Vulnerability Name CVE Severity
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14329) CVE-2019-14329
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14330) CVE-2019-14330
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14331) CVE-2019-14331
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14349) CVE-2019-14349
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14350) CVE-2019-14350
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14546) CVE-2019-14546
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14547) CVE-2019-14547
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14548) CVE-2019-14548
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14549) CVE-2019-14549
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14550) CVE-2019-14550
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3539) CVE-2021-3539
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-59428) CVE-2025-59428
EspoCRM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Vulnerability (CVE-2026-33657) CVE-2026-33657
EspoCRM Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2025-32390) CVE-2025-32390
EspoCRM Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') Vulnerability (CVE-2025-52575) CVE-2025-52575
EspoCRM Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2019-14351) CVE-2019-14351
EspoCRM Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2025-32385) CVE-2025-32385
EspoCRM Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2025-52892) CVE-2025-52892
EspoCRM Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7986) CVE-2014-7986
EspoCRM Relative Path Traversal Vulnerability (CVE-2026-33733) CVE-2026-33733
EspoCRM Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-46736) CVE-2023-46736
EspoCRM Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-33534) CVE-2026-33534
EspoCRM Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2026-33659) CVE-2026-33659
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-38843) CVE-2022-38843
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5965) CVE-2023-5965
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5966) CVE-2023-5966
EspoCRM URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-24818) CVE-2024-24818
Express cookie-session weak secret key
Express Development Mode enabled
Express express-session weak secret key
Expression language injection
ExpressJs Local File Read via the layout parameter
Ext JS arbitrary file read
Ext JS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-8046) CVE-2018-8046
Ext JS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2007-6758) CVE-2007-6758
F5 BIG-IP Cookie Information Disclosure
F5 BIG-IP Request Smuggling (CVE-2023-46747) CVE-2023-46747
F5 BIG-IP Traffic Management User Interface (TMUI) RCE CVE-2020-5902
F5 iControl REST unauthenticated remote command execution vulnerability CVE-2021-22986
Family Connections Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-0699) CVE-2012-0699
Family Connections Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-3419) CVE-2010-3419
Family Connections Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-5130) CVE-2011-5130
Family Connections Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-2901) CVE-2008-2901
Family Connections Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-2010) CVE-2009-2010
Family Connections Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-4338) CVE-2007-4338
fancybox Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-1494) CVE-2015-1494
FastAdmin Path Traversal (CVE-2024-7928) CVE-2024-7928
FastCGI Unauthorized Access Vulnerability
FCKeditor arbitrary file upload CVE-2009-2265
FCKeditor spellchecker.php cross site scripting vulnerability CVE-2012-4000
File Content Disclosure in Action View CVE-2019-5418
File creation via HTTP method PUT
File tampering
File Upload Functionality Detected
File upload XSS (Java applet)
Firebase database accessible without authentication
Flask debug mode
Flask weak secret key
Flex BlazeDS AMF Deserialization RCE CVE-2017-5641
Flowise Authentication Bypass (CVE-2024-31621) CVE-2024-31621
FluxBB CVE-2011-3621 Vulnerability (CVE-2011-3621) CVE-2011-3621
FluxBB Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-9574) CVE-2014-9574
FluxBB Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-35240) CVE-2020-35240
FluxBB Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-43677) CVE-2021-43677
FluxBB Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-44110) CVE-2025-44110
FluxBB Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-10029) CVE-2014-10029
FluxBB Other Vulnerability (CVE-2014-10030) CVE-2014-10030
FluxBB Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2020-28873) CVE-2020-28873
ForgeRock AM / OpenAM Deserialization RCE (CVE-2021-35464) CVE-2021-35464
ForgeRock OpenAM Deserialization RCE (CVE-2021-29156) CVE-2021-29156
Fortigate SSL VPN Arbitrary File reading (CVE-2018-13379) CVE-2018-13379
Fortinet Authentication bypass on administrative interface CVE-2022-40684
Fortinet FortiNAC RCE via arbitrary file upload CVE-2022-39952
Fortinet Out-Of-Bound Memory Write RCE (CVE-2024-21762) CVE-2024-21762
FortiWeb Authentication Bypass (CVE-2025-64446) CVE-2025-64446 CVE-2025-58034