Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial Of Service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Prompt Leakage Llm Sensitive Information Disclosure Malware Missing Update Privilege Escalation SSRF Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-0932) CVE-2020-0932 CWE-434 CWE-434 High SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-0971) CVE-2020-0971 CWE-434 CWE-434 High SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-0974) CVE-2020-0974 CWE-434 CWE-434 High SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-1023) CVE-2020-1023 CWE-434 CWE-434 High SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-1024) CVE-2020-1024 CWE-434 CWE-434 High SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-1102) CVE-2020-1102 CWE-434 CWE-434 High SharePoint Untrusted Pointer Dereference Vulnerability (CVE-2025-27747) CVE-2025-27747 CWE-822 CWE-822 High SharePoint Untrusted Pointer Dereference Vulnerability (CVE-2025-54905) CVE-2025-54905 CWE-822 CWE-822 High SharePoint Untrusted Pointer Dereference Vulnerability (CVE-2026-20948) CVE-2026-20948 CWE-822 CWE-822 High SharePoint Untrusted Pointer Dereference Vulnerability (CVE-2026-40367) CVE-2026-40367 CWE-822 CWE-822 High SharePoint Untrusted Search Path Vulnerability (CVE-2026-20943) CVE-2026-20943 CWE-426 CWE-426 High SharePoint URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-1323) CVE-2020-1323 CWE-601 CWE-601 Medium SharePoint Use After Free Vulnerability (CVE-2025-47168) CVE-2025-47168 CWE-416 CWE-416 High SharePoint Use After Free Vulnerability (CVE-2025-49703) CVE-2025-49703 CWE-416 CWE-416 High SharePoint Use After Free Vulnerability (CVE-2025-59221) CVE-2025-59221 CWE-416 CWE-416 High SharePoint Use After Free Vulnerability (CVE-2025-59222) CVE-2025-59222 CWE-416 CWE-416 High SharePoint Use After Free Vulnerability (CVE-2025-62555) CVE-2025-62555 CWE-416 CWE-416 High SharePoint Use After Free Vulnerability (CVE-2025-62558) CVE-2025-62558 CWE-416 CWE-416 High SharePoint Use After Free Vulnerability (CVE-2025-62559) CVE-2025-62559 CWE-416 CWE-416 High SharePoint Use After Free Vulnerability (CVE-2025-62562) CVE-2025-62562 CWE-416 CWE-416 High SharePoint user enumeration CWE-200 CWE-200 High silverstripeCMS Credentials Management Errors Vulnerability (CVE-2010-5080) CVE-2010-5080 Medium silverstripeCMS Credentials Management Errors Vulnerability (CVE-2010-5092) CVE-2010-5092 Low silverstripeCMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-5088) CVE-2010-5088 CWE-352 CWE-352 Medium silverstripeCMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-12246) CVE-2019-12246 CWE-352 CWE-352 Medium silverstripeCMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-12437) CVE-2019-12437 CWE-352 CWE-352 High silverstripeCMS Cryptographic Issues Vulnerability (CVE-2010-5079) CVE-2010-5079 Medium silverstripeCMS CVE-2019-12204 Vulnerability (CVE-2019-12204) CVE-2019-12204 Critical silverstripeCMS CVE-2019-12617 Vulnerability (CVE-2019-12617) CVE-2019-12617 Low silverstripeCMS CVE-2019-16409 Vulnerability (CVE-2019-16409) CVE-2019-16409 Medium silverstripeCMS CVE-2020-6164 Vulnerability (CVE-2020-6164) CVE-2020-6164 High silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-4822) CVE-2010-4822 CWE-200 CWE-200 Medium silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-5187) CVE-2010-5187 CWE-200 CWE-200 Medium silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-5188) CVE-2010-5188 CWE-200 CWE-200 Medium silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-6789) CVE-2013-6789 CWE-200 CWE-200 Medium silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-12849) CVE-2017-12849 CWE-200 CWE-200 Medium silverstripeCMS Files or Directories Accessible to External Parties Vulnerability (CVE-2019-14273) CVE-2019-14273 CWE-552 CWE-552 Medium silverstripeCMS Improper Authentication Vulnerability (CVE-2020-26136) CVE-2020-26136 CWE-287 CWE-287 Medium silverstripeCMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-5091) CVE-2010-5091 CWE-94 CWE-94 Medium silverstripeCMS Improper Input Validation Vulnerability (CVE-2011-4962) CVE-2011-4962 CWE-20 CWE-20 Medium silverstripeCMS Improper Input Validation Vulnerability (CVE-2013-2653) CVE-2013-2653 CWE-20 CWE-20 Medium silverstripeCMS Improper Input Validation Vulnerability (CVE-2020-26138) CVE-2020-26138 CWE-20 CWE-20 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-1593) CVE-2010-1593 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4823) CVE-2010-4823 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-5095) CVE-2010-5095 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4958) CVE-2011-4958 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-0976) CVE-2012-0976 CWE-707 CWE-707 Low silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4968) CVE-2012-4968 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-6458) CVE-2012-6458 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5063) CVE-2015-5063 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-8606) CVE-2015-8606 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-5197) CVE-2017-5197 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-14498) CVE-2017-14498 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-12205) CVE-2019-12205 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14272) CVE-2019-14272 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-19325) CVE-2019-19325 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-9311) CVE-2020-9311 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36150) CVE-2021-36150 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-28803) CVE-2022-28803 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-37421) CVE-2022-37421 CWE-707 CWE-707 Medium silverstripeCMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2017-18049) CVE-2017-18049 CWE-138 CWE-138 Medium silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-6753) CVE-2008-6753 CWE-138 CWE-138 High silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-1433) CVE-2009-1433 CWE-138 CWE-138 High silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4824) CVE-2010-4824 CWE-138 CWE-138 Medium silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2011-4959) CVE-2011-4959 CWE-138 CWE-138 Medium silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2011-4960) CVE-2011-4960 CWE-138 CWE-138 High silverstripeCMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-5715) CVE-2019-5715 CWE-138 CWE-138 Critical silverstripeCMS Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') Vulnerability (CVE-2021-41559) CVE-2021-41559 CWE-776 CWE-776 Medium silverstripeCMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-25817) CVE-2020-25817 CWE-611 CWE-611 Medium silverstripeCMS Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2019-19326) CVE-2019-19326 Medium silverstripeCMS Incorrect Authorization Vulnerability (CVE-2021-28661) CVE-2021-28661 CWE-863 CWE-863 Medium silverstripeCMS Incorrect Default Permissions Vulnerability (CVE-2020-6165) CVE-2020-6165 CWE-276 CWE-276 Medium silverstripeCMS Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2019-12245) CVE-2019-12245 CWE-732 CWE-732 Medium silverstripeCMS Other Vulnerability (CVE-2007-2321) CVE-2007-2321 Critical silverstripeCMS Other Vulnerability (CVE-2015-5062) CVE-2015-5062 Medium 1...186187188189...327 187 / 327