Vulnerability Name CVE Severity
.NET HTTP Remoting publicly exposed
.NET JSON.NET Deserialization RCE
AbanteCart Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2025-50971) CVE-2025-50971
AbanteCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-10755) CVE-2016-10755
AbanteCart Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26521) CVE-2022-26521
ACME mini_httpd arbitrary file read CVE-2018-18778
Adminer 4.6.2 file disclosure vulnerability
Adobe Coldfusion 8 multiple linked XSS vulnerabilies CVE-2009-1872
Adobe ColdFusion 9 administrative login bypass CVE-2013-0625 CVE-2013-0629 CVE-2013-0631 CVE-2013-0632
Adobe ColdFusion directory traversal CVE-2013-3336
Adobe Experience Manager Blind XXE via package upload CVE-2025-54251 CVE-2025-54249 CVE-2025-54252 CVE-2025-54250 CVE-2025-54247 CVE-2025-54248 CVE-2025-54246
Adobe Experience Manager exposed user passwords via querybuilder CVE-2025-54251 CVE-2025-54249 CVE-2025-54252 CVE-2025-54250 CVE-2025-54247 CVE-2025-54248 CVE-2025-54246
Adobe Experience Manager Expression Language injection via cloudsettings CVE-2025-54251 CVE-2025-54249 CVE-2025-54252 CVE-2025-54250 CVE-2025-54247 CVE-2025-54248 CVE-2025-54246
Adobe Experience Manager Misconfiguration CVE-2016-0957
Adobe Experience Manager SSRF via MS token verify servlet CVE-2025-54251 CVE-2025-54249 CVE-2025-54252 CVE-2025-54250 CVE-2025-54247 CVE-2025-54248 CVE-2025-54246
Adobe Experience Manager writable JCR nodes via querybuilder CVE-2025-54251 CVE-2025-54249 CVE-2025-54252 CVE-2025-54250 CVE-2025-54247 CVE-2025-54248 CVE-2025-54246
Adobe Flex 3 DOM-based XSS vulnerability CVE-2008-2640
Agentejo Cockpit CMS resetpassword NoSQLi (CVE-2020-35847) CVE-2020-35847
AjaxControlToolkit directory traversal CVE-2015-4670
AjaxPro.NET Professional Deserialization RCE (CVE-2021-23758) CVE-2021-23758
Akeeba backup access control bypass
Alibaba Nacos Authentication Bypass (CVE-2021-29441) CVE-2021-29441
Amazon S3 publicly writable bucket
Ampache Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-51484) CVE-2024-51484
Ampache Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-51485) CVE-2024-51485
Ampache Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-51487) CVE-2024-51487
Ampache Deserialization of Untrusted Data Vulnerability (CVE-2017-18375) CVE-2017-18375
Ampache Improper Access Control Vulnerability (CVE-2021-21399) CVE-2021-21399
Ampache Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-3929) CVE-2008-3929
Ampache Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-51486) CVE-2024-51486
Ampache Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-12385) CVE-2019-12385
Ampache Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-0771) CVE-2023-0771
Ampache Other Vulnerability (CVE-2006-5668) CVE-2006-5668
Ampache Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-4665) CVE-2022-4665
Angular Inefficient Regular Expression Complexity Vulnerability (CVE-2024-21490) CVE-2024-21490
AngularJS client-side template injection
AngularJS Improper Input Validation Vulnerability (CVE-2019-10768) CVE-2019-10768
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2022-25844) CVE-2022-25844
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2024-21490) CVE-2024-21490
Apache ActiveMQ default administrative credentials
Apache Airflow default credentials
Apache Airflow Experimental API Auth Bypass CVE-2020-13927 CVE-2020-13927
Apache Airflow Unauthorized Access Vulnerability
Apache Axis2 administration console weak password
Apache Axis2 xsd local file inclusion
Apache CouchDB JSON Remote Privilege Escalation Vulnerability CVE-2017-12635
Apache Flink jobmanager/logs Path Traversal CVE-2020-17519
Apache Geronimo default administrative credentials
Apache HTTP Server Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9517) CVE-2019-9517
Apache HTTP Server Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-30522) CVE-2022-30522
Apache HTTP Server Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-27316) CVE-2024-27316
Apache HTTP Server Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-29168) CVE-2026-29168
Apache HTTP Server Buffer Over-read Vulnerability (CVE-2026-34059) CVE-2026-34059
Apache HTTP Server Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2019-0217) CVE-2019-0217
Apache HTTP Server Confusion Attacks CVE-2024-38472 CVE-2024-39573 CVE-2024-38477 CVE-2024-38476 CVE-2024-38475 CVE-2024-38474 CVE-2024-38473 CVE-2023-38709
Apache HTTP Server Cryptographic Issues Vulnerability (CVE-2016-0736) CVE-2016-0736
Apache HTTP Server CVE-1999-0236 Vulnerability (CVE-1999-0236) CVE-1999-0236
Apache HTTP Server CVE-2002-0392 Vulnerability (CVE-2002-0392) CVE-2002-0392
Apache HTTP Server CVE-2002-0839 Vulnerability (CVE-2002-0839) CVE-2002-0839
Apache HTTP Server CVE-2013-2249 Vulnerability (CVE-2013-2249) CVE-2013-2249
Apache HTTP Server CVE-2016-5387 Vulnerability (CVE-2016-5387) CVE-2016-5387
Apache HTTP Server CVE-2016-8743 Vulnerability (CVE-2016-8743) CVE-2016-8743
Apache HTTP Server CVE-2019-0190 Vulnerability (CVE-2019-0190) CVE-2019-0190
Apache HTTP Server CVE-2019-0215 Vulnerability (CVE-2019-0215) CVE-2019-0215
Apache HTTP Server Double Free Vulnerability (CVE-2026-23918) CVE-2026-23918
Apache HTTP Server Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-30556) CVE-2022-30556
Apache HTTP Server Improper Access Control Vulnerability (CVE-2016-4979) CVE-2016-4979
Apache HTTP Server Improper Authentication Vulnerability (CVE-2025-49812) CVE-2025-49812
Apache HTTP Server Improper Encoding or Escaping of Output Vulnerability (CVE-2024-38473) CVE-2024-38473
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2016-2161) CVE-2016-2161
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2017-15715) CVE-2017-15715
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2024-39573) CVE-2024-39573
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2024-42516) CVE-2024-42516
Apache HTTP Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-41773) CVE-2021-41773
Apache HTTP Server Improper Locking Vulnerability (CVE-2002-1850) CVE-2002-1850