Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2021-36373 Vulnerability in apache (CVE-2021-36373)
vulnerability in apache (CVE-2021-36373). Risk of unauthorized operations or information disclosure.
CVE-2021-36374 Vulnerability in apache (CVE-2021-36374)
vulnerability in apache (CVE-2021-36374). Risk of unauthorized operations or information disclosure.
CVE-2021-33037 Vulnerability in apache (CVE-2021-33037)
vulnerability in apache (CVE-2021-33037). Risk of unauthorized operations or information disclosure.
CVE-2021-25122 Information Disclosure in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.43` or later.
CVE-2021-29425 Vulnerability in apache (CVE-2021-29425)
vulnerability in apache (CVE-2021-29425). Risk of unauthorized operations or information disclosure.
CVE-2020-29238 Vulnerability in nginx (CVE-2020-29238)
vulnerability in nginx (CVE-2020-29238). Confidential information can be exposed externally.
CVE-2021-25329 Vulnerability in apache (CVE-2021-25329)
vulnerability in apache (CVE-2021-25329). Successful exploitation can lead to full system takeover.
CVE-2021-26117 Authentication Bypass in apache (CVE-2021-26117)
authentication bypass in apache (CVE-2021-26117). Data can be tampered with by attackers.
CVE-2021-26118 Vulnerability in org.apache.activemq:artemis-openwire-protocol (CVE-2021-26118)
vulnerability in org.apache.activemq:artemis-openwire-protocol (CVE-2021-26118). Data can be tampered with by attackers. Mitigation: upgrade to `2.16.0` or later.
CVE-2020-28707 Cross-Site Scripting (XSS) in wordpress (CVE-2020-28707)
cross-site scripting in wordpress (CVE-2020-28707). Risk of unauthorized operations or information disclosure.
CVE-2021-20190 Unsafe Deserialization in fasterxml (CVE-2021-20190)
vulnerability in fasterxml (CVE-2021-20190). Successful exploitation can lead to full system takeover.
CVE-2021-24122 Information Disclosure in apache (CVE-2021-24122)
vulnerability in apache (CVE-2021-24122). Confidential information can be exposed externally.
CVE-2020-36183 Unsafe Deserialization in apache (CVE-2020-36183)
vulnerability in apache (CVE-2020-36183). Successful exploitation can lead to full system takeover.
CVE-2020-36179 Unsafe Deserialization in apache (CVE-2020-36179)
vulnerability in apache (CVE-2020-36179). Successful exploitation can lead to full system takeover.
CVE-2020-36180 Unsafe Deserialization in apache (CVE-2020-36180)
vulnerability in apache (CVE-2020-36180). Successful exploitation can lead to full system takeover.
CVE-2020-36182 Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
CVE-2020-36184 Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
CVE-2020-36185 Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
CVE-2020-36186 Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
CVE-2020-36187 Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
CVE-2020-36181 Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
CVE-2020-35728 Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
CVE-2020-35490 Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
CVE-2020-35491 Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
CVE-2020-17521 Vulnerability in apache (CVE-2020-17521)
vulnerability in apache (CVE-2020-17521). Confidential information can be exposed externally.
CVE-2020-25649 XXE (XML External Entity) in fasterxml (CVE-2020-25649)
vulnerability in fasterxml (CVE-2020-25649). Data can be tampered with by attackers.
CVE-2020-13932 Cross-Site Scripting (XSS) in org.apache.activemq:apache-artemis (CVE-2020-13932)
cross-site scripting in org.apache.activemq:apache-artemis (CVE-2020-13932). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.14.0` or later.
CVE-2020-10727 Vulnerability in org.apache.activemq:artemis-commons (CVE-2020-10727)
vulnerability in org.apache.activemq:artemis-commons (CVE-2020-10727). Confidential information can be exposed externally. Exploitable via ``resetUsers``. Mitigation: upgrade to `2.13.0` or later.
CVE-2020-14060 Unsafe Deserialization in apache (CVE-2020-14060)
vulnerability in apache (CVE-2020-14060). Successful exploitation can lead to full system takeover.
CVE-2020-14062 Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
CVE-2020-9484 Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
CVE-2020-9488 Vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488)
vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.2` or later.
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-9281 Cross-Site Scripting (XSS) in ckeditor (CVE-2020-9281)
cross-site scripting in ckeditor (CVE-2020-9281). Risk of unauthorized operations or information disclosure.
CVE-2020-9546 Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
CVE-2019-17569 Vulnerability in apache (CVE-2019-17569)
vulnerability in apache (CVE-2019-17569). Risk of unauthorized operations or information disclosure.
CVE-2019-17571 Unsafe Deserialization in log4j:log4j (CVE-2019-17571)
vulnerability in log4j:log4j (CVE-2019-17571). Successful exploitation can lead to full system takeover.
CVE-2019-10086 Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
CVE-2018-15756 Vulnerability in spring (CVE-2018-15756)
vulnerability in spring (CVE-2018-15756). Risk of unauthorized operations or information disclosure.
CVE-2018-11039 Vulnerability in spring (CVE-2018-11039)
vulnerability in spring (CVE-2018-11039). Confidential information can be exposed externally.
CVE-2018-1258 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CVE-2017-12174 Vulnerability in apache (CVE-2017-12174)
vulnerability in apache (CVE-2017-12174). Risk of unauthorized operations or information disclosure.
CVE-2017-12626 Vulnerability in org.apache.poi:poi (CVE-2017-12626)
vulnerability in org.apache.poi:poi (CVE-2017-12626). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.17` or later.
CVE-2017-8046 Vulnerability in spring (CVE-2017-8046)
vulnerability in spring (CVE-2017-8046). Successful exploitation can lead to full system takeover.
CVE-2015-3302 Vulnerability in wordpress (CVE-2015-3302)
vulnerability in wordpress (CVE-2015-3302). Confidential information can be exposed externally.
CVE-2017-17916 SQL Injection in rails (CVE-2017-17916)
SQL injection in rails (CVE-2017-17916). Successful exploitation can lead to full system takeover.
CVE-2017-17917 SQL Injection in rails (CVE-2017-17917)
SQL injection in rails (CVE-2017-17917). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →