Browse vulnerabilities

571 results

CVEPriorityEPSSCVSSKEVWhat
CVE-2021-40438 Act now 100.0% 9.0 A crafted request uri-path can cause mod_proxy to forward the request to an origin server …
CVE-2017-12617 Act now 100.0% 8.1 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.4…
CVE-2026-31431 Act now 99.9% 7.8 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - …
CVE-2022-0543 Act now 99.4% Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote cod…
CVE-2020-1938 Act now 99.3% 9.8 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming conn…
CVE-2018-7602 Act now 99.2% 9.8 A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and …
CVE-2022-30333 Act now 99.1% 7.5 RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files du…
CVE-2012-0507 Act now 98.1% 9.8 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S…
CVE-2016-8735 Act now 90.3% 9.8 Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x…
CVE-2024-1086 Act now 28.1% 7.8 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be…
CVE-2024-9680 Act now 23.2% 9.8 An attacker was able to achieve code execution in the content process by exploiting a use-…
CVE-2025-38352 Act now 1.3% 7.8 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix…
CVE-2025-39682 Act now 0.5% 9.8 In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of …
CVE-2021-45105 High 100.0% 5.9 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not prot…
CVE-2020-13935 High 86.6% 7.5 The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.…
CVE-2021-33037 High 75.4% 5.3 Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctl…
CVE-2020-13934 High 64.1% 7.5 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8…
CVE-2020-9484 High 56.6% 7.0 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5…
CVE-2021-41182 Medium 39.4% 6.5 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, acceptin…
CVE-2026-49975 Medium 34.3% 7.5 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http…
CVE-2019-10086 Medium 29.2% 7.3 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows…
CVE-2021-24122 Medium 22.9% 5.9 When serving resources from a network location using the NTFS file system, Apache Tomcat v…
CVE-2020-36179 Medium 21.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2020-9548 Medium 18.3% 9.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ…
CVE-2021-25122 Medium 18.1% 7.5 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0…
CVE-2023-1380 Medium 16.5% 7.1 A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/…
CVE-2020-35728 Medium 12.5% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2020-36188 Medium 10.9% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2026-9256 Medium 10.9% 8.1 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module modul…
CVE-2020-36184 Medium 10.4% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2021-29425 Medium 10.2% 4.8 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an …
CVE-2020-35491 Medium 9.6% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2021-25329 Medium 9.5% 7.0 The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.…
CVE-2020-24616 Medium 9.4% 8.1 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serializ…
CVE-2018-15756 Medium 9.2% 7.5 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3…
CVE-2020-14062 Medium 8.1% 8.1 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serializ…
CVE-2020-10673 Medium 8.0% 8.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ…
CVE-2020-35490 Medium 7.8% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2021-20190 Medium 7.5% 8.1 A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction…
CVE-2021-40690 Medium 7.4% 7.5 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vuln…
CVE-2020-24750 Medium 7.3% 8.1 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serializ…
CVE-2021-20322 Medium 6.8% 7.4 A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) …
CVE-2020-11113 Medium 6.3% 8.8 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ…
CVE-2022-27666 Medium 5.5% 7.8 A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c …
CVE-2020-36185 Medium 5.2% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2020-36186 Medium 5.2% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2020-36187 Medium 5.2% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2020-36180 Medium 5.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2020-36181 Medium 5.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
CVE-2020-36182 Medium 5.0% 8.1 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ…
Page 1 of 12 Next →