Browse vulnerabilities
613 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2017-5638 | Act now | 100.0% | — | ● | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-… |
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an origin server … |
| CVE-2021-44228 | Act now | 100.0% | 10.0 | ● | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.… |
| CVE-2013-2251 | Act now | 100.0% | — | ● | Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Languag… |
| CVE-2021-41773 | Act now | 100.0% | — | ● | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perf… |
| CVE-2018-11776 | Act now | 100.0% | — | ● | Apache Struts contains a vulnerability that allows for remote code execution under two cir… |
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.4… |
| CVE-2024-45195 | Act now | 100.0% | — | ● | Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obt… |
| CVE-2021-45046 | Act now | 100.0% | — | ● | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomp… |
| CVE-2021-42013 | Act now | 100.0% | — | ● | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perf… |
| CVE-2024-38475 | Act now | 100.0% | — | ● | Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite th… |
| CVE-2023-38035 | Act now | 100.0% | — | ● | Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vuln… |
| CVE-2025-24813 | Act now | 99.9% | — | ● | Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to e… |
| CVE-2022-47966 | Act now | 99.8% | 9.8 | ● | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, al… |
| CVE-2023-46604 | Act now | 99.7% | — | ● | Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow … |
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via set… |
| CVE-2024-32113 | Act now | 99.4% | — | ● | Apache OFBiz contains a path traversal vulnerability that could allow for remote code exec… |
| CVE-2024-38856 | Act now | 99.4% | — | ● | Apache OFBiz contains an incorrect authorization vulnerability that could allow remote cod… |
| CVE-2017-9805 | Act now | 99.4% | — | ● | Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deseriali… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming conn… |
| CVE-2024-27348 | Act now | 99.2% | — | ● | Apache HugeGraph-Server contains an improper access control vulnerability that could allow… |
| CVE-2017-9791 | Act now | 98.9% | — | ● | The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious fie… |
| CVE-2026-34486 | Act now | 98.6% | 7.5 | ● | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE… |
| CVE-2019-17558 | Act now | 98.6% | — | ● | The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which… |
| CVE-2016-3088 | Act now | 98.5% | — | ● | The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and ex… |
| CVE-2026-34197 | Act now | 98.3% | 8.8 | ● | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulne… |
| CVE-2020-17519 | Act now | 97.8% | — | ● | Apache Flink contains an improper access control vulnerability that allows an attacker to … |
| CVE-2023-27524 | Act now | 97.4% | — | ● | Apache Superset contains an insecure default initialization of a resource vulnerability th… |
| CVE-2020-1956 | Act now | 97.3% | — | ● | Apache Kylin contains an OS command injection vulnerability which could permit an attacker… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupporte… |
| CVE-2023-33246 | Act now | 96.6% | — | ● | Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are e… |
| CVE-2015-4852 | Act now | 96.0% | — | ● | Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within A… |
| CVE-2022-24112 | Act now | 96.0% | — | ● | Apache APISIX contains an authentication bypass vulnerability that allows for remote code … |
| CVE-2020-17530 | Act now | 95.9% | — | ● | Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated… |
| CVE-2022-33891 | Act now | 93.1% | — | ● | Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when… |
| CVE-2016-4437 | Act now | 93.0% | — | ● | Apache Shiro contains a vulnerability which may allow remote attackers to execute code or … |
| CVE-2022-24706 | Act now | 92.5% | — | ● | Apache CouchDB contains an insecure default initialization of resource vulnerability which… |
| CVE-2017-3066 | Act now | 90.6% | — | ● | Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library th… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x… |
| CVE-2019-0193 | Act now | 83.5% | — | ● | The optional Apache Solr module DataImportHandler contains a code injection vulnerability. |
| CVE-2012-0391 | Act now | 75.6% | — | ● | The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper in… |
| CVE-2019-0211 | Act now | 65.0% | — | ● | Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged c… |
| CVE-2006-1547 | Act now | 54.6% | — | ● | ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerabil… |
| CVE-2026-21962 | Act now | 42.5% | 10.0 | ● | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of O… |
| CVE-2021-45105 | High | 100.0% | 5.9 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not prot… | |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.… | |
| CVE-2021-33037 | High | 75.4% | 5.3 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctl… | |
| CVE-2020-13934 | High | 64.1% | 7.5 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8… | |
| CVE-2020-9484 | High | 56.6% | 7.0 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5… | |
| CVE-2026-44181 | High | 0.7% | 10.0 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… |
Page 1 of 13
Next →