Vulnerability Name CVE Severity
qdPM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-8390) CVE-2019-8390
qdPM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-8391) CVE-2019-8391
qdPM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-18468) CVE-2020-18468
qdPM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-19515) CVE-2020-19515
qdPM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-26166) CVE-2020-26166
qdPM Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-11814) CVE-2020-11814
qdPM Information Disclosure
qdPM Multiple Cross-site Scripting (XSS) Vulnerabilities (CVE-2015-3883) CVE-2015-3883
qdPM Sensitive Information Disclosure Vulnerability (CVE-2015-3881) CVE-2015-3881
qdPM Sensitive Information Disclosure Vulnerability (CVE-2015-3882) CVE-2015-3882
qdPM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11811) CVE-2020-11811
qdPM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-45856) CVE-2023-45856
Qlik Sense Enterprise Auth Bypass (CVE-2023-41266) CVE-2023-41266
Question2Answer Improper Input Validation Vulnerability (CVE-2017-12775) CVE-2017-12775
rack-mini-profiler environment variables disclosure
Railo administration panel cross-site scripting
Rails application running in development mode
Rails Asset Pipeline Directory Traversal Vulnerability CVE-2018-3760
Rails controller possible sensitive information disclosure
Rails Devise authentication password reset CVE-2013-0233
Rails mass assignment
Rails remote code execution using render :inline CVE-2016-2098
Ramda Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') Vulnerability (CVE-2021-42581) CVE-2021-42581
RCE in Ivanti Connect Secure and Policy Secure (CVE-2024-21887) CVE-2024-21887
RCE in SQL Server Reporting Services (SSRS) CVE-2020-0618
RCE with Spring Data Commons CVE-2018-1273
Reachable SharePoint interface
React Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-6341) CVE-2018-6341
Redis Unauthorized Access Vulnerability
Reflected Cross-Site Scripting (XSS) vulnerability in PAN-OS management web interface CVE-2020-2036
Rejetto HTTP File Server SSTI RCE (CVE-2024-23692) CVE-2024-23692
Remote Code Execution (RCE) in Spring Security OAuth CVE-2016-4977
Remote Code Execution (Spring4Shell) CVE-2022-22965
Remote code execution in bootstrap-sass 3.2.0.3 CVE-2019-10842
Remote code execution of user-provided local names in Rails CVE-2020-8163
Remote code execution vulnerability in WordPress Duplicator
Remote File Inclusion
Remote File Inclusion (admin/lang.php) (CMS Made Simple) CVE-2005-2846
Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387) CVE-2024-6387
Request Smuggling
Resin Application Server Improper Input Validation Vulnerability (CVE-2012-2965) CVE-2012-2965
Resin Application Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2012-2968) CVE-2012-2968
Resin Application Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-44138) CVE-2021-44138
Resin Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2008-2462) CVE-2008-2462
Resin Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-2032) CVE-2010-2032
Resin Application Server Other Vulnerability (CVE-2004-0281) CVE-2004-0281
Resin Application Server Other Vulnerability (CVE-2012-2966) CVE-2012-2966
Resin Application Server Other Vulnerability (CVE-2012-2967) CVE-2012-2967
Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2969) CVE-2012-2969
Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-2966) CVE-2014-2966
Resource Accessible Without Required Authentication
Restlet Framework Deserialization of Untrusted Data Vulnerability (CVE-2013-4271) CVE-2013-4271
Restlet Framework Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-14868) CVE-2017-14868
Restlet Framework Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-14949) CVE-2017-14949
Restlet Framework XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2013-4221) CVE-2013-4221
RethinkDB administrative interface publicly exposed
Retired hash function in SAML Response
reveal.js Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-8127) CVE-2020-8127
reveal.js Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-0776) CVE-2022-0776
Reverse proxy bypass CVE-2011-3368
Reverse Proxy Detected
Reverse proxy misrouting
Reverse proxy misrouting through HTTP/2 pseudo-headers (SSRF)
ReviveAdserver 7PK - Security Features Vulnerability (CVE-2016-9470) CVE-2016-9470
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-5954) CVE-2013-5954
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9407) CVE-2014-9407
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-7364) CVE-2015-7364
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-7366) CVE-2015-7366
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9127) CVE-2016-9127
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9455) CVE-2016-9455
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9456) CVE-2016-9456
ReviveAdserver Deserialization of Untrusted Data Vulnerability (CVE-2017-5830) CVE-2017-5830
ReviveAdserver Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-7368) CVE-2015-7368
ReviveAdserver Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9129) CVE-2016-9129
ReviveAdserver Improper Access Control Vulnerability (CVE-2015-7367) CVE-2015-7367