Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2016-5018 Vulnerability in apache (CVE-2016-5018)
vulnerability in apache (CVE-2016-5018). Confidential information can be exposed externally.
CVE-2016-6794 Vulnerability in apache (CVE-2016-6794)
vulnerability in apache (CVE-2016-6794). Risk of unauthorized operations or information disclosure.
CVE-2016-6812 Cross-Site Scripting (XSS) in apache (CVE-2016-6812)
cross-site scripting in apache (CVE-2016-6812). Risk of unauthorized operations or information disclosure.
CVE-2017-9799 Vulnerability in apache (CVE-2017-9799)
vulnerability in apache (CVE-2017-9799). Successful exploitation can lead to full system takeover.
CVE-2014-6393 Cross-Site Scripting (XSS) in express (CVE-2014-6393)
cross-site scripting in express (CVE-2014-6393). Risk of unauthorized operations or information disclosure.
CVE-2017-8691 Buffer Overflow in express (CVE-2017-8691)
vulnerability in express (CVE-2017-8691). Successful exploitation can lead to full system takeover.
CVE-2010-2245 XXE (XML External Entity) in apache (CVE-2010-2245)
vulnerability in apache (CVE-2010-2245). Confidential information can be exposed externally.
CVE-2011-4343 Information Disclosure in apache (CVE-2011-4343)
vulnerability in apache (CVE-2011-4343). Confidential information can be exposed externally.
CVE-2012-0803 Authentication Bypass in apache (CVE-2012-0803)
authentication bypass in apache (CVE-2012-0803). Successful exploitation can lead to full system takeover.
CVE-2012-0880 Vulnerability in c (CVE-2012-0880)
vulnerability in c (CVE-2012-0880). Risk of unauthorized operations or information disclosure.
CVE-2017-12677 Cross-Site Scripting (XSS) in angular (CVE-2017-12677)
cross-site scripting in angular (CVE-2017-12677). Risk of unauthorized operations or information disclosure.
CVE-2014-9260 Vulnerability in wordpress (CVE-2014-9260)
vulnerability in wordpress (CVE-2014-9260). Successful exploitation can lead to full system takeover.
CVE-2014-9262 Vulnerability in wordpress (CVE-2014-9262)
vulnerability in wordpress (CVE-2014-9262). Confidential information can be exposed externally.
CVE-2017-12650 SQL Injection in wordpress (CVE-2017-12650)
SQL injection in wordpress (CVE-2017-12650). Successful exploitation can lead to full system takeover.
CVE-2017-12651 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2017-12651)
vulnerability in wordpress (CVE-2017-12651). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
CVE-2015-7875 Vulnerability in drupal (CVE-2015-7875)
vulnerability in drupal (CVE-2015-7875). Data can be tampered with by attackers.
CVE-2017-9801 Vulnerability in apache (CVE-2017-9801)
vulnerability in apache (CVE-2017-9801). Data can be tampered with by attackers.
CVE-2017-7916 Vulnerability in react (CVE-2017-7916)
vulnerability in react (CVE-2017-7916). Confidential information can be exposed externally.
CVE-2017-7920 Authentication Bypass in react (CVE-2017-7920)
authentication bypass in react (CVE-2017-7920). Confidential information can be exposed externally.
CVE-2017-6747 Authentication Bypass in express (CVE-2017-6747)
authentication bypass in express (CVE-2017-6747). Successful exploitation can lead to full system takeover.
CVE-2017-11364 Vulnerability in joomla (CVE-2017-11364)
vulnerability in joomla (CVE-2017-11364). Successful exploitation can lead to full system takeover.
CVE-2017-12199 SQL Injection in wordpress (CVE-2017-12199)
SQL injection in wordpress (CVE-2017-12199). Successful exploitation can lead to full system takeover.
CVE-2017-12200 Cross-Site Scripting (XSS) in wordpress (CVE-2017-12200)
cross-site scripting in wordpress (CVE-2017-12200). Risk of unauthorized operations or information disclosure.
CVE-2017-12068 Cross-Site Scripting (XSS) in wordpress (CVE-2017-12068)
cross-site scripting in wordpress (CVE-2017-12068). Risk of unauthorized operations or information disclosure.
CVE-2017-12131 Cross-Site Scripting (XSS) in wordpress (CVE-2017-12131)
cross-site scripting in wordpress (CVE-2017-12131). Risk of unauthorized operations or information disclosure.
CVE-2017-11726 Cross-Site Request Forgery (CSRF) in rails (CVE-2017-11726)
vulnerability in rails (CVE-2017-11726). Successful exploitation can lead to full system takeover.
CVE-2017-11727 Cross-Site Scripting (XSS) in rails (CVE-2017-11727)
cross-site scripting in rails (CVE-2017-11727). Risk of unauthorized operations or information disclosure.
CVE-2017-11694 Vulnerability in apache (CVE-2017-11694)
vulnerability in apache (CVE-2017-11694). Confidential information can be exposed externally.
CVE-2016-0736 Vulnerability in apache (CVE-2016-0736)
vulnerability in apache (CVE-2016-0736). Confidential information can be exposed externally.
CVE-2016-2161 Vulnerability in apache (CVE-2016-2161)
vulnerability in apache (CVE-2016-2161). Risk of unauthorized operations or information disclosure.
CVE-2016-8743 Vulnerability in apache (CVE-2016-8743)
vulnerability in apache (CVE-2016-8743). Data can be tampered with by attackers.
CVE-2017-7659 Vulnerability in apache (CVE-2017-7659)
vulnerability in apache (CVE-2017-7659). Risk of unauthorized operations or information disclosure.
CVE-2017-11658 Path Traversal in wordpress (CVE-2017-11658)
path traversal in wordpress (CVE-2017-11658). Confidential information can be exposed externally.
CVE-2017-11612 Cross-Site Scripting (XSS) in joomla (CVE-2017-11612)
cross-site scripting in joomla (CVE-2017-11612). Risk of unauthorized operations or information disclosure.
CVE-2015-3421 Cross-Site Scripting (XSS) in wordpress (CVE-2015-3421)
cross-site scripting in wordpress (CVE-2015-3421). Risk of unauthorized operations or information disclosure.
CVE-2016-5394 Cross-Site Scripting (XSS) in apache (CVE-2016-5394)
cross-site scripting in apache (CVE-2016-5394). Risk of unauthorized operations or information disclosure.
CVE-2016-6798 XXE (XML External Entity) in apache (CVE-2016-6798)
vulnerability in apache (CVE-2016-6798). Successful exploitation can lead to full system takeover.
CVE-2017-9933 Information Disclosure in joomla (CVE-2017-9933)
vulnerability in joomla (CVE-2017-9933). Confidential information can be exposed externally.
CVE-2017-9934 Cross-Site Scripting (XSS) in csrf (CVE-2017-9934)
cross-site scripting in csrf (CVE-2017-9934). Risk of unauthorized operations or information disclosure.
CVE-2017-7685 Vulnerability in apache (CVE-2017-7685)
vulnerability in apache (CVE-2017-7685). Risk of unauthorized operations or information disclosure.
CVE-2017-7688 Apache OpenMeetings 1.0.0 updates user password in insecure manner.
Apache OpenMeetings 1.0.0 updates user password in insecure manner.
CVE-2017-7663 Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.
Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.
CVE-2017-7664 Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
CVE-2017-7666 Cross-Site Scripting (XSS) in apache (CVE-2017-7666)
cross-site scripting in apache (CVE-2017-7666). Successful exploitation can lead to full system takeover.
CVE-2017-7673 Vulnerability in apache (CVE-2017-7673)
vulnerability in apache (CVE-2017-7673). Successful exploitation can lead to full system takeover.
CVE-2017-7680 Vulnerability in apache (CVE-2017-7680)
vulnerability in apache (CVE-2017-7680). Data can be tampered with by attackers.
CVE-2017-7681 SQL Injection in apache (CVE-2017-7681)
SQL injection in apache (CVE-2017-7681). Successful exploitation can lead to full system takeover.
CVE-2017-7682 Vulnerability in apache (CVE-2017-7682)
vulnerability in apache (CVE-2017-7682). Data can be tampered with by attackers.
CVE-2017-7683 Information Disclosure in apache (CVE-2017-7683)
vulnerability in apache (CVE-2017-7683). Confidential information can be exposed externally.
CVE-2017-7684 Vulnerability in apache (CVE-2017-7684)
vulnerability in apache (CVE-2017-7684). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →