Vulnerability Name CVE Severity
Handlebars CVE-2021-23369 Vulnerability (CVE-2021-23369) CVE-2021-23369
Handlebars Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2026-33939) CVE-2026-33939
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920) CVE-2019-20920
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-33937) CVE-2026-33937
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-33938) CVE-2026-33938
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-33940) CVE-2026-33940
Handlebars Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-8861) CVE-2015-8861
Handlebars Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-33916) CVE-2026-33916
Handlebars Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-33941) CVE-2026-33941
Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2019-19919) CVE-2019-19919
Handlebars Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20922) CVE-2019-20922
Handlebars Other Vulnerability (CVE-2021-23383) CVE-2021-23383
Harbor Unauthorized Access Vulnerability CVE-2022-46463
Hashicorp Consul API is accessible without authentication
Hasura GraphQL API without authentication
Hesk Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3743) CVE-2011-3743
Hesk Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-5287) CVE-2011-5287
Hesk Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13897) CVE-2020-13897
Hiawatha CVE-2025-57783 Vulnerability (CVE-2025-57783) CVE-2025-57783
Hiawatha CVE-2025-57784 Vulnerability (CVE-2025-57784) CVE-2025-57784
Hiawatha Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-8358) CVE-2019-8358
Hibernate Query Language (HQL) Injection
Highcharts JS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-29489) CVE-2021-29489
Highcharts JS Incorrect Regular Expression Vulnerability (CVE-2018-20801) CVE-2018-20801
HipChat for JIRA plugin - Velocity template injection CVE-2015-5603
Horde/IMP Plesk webmail exploit
Horde Imp Unauthenticated Remote Command Execution CVE-2018-19518
Horde remote code execution CVE-2014-1691
Horizontal Broken Function Level Authorization (BFLA)
Horizontal IDOR/BOLA (Broken Object Level Authorization)
Host header attack
Hostile subdomain takeover
HSQLDB CVE-2022-41853 Vulnerability (CVE-2022-41853) CVE-2022-41853
HTML Attribute Injection
HTML Form found in redirect page
HTML Injection
HTML Injection (requiring unencoded tag delimiter)
HTTP.sys remote code execution vulnerability CVE-2015-1635
HTTP/2 pseudo-header server side request forgery
HTTP Header Injection
HTTP header reflected in cached response
Httpoxy vulnerability
HTTP parameter pollution
Http redirect security bypass
HTTP response splitting with cloud storage
HTTPS connection uses outdated TLS version
HTTPS connection with weak key length
HTTP Strict Transport Security (HSTS) Errors and Warnings
HTTP Strict Transport Security (HSTS) Policy Not Enabled
HTTP verb tampering via POST
IBM Aspera Faspex RCE (CVE-2022-47986) CVE-2022-47986
IBMHttpServer CVE-2010-0425 Vulnerability (CVE-2010-0425) CVE-2010-0425
IBMHttpServer CVE-2012-5955 Vulnerability (CVE-2012-5955) CVE-2012-5955
IBMHttpServer Expired Pointer Dereference Vulnerability (CVE-2026-8854) CVE-2026-8854
IBMHttpServer Heap-based Buffer Overflow Vulnerability (CVE-2026-8834) CVE-2026-8834
IBMHttpServer Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-8855) CVE-2026-8855
IBMHttpServer Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-9170) CVE-2026-9170
IBMHttpServer Improper Input Validation Vulnerability (CVE-2023-26281) CVE-2023-26281
IBMHttpServer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-1360) CVE-2011-1360
IBMHttpServer Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2015-4947) CVE-2015-4947
IBMHttpServer NULL Pointer Dereference Vulnerability (CVE-2026-8850) CVE-2026-8850
IBMHttpServer Observable Discrepancy Vulnerability (CVE-2023-32342) CVE-2023-32342
IBMHttpServer Other Vulnerability (CVE-2000-0505) CVE-2000-0505
IBMHttpServer Other Vulnerability (CVE-2000-1168) CVE-2000-1168
IBMHttpServer Other Vulnerability (CVE-2001-0122) CVE-2001-0122
IBMHttpServer Other Vulnerability (CVE-2002-1822) CVE-2002-1822
IBMHttpServer Other Vulnerability (CVE-2004-0263) CVE-2004-0263
IBMHttpServer Other Vulnerability (CVE-2004-0492) CVE-2004-0492
IBMHttpServer Other Vulnerability (CVE-2004-0493) CVE-2004-0493
IBMHttpServer Other Vulnerability (CVE-2004-1082) CVE-2004-1082
IBMHttpServer Other Vulnerability (CVE-2006-3918) CVE-2006-3918
IBMHttpServer Reachable Assertion Vulnerability (CVE-2026-8852) CVE-2026-8852
IBMHttpServer Uncontrolled Resource Consumption Vulnerability (CVE-2026-8856) CVE-2026-8856
IBMHttpServer Untrusted Pointer Dereference Vulnerability (CVE-2026-8835) CVE-2026-8835
IBM Lotus Domino web server Cross-Site Scripting vulnerabilities CVE-2012-3301 CVE-2012-3302