Vulnerability Name CVE Severity
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5078) CVE-2010-5078
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5087) CVE-2010-5087
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5089) CVE-2010-5089
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5090) CVE-2010-5090
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5093) CVE-2010-5093
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5094) CVE-2010-5094
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4961) CVE-2011-4961
silverstripeCMS Session Fixation Vulnerability (CVE-2019-12203) CVE-2019-12203
silverstripeCMS Session Fixation Vulnerability (CVE-2022-24444) CVE-2022-24444
silverstripeCMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-9280) CVE-2020-9280
SimpleHelp Path Traversal (CVE-2024-57727) CVE-2024-57727 CVE-2024-57726 CVE-2024-57728
Sitecore Arbitrary File Read (CVE-2024-46938) CVE-2024-46938
Sitecore XM/XP Insecure Deserialization (CVE-2025-27218) CVE-2025-27218
Sitecore XP Deserialization RCE (CVE-2021-42237) CVE-2021-42237
Sitecore XP TemplateParser RCE (CVE-2023-35813) CVE-2023-35813
Skipper Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-23742) CVE-2026-23742
Skipper Incorrect Authorization Vulnerability (CVE-2022-34296) CVE-2022-34296
Skipper Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-38580) CVE-2022-38580
Skipper Unintended Proxy or Intermediary ('Confused Deputy') Vulnerability (CVE-2026-24470) CVE-2026-24470
Skype for Business SSRF (CVE-2023-41763) CVE-2023-41763
SmarterTools SmarterMail Admin Password Reset (CVE-2026-23760) CVE-2026-23760
Snoop Servlet information disclosure
SOAP WS-Addressing SSRF
SolarWinds Orion API Auth bypass (CVE-2020-10148) CVE-2020-10148
SolarWinds Serv-U Directory Traversal (CVE-2024-28995) CVE-2024-28995
SolarWinds Web Help Desk Hardcoded Credential (CVE-2024-28987) CVE-2024-28987
SolarWinds Web Help Desk RCE (CVE-2024-28986) CVE-2024-28986
SonarQube default credentials
Sonicwall SMA 100 Unintended proxy (CVE-2021-20042) CVE-2021-20042
SonicWall SSL-VPN 8.0.0.0 RCE via ShellShock exploit
Source Code Disclosure
Source Code Disclosure (Node.js)
Source Code Disclosure (Python)
spring-boot-actuator-logview Path Traversal CVE-2021-21234
Spring Boot Actuator
Spring Boot Actuator v2
Spring Boot Misconfiguration: Actuator endpoint security disabled
Spring Boot Misconfiguration: Admin MBean enabled
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
Spring Boot Misconfiguration: Datasource credentials stored in the properties file
Spring Boot Misconfiguration: Developer tools enabled on production
Spring Boot Misconfiguration: H2 console enabled
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Spring Boot Misconfiguration: Overly long session timeout
Spring Boot Misconfiguration: Spring Boot Actuator shutdown endpoint is web exposed
Spring Boot Misconfiguration: Unsafe value for session tracking
Spring Boot Whitelabel Error Page SpEL
Spring Cloud Gateway Improper Certificate Validation Vulnerability (CVE-2022-22946) CVE-2022-22946
Spring Cloud Gateway Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression La Vulnerability (CVE-2022-22947) CVE-2022-22947
Spring Cloud Gateway Incorrect Authorization Vulnerability (CVE-2021-22051) CVE-2021-22051
Spring Data REST RCE via PATCH requests CVE-2017-8046
Spring Misconfiguration: HTML Escaping disabled
Spring Security Authentication Bypass CVE-2016-5007
SQL Injection
SQL Injection (stylesheet.php) (CMS Made Simple) CVE-2007-2473
SQL Injection in Symphony CVE-2013-2559
SQL injection in the authentication header
Sqlite Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Vulnerability (CVE-2015-3717) CVE-2015-3717
Sqlite CVE-2015-5895 Vulnerability (CVE-2015-5895) CVE-2015-5895
Sqlite CVE-2019-19244 Vulnerability (CVE-2019-19244) CVE-2019-19244
Sqlite CVE-2019-19603 Vulnerability (CVE-2019-19603) CVE-2019-19603
Sqlite CVE-2020-13631 Vulnerability (CVE-2020-13631) CVE-2020-13631
Sqlite CVE-2021-20223 Vulnerability (CVE-2021-20223) CVE-2021-20223
Sqlite CVE-2021-36690 Vulnerability (CVE-2021-36690) CVE-2021-36690
Sqlite CVE-2023-36191 Vulnerability (CVE-2023-36191) CVE-2023-36191
SQLite Database File Found
Sqlite Divide By Zero Vulnerability (CVE-2019-16168) CVE-2019-16168
Sqlite Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2019-19646) CVE-2019-19646
Sqlite Improper Clearing of Heap Memory Before Release ('Heap Inspection') Vulnerability (CVE-2025-70873) CVE-2025-70873
Sqlite Improper Handling of Exceptional Conditions Vulnerability (CVE-2019-19924) CVE-2019-19924
Sqlite Improper Initialization Vulnerability (CVE-2020-11655) CVE-2020-11655
Sqlite Improper Input Validation Vulnerability (CVE-2016-6153) CVE-2016-6153
Sqlite Improper Input Validation Vulnerability (CVE-2017-13685) CVE-2017-13685
Sqlite Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-6590) CVE-2008-6590
Sqlite Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-6592) CVE-2008-6592