
2018-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2018-11776DEB KEV
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Executi…
2018-01-01KEV
EPSS100.0%
pct 99
7.5
CVE-2021-41773DEB KEV
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attack…
2021-01-01KEV
EPSS100.0%
pct 99
8.1
CVE-2017-12617DEB KEV
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and…
2017-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2024-4577ANC KEV
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache…
2024-01-01KEV
EPSS100.0%
pct 99
7.8
CVE-2021-22204AST KEV
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up a…
2021-01-01KEV
EPSS100.0%
pct 99
8.1
CVE-2021-45046DEB KEV
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in ce…
2021-01-01KEV
EPSS100.0%
pct 99
8.1
CVE-2021-42013DEB KEV
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An …
2021-01-01KEV
EPSS100.0%
pct 99
9.0
CVE-2019-10149AST KEV
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient ad…
2019-01-01KEV
EPSS100.0%
pct 99
9.1
CVE-2024-38475ANC KEV
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an a…
2024-01-01KEV
EPSS100.0%
pct 99
7.3
CVE-2021-39226DEB KEV
Grafana is an open source data visualization platform. In affected versions unauthenticated and…
2021-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2025-24813ANC KEV
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Informatio…
2025-01-01KEV
EPSS99.9%
pct 99
9.8
CVE-2014-7169DEB KEV
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function def…
2014-01-01KEV
EPSS99.9%
pct 99
6.5
CVE-2015-1427DEB KEV
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote …
2015-01-01KEV
EPSS99.9%
pct 99
9.8
CVE-2022-46169DEB KEV
Cacti is an open source platform which provides a robust and extensible operational monitoring …
2022-01-01KEV
EPSS99.8%
pct 99
9.8
CVE-2019-15107DEB KEV
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a …
2019-01-01KEV
EPSS99.8%
pct 99
9.6
CVE-2023-4863AST KEV
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allo…
2023-01-01KEV
EPSS99.7%
pct 99
10.0
CVE-2021-22205ANC KEV
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab …
2021-01-01KEV
EPSS99.7%
pct 99
9.8
CVE-2016-10033DEB KEV
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote att…
2016-01-01KEV
EPSS99.7%
pct 99
9.8
CVE-2020-13927DEB KEV
The previous default setting for Airflow's Experimental API was to allow all API requests witho…
2020-01-01KEV
EPSS99.7%
pct 99
8.1
CVE-2017-1000353DEB KEV
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauth…
2017-01-01KEV
EPSS99.7%
pct 99
8.1
CVE-2022-22965DEB KEV
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code e…
2022-01-01KEV
EPSS99.7%
pct 99
10.0
CVE-2022-0543DEB KEV
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is pr…
2022-01-01KEV
EPSS99.7%
pct 99
9.8
CVE-2023-46604DEB KEV
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerabili…
2023-01-01KEV
EPSS99.7%
pct 99
8.8
CVE-2014-6278DEB KEV
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of e…
2014-01-01KEV
EPSS99.6%
pct 99
8.1
CVE-2017-12615DEB KEV
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting …
2017-01-01KEV
EPSS99.6%
pct 99
9.8
CVE-2020-16846DEB KEV
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Sal…
2020-01-01KEV
EPSS99.6%
pct 99
9.8
CVE-2020-1472DEB KEV
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlog…
2020-01-01MicrosoftKEV
EPSS99.5%
pct 99
8.1
CVE-2019-11043AST KEV
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain config…
2019-01-01KEV
EPSS99.5%
pct 99
8.1
CVE-2017-9805DEB KEV
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses…
2017-01-01KEV
EPSS99.5%
pct 99
Select a vulnerability on the left to open the preview.