Browse vulnerabilities
571 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an origin server … |
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.4… |
| CVE-2026-31431 | Act now | 99.9% | 7.8 | ● | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - … |
| CVE-2022-0543 | Act now | 99.4% | — | ● | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote cod… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming conn… |
| CVE-2018-7602 | Act now | 99.2% | 9.8 | ● | A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and … |
| CVE-2022-30333 | Act now | 99.1% | 7.5 | ● | RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files du… |
| CVE-2012-0507 | Act now | 98.1% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x… |
| CVE-2024-1086 | Act now | 28.1% | 7.8 | ● | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be… |
| CVE-2024-9680 | Act now | 23.2% | 9.8 | ● | An attacker was able to achieve code execution in the content process by exploiting a use-… |
| CVE-2025-38352 | Act now | 1.3% | 7.8 | ● | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix… |
| CVE-2025-39682 | Act now | 0.5% | 9.8 | ● | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of … |
| CVE-2021-45105 | High | 100.0% | 5.9 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not prot… | |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.… | |
| CVE-2021-33037 | High | 75.4% | 5.3 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctl… | |
| CVE-2020-13934 | High | 64.1% | 7.5 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8… | |
| CVE-2020-9484 | High | 56.6% | 7.0 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5… | |
| CVE-2021-41182 | Medium | 39.4% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, acceptin… | |
| CVE-2026-49975 | Medium | 34.3% | 7.5 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http… | |
| CVE-2019-10086 | Medium | 29.2% | 7.3 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows… | |
| CVE-2021-24122 | Medium | 22.9% | 5.9 | When serving resources from a network location using the NTFS file system, Apache Tomcat v… | |
| CVE-2020-36179 | Medium | 21.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-9548 | Medium | 18.3% | 9.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2021-25122 | Medium | 18.1% | 7.5 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0… | |
| CVE-2023-1380 | Medium | 16.5% | 7.1 | A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/… | |
| CVE-2020-35728 | Medium | 12.5% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36188 | Medium | 10.9% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2026-9256 | Medium | 10.9% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module modul… | |
| CVE-2020-36184 | Medium | 10.4% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2021-29425 | Medium | 10.2% | 4.8 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an … | |
| CVE-2020-35491 | Medium | 9.6% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2021-25329 | Medium | 9.5% | 7.0 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.… | |
| CVE-2020-24616 | Medium | 9.4% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serializ… | |
| CVE-2018-15756 | Medium | 9.2% | 7.5 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3… | |
| CVE-2020-14062 | Medium | 8.1% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serializ… | |
| CVE-2020-10673 | Medium | 8.0% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2020-35490 | Medium | 7.8% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2021-20190 | Medium | 7.5% | 8.1 | A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction… | |
| CVE-2021-40690 | Medium | 7.4% | 7.5 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vuln… | |
| CVE-2020-24750 | Medium | 7.3% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serializ… | |
| CVE-2021-20322 | Medium | 6.8% | 7.4 | A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) … | |
| CVE-2020-11113 | Medium | 6.3% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2022-27666 | Medium | 5.5% | 7.8 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c … | |
| CVE-2020-36185 | Medium | 5.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36186 | Medium | 5.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36187 | Medium | 5.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36180 | Medium | 5.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36181 | Medium | 5.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36182 | Medium | 5.0% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… |
Page 1 of 12
Next →