Vulnerability Name CVE Severity
Telerik Web UI Unrestricted File Upload (CVE-2017-11317) CVE-2017-11317
Test CGI script leaking environment variables
TestRail Information Disclosure (CVE-2021-40875) CVE-2021-40875
Text4shell: Apache Commons Text RCE via insecure interpolation CVE-2022-42889
The DROWN attack (SSLv2 supported) CVE-2016-0800
The FREAK attack CVE-2015-0204
The GHOST Vulnerability CVE-2015-0235
The Heartbleed Bug CVE-2014-0160
The POODLE attack (SSLv3 with CBC cipher suites) CVE-2014-3566
ThinkPHP v5.0.22/5.1.29 Remote Code Execution Vulnerability
Three.js Uncontrolled Resource Consumption Vulnerability (CVE-2020-28496) CVE-2020-28496
Tiki Wiki CMS: Arbitrary Code Execution
Tiki Wiki CMS: Arbitrary File Download
Tiki Wiki CMS: Remote Code Execution via Calendar Module
timthumb.php remote code execution CVE-2011-4106
TimThumb WebShot remote code execution
TinyMCE ajax_create_folder remote code execution vulnerability
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-1010091) CVE-2019-1010091
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12648) CVE-2020-12648
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-17480) CVE-2020-17480
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-23066) CVE-2020-23066
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-23494) CVE-2022-23494
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-45818) CVE-2023-45818
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-45819) CVE-2023-45819
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-48219) CVE-2023-48219
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21908) CVE-2024-21908
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21910) CVE-2024-21910
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21911) CVE-2024-21911
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-29203) CVE-2024-29203
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-29881) CVE-2024-29881
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-47759) CVE-2026-47759
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-47760) CVE-2026-47760
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-47761) CVE-2026-47761
TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-47762) CVE-2026-47762
TLS/SSL (EC)DHE Key Reuse
TLS/SSL certificate key size too small
TLS/SSL LOGJAM attack CVE-2015-4000
TLS/SSL Sweet32 attack CVE-2016-2183 CVE-2016-6329
TLS/SSL Weak Cipher Suites
Tomcat path traversal via reverse proxy mapping
Tomcat status page
ToolsPack malware plugin
TorchServe Management API publicly exposed CVE-2023-43654
TorchServe Management API SSRF (CVE-2023-43654) CVE-2023-43654
Tornado Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-52804) CVE-2024-52804
Tornado Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2025-47287) CVE-2025-47287
Tornado debug mode
Tornado Improper Handling of Invalid Use of Special Elements Vulnerability (CVE-2026-35536) CVE-2026-35536
Tornado Improper Input Validation Vulnerability (CVE-2012-2374) CVE-2012-2374
Tornado Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-67724) CVE-2025-67724
Tornado Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2020-28476) CVE-2020-28476
Tornado Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2014-9720) CVE-2014-9720
Tornado Uncontrolled Resource Consumption Vulnerability (CVE-2025-67725) CVE-2025-67725
Tornado Uncontrolled Resource Consumption Vulnerability (CVE-2025-67726) CVE-2025-67726
Tornado Uncontrolled Resource Consumption Vulnerability (CVE-2026-31958) CVE-2026-31958
Tornado URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-28370) CVE-2023-28370
Tornado weak secret key
Total.js Directory Traversal (CVE-2019-8903) CVE-2019-8903
Trac CVE-2009-4405 Vulnerability (CVE-2009-4405) CVE-2009-4405
Trace.axd Detected
TRACE Method enabled
Trac Incorrect Default Permissions Vulnerability (CVE-2010-5108) CVE-2010-5108
TRACK Method enabled
Trac URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2008-2951) CVE-2008-2951
Tracy debugging tool enabled
Trojan shell script
TwistedHTTP Request Splitting Vulnerability (CVE-2020-10108) CVE-2020-10108
TwistedHTTP Request Splitting Vulnerability (CVE-2020-10109) CVE-2020-10109
Twisted Web HTTP Server Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Vulnerability (CVE-2022-21716) CVE-2022-21716
Twisted Web HTTP Server Direct Request ('Forced Browsing') Vulnerability (CVE-2016-1000111) CVE-2016-1000111
Twisted Web HTTP Server Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-21712) CVE-2022-21712
Twisted Web HTTP Server Improper Certificate Validation Vulnerability (CVE-2014-7143) CVE-2014-7143
Twisted Web HTTP Server Improper Certificate Validation Vulnerability (CVE-2019-12855) CVE-2019-12855
Twisted Web HTTP Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-39348) CVE-2022-39348
Twisted Web HTTP Server Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2019-12387) CVE-2019-12387