Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial Of Service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Prompt Leakage Llm Sensitive Information Disclosure Malware Missing Update Privilege Escalation SSRF Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Email injection CWE-20 CWE-20 High Envoy mishandles dropped and truncated datagrams Issue (CVE-2020-35471) CVE-2020-35471 High Envoy Proxy Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-15225) CVE-2019-15225 CWE-770 CWE-770 High Envoy Proxy Always-Incorrect Control Flow Implementation Vulnerability (CVE-2022-21655) CVE-2022-21655 CWE-670 CWE-670 High Envoy Proxy Always-Incorrect Control Flow Implementation Vulnerability (CVE-2024-53269) CVE-2024-53269 CWE-670 CWE-670 High Envoy Proxy Always-Incorrect Control Flow Implementation Vulnerability (CVE-2024-53271) CVE-2024-53271 CWE-670 CWE-670 High Envoy Proxy CVE-2020-25018 Vulnerability (CVE-2020-25018) CVE-2020-25018 High Envoy Proxy CVE-2023-27496 Vulnerability (CVE-2023-27496) CVE-2023-27496 High Envoy Proxy CVE-2024-23324 Vulnerability (CVE-2024-23324) CVE-2024-23324 High Envoy Proxy CVE-2024-45807 Vulnerability (CVE-2024-45807) CVE-2024-45807 High Envoy Proxy CVE-2024-45810 Vulnerability (CVE-2024-45810) CVE-2024-45810 High Envoy Proxy CVE-2025-30157 Vulnerability (CVE-2025-30157) CVE-2025-30157 High Envoy Proxy CVE-2026-26310 Vulnerability (CVE-2026-26310) CVE-2026-26310 High Envoy Proxy Detection of Error Condition Without Action Vulnerability (CVE-2024-27919) CVE-2024-27919 CWE-390 CWE-390 High Envoy Proxy Detection of Error Condition Without Action Vulnerability (CVE-2024-30255) CVE-2024-30255 CWE-390 CWE-390 High Envoy Proxy Excessive Iteration Vulnerability (CVE-2021-32778) CVE-2021-32778 CWE-834 CWE-834 High Envoy Proxy Excessive Iteration Vulnerability (CVE-2021-39204) CVE-2021-39204 CWE-834 CWE-834 High Envoy Proxy Improper Authentication Vulnerability (CVE-2021-21378) CVE-2021-21378 CWE-287 CWE-287 High Envoy Proxy Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2021-32780) CVE-2021-32780 CWE-754 CWE-754 High Envoy Proxy Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2021-39162) CVE-2021-39162 CWE-754 CWE-754 High Envoy Proxy Improper Handling of Exceptional Conditions Vulnerability (CVE-2024-23325) CVE-2024-23325 CWE-755 CWE-755 High Envoy Proxy Improper Handling of Highly Compressed Data (Data Amplification) Vulnerability (CVE-2022-29225) CVE-2022-29225 CWE-409 CWE-409 High Envoy Proxy Improper Input Validation Vulnerability (CVE-2019-9900) CVE-2019-9900 CWE-20 CWE-20 High Envoy Proxy Improper Null Termination Vulnerability (CVE-2025-66220) CVE-2025-66220 CWE-170 CWE-170 High Envoy Proxy Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2020-12604) CVE-2020-12604 CWE-119 CWE-119 High Envoy Proxy Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2021-32781) CVE-2021-32781 CWE-119 CWE-119 High Envoy Proxy Incomplete Cleanup Vulnerability (CVE-2023-35945) CVE-2023-35945 CWE-459 CWE-459 High Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2024-23326) CVE-2024-23326 High Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32777) CVE-2021-32777 CWE-863 CWE-863 High Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32779) CVE-2021-32779 CWE-863 CWE-863 High Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-39206) CVE-2021-39206 CWE-863 CWE-863 High Envoy Proxy Incorrect Authorization Vulnerability (CVE-2026-26308) CVE-2026-26308 CWE-863 CWE-863 High Envoy Proxy Insufficient Session Expiration Vulnerability (CVE-2025-55162) CVE-2025-55162 CWE-613 CWE-613 High Envoy Proxy Integer Overflow or Wraparound Vulnerability (CVE-2021-28682) CVE-2021-28682 CWE-190 CWE-190 High Envoy Proxy Integer Underflow (Wrap or Wraparound) Vulnerability (CVE-2024-32975) CVE-2024-32975 CWE-191 CWE-191 High Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-18836) CVE-2019-18836 CWE-835 CWE-835 High Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2024-32976) CVE-2024-32976 CWE-835 CWE-835 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2019-18838) CVE-2019-18838 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-28683) CVE-2021-28683 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-43824) CVE-2021-43824 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-23327) CVE-2024-23327 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-45809) CVE-2024-45809 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-53270) CVE-2024-53270 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2025-62409) CVE-2025-62409 CWE-476 CWE-476 High Envoy Proxy Other Vulnerability (CVE-2020-25017) CVE-2020-25017 High Envoy Proxy Other Vulnerability (CVE-2024-34363) CVE-2024-34363 High Envoy Proxy Reachable Assertion Vulnerability (CVE-2021-29258) CVE-2021-29258 CWE-617 CWE-617 High Envoy Proxy Reachable Assertion Vulnerability (CVE-2022-29228) CVE-2022-29228 CWE-617 CWE-617 High Envoy Proxy Reachable Assertion Vulnerability (CVE-2024-32475) CVE-2024-32475 CWE-617 CWE-617 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2019-15226) CVE-2019-15226 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-8663) CVE-2020-8663 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12603) CVE-2020-12603 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12605) CVE-2020-12605 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2023-44487) CVE-2023-44487 CWE-400 CWE-400 High Envoy Proxy Use After Free Vulnerability (CVE-2021-43825) CVE-2021-43825 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2021-43826) CVE-2021-43826 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2022-29227) CVE-2022-29227 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2023-35943) CVE-2023-35943 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2024-23322) CVE-2024-23322 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2024-32974) CVE-2024-32974 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2025-54588) CVE-2025-54588 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2025-62504) CVE-2025-62504 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2026-26330) CVE-2026-26330 CWE-416 CWE-416 High Envoy Wrong DOWNSTREAM_REMOTE_ADDRESS logged Issue (CVE-2020-35470) CVE-2020-35470 High EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38844) CVE-2022-38844 CWE-1236 CWE-1236 High EspoCRM Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2025-32390) CVE-2025-32390 CWE-138 CWE-138 High EspoCRM Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2019-14351) CVE-2019-14351 CWE-307 CWE-307 High EspoCRM Relative Path Traversal Vulnerability (CVE-2026-33733) CVE-2026-33733 CWE-23 CWE-23 High EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-38843) CVE-2022-38843 CWE-434 CWE-434 High EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5965) CVE-2023-5965 CWE-434 CWE-434 High EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5966) CVE-2023-5966 CWE-434 CWE-434 High Expression language injection CWE-917 CWE-917 High ExpressJs Local File Read via the layout parameter CWE-22 CWE-22 High Ext JS arbitrary file read CWE-22 CWE-22 High Ext JS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2007-6758) CVE-2007-6758 CWE-918 CWE-918 High 1...15161718...176 16 / 176