Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2022-25762 Vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762)
vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.20` or later.
CVE-2018-7602 KEV [KEV] Code Injection in Drupal core (CVE-2018-7602)
code injection in Drupal core (CVE-2018-7602). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2019-6340 KEV [KEV] Unsafe Deserialization in Drupal core (CVE-2019-6340)
vulnerability in Drupal core (CVE-2019-6340). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2016-0752 KEV [KEV] Path Traversal in rails (CVE-2016-0752)
path traversal in rails (CVE-2016-0752). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2014-0130 KEV [KEV] Path Traversal in rails (CVE-2014-0130)
path traversal in rails (CVE-2014-0130). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2013-2251 KEV [KEV] Vulnerability in Apache struts (CVE-2013-2251)
vulnerability in Apache struts (CVE-2013-2251). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-1956 KEV [KEV] OS Command Injection in Apache kylin (CVE-2020-1956)
OS command injection in Apache kylin (CVE-2020-1956). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-1273 KEV [KEV] Code Injection in Vmware tanzu vmware-tanzu (CVE-2018-1273)
code injection in Vmware tanzu vmware-tanzu (CVE-2018-1273). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2017-12617 KEV [KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12617)
vulnerability in Apache tomcat (CVE-2017-12617). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2017-12615 KEV [KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12615)
vulnerability in Apache tomcat (CVE-2017-12615). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-1938 KEV [KEV] Privilege Escalation in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `7.0.100` or later.
CVE-2017-9791 KEV [KEV] Vulnerability in Apache struts-1 (CVE-2017-9791)
vulnerability in Apache struts-1 (CVE-2017-9791). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2016-3088 KEV [KEV] Vulnerability in Apache activemq (CVE-2016-3088)
vulnerability in Apache activemq (CVE-2016-3088). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-13935 Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.105` or later.
CVE-2020-13934 Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5.56` or later.
CVE-2022-23913 Vulnerability in org.apache.activemq:artemis-core-client (CVE-2022-23913)
vulnerability in org.apache.activemq:artemis-core-client (CVE-2022-23913). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.19.1` or later.
CVE-2022-23437 Vulnerability in apache (CVE-2022-23437)
vulnerability in apache (CVE-2022-23437). Risk of unauthorized operations or information disclosure.
CVE-2006-1547 KEV [KEV] Vulnerability in Apache struts-1 (CVE-2006-1547)
vulnerability in Apache struts-1 (CVE-2006-1547). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2012-0391 KEV [KEV] Vulnerability in Apache struts-2 (CVE-2012-0391)
vulnerability in Apache struts-2 (CVE-2012-0391). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2022-23302 Unsafe Deserialization in apache (CVE-2022-23302)
vulnerability in apache (CVE-2022-23302). Successful exploitation can lead to full system takeover.
CVE-2022-23307 Unsafe Deserialization in apache (CVE-2022-23307)
vulnerability in apache (CVE-2022-23307). Successful exploitation can lead to full system takeover.
CVE-2022-23305 SQL Injection in log4j:log4j (CVE-2022-23305)
SQL injection in log4j:log4j (CVE-2022-23305). Successful exploitation can lead to full system takeover.
CVE-2020-13671 KEV [KEV] Unrestricted File Upload in drupal (CVE-2020-13671)
vulnerability in drupal (CVE-2020-13671). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-11978 KEV [KEV] OS Command Injection in Apache airflow (CVE-2020-11978)
OS command injection in Apache airflow (CVE-2020-11978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-13927 KEV [KEV] Vulnerability in Apache airflows-experimental-api (CVE-2020-13927)
vulnerability in Apache airflows-experimental-api (CVE-2020-13927). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-44832 Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.
CVE-2021-45105 Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.1` or later.
CVE-2021-4104 Unsafe Deserialization in apache (CVE-2021-4104)
vulnerability in apache (CVE-2021-4104). Successful exploitation can lead to full system takeover.
CVE-2019-0193 KEV [KEV] Code Injection in Apache solr (CVE-2019-0193)
code injection in Apache solr (CVE-2019-0193). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-44228 KEV [KEV] Vulnerability in Apache log4j2 (CVE-2021-44228)
vulnerability in Apache log4j2 (CVE-2021-44228). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-40438 KEV [KEV] SSRF (Server-Side Request Forgery) in Apache resf (CVE-2021-40438)
SSRF in Apache resf (CVE-2021-40438). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-24713 Cross-Site Scripting (XSS) in wordpress (CVE-2021-24713)
cross-site scripting in wordpress (CVE-2021-24713). Risk of unauthorized operations or information disclosure.
CVE-2021-41164 Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
CVE-2020-25213 KEV [KEV] Unrestricted File Upload in Wordpress file-manager-plugin (CVE-2020-25213)
vulnerability in Wordpress file-manager-plugin (CVE-2020-25213). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-11738 KEV [KEV] Path Traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738)
path traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-9978 KEV [KEV] Cross-Site Scripting (XSS) in Wordpress social-warfare-plugin (CVE-2019-9978)
cross-site scripting in Wordpress social-warfare-plugin (CVE-2019-9978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-7600 KEV [KEV] Vulnerability in drupal (CVE-2018-7600)
vulnerability in drupal (CVE-2018-7600). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2017-9805 KEV [KEV] Unsafe Deserialization in Apache struts (CVE-2017-9805)
vulnerability in Apache struts (CVE-2017-9805). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-17530 KEV [KEV] Vulnerability in Apache struts (CVE-2020-17530)
vulnerability in Apache struts (CVE-2020-17530). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2017-5638 KEV [KEV] Vulnerability in Apache struts (CVE-2017-5638)
vulnerability in Apache struts (CVE-2017-5638). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2018-11776 KEV [KEV] Vulnerability in Apache struts (CVE-2018-11776)
vulnerability in Apache struts (CVE-2018-11776). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-42013 KEV [KEV] Path Traversal in Apache http-server (CVE-2021-42013)
path traversal in Apache http-server (CVE-2021-42013). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-41773 KEV [KEV] Path Traversal in Apache http-server (CVE-2021-41773)
path traversal in Apache http-server (CVE-2021-41773). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2019-0211 KEV [KEV] Use-After-Free in Apache http-server (CVE-2019-0211)
vulnerability in Apache http-server (CVE-2019-0211). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2016-4437 KEV [KEV] Vulnerability in Apache shiro (CVE-2016-4437)
vulnerability in Apache shiro (CVE-2016-4437). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2019-17558 KEV [KEV] Vulnerability in Apache solr (CVE-2019-17558)
vulnerability in Apache solr (CVE-2019-17558). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-41182 Cross-Site Scripting (XSS) in jquery-ui (CVE-2021-41182)
cross-site scripting in jquery-ui (CVE-2021-41182). Data can be tampered with by attackers. Exploitable via ``altField``. Mitigation: upgrade to `1.13.0` or later.
CVE-2021-41183 Cross-Site Scripting (XSS) in jquery-ui (CVE-2021-41183)
cross-site scripting in jquery-ui (CVE-2021-41183). Data can be tampered with by attackers. Exploitable via ``doEvilThing``. Mitigation: upgrade to `1.13.0` or later.
CVE-2021-41184 Cross-Site Scripting (XSS) in jquery-ui (CVE-2021-41184)
cross-site scripting in jquery-ui (CVE-2021-41184). Data can be tampered with by attackers. Mitigation: upgrade to `1.13.0` or later.
CVE-2021-40690 Information Disclosure in apache (CVE-2021-40690)
vulnerability in apache (CVE-2021-40690). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →