Vulnerability Name CVE Severity
Grafana Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2024-9264) CVE-2024-9264
Grafana Improper Verification of Cryptographic Signature Vulnerability (CVE-2022-31123) CVE-2022-31123
Grafana Incorrect Authorization Vulnerability (CVE-2022-31107) CVE-2022-31107
Grafana Incorrect Authorization Vulnerability (CVE-2026-21721) CVE-2026-21721
Grafana Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-27962) CVE-2021-27962
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2022-31130) CVE-2022-31130
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2019-15043) CVE-2019-15043
Grafana Open Redirect (CVE-2025-4123) CVE-2025-4123
Grafana Out-of-bounds Write Vulnerability (CVE-2026-27880) CVE-2026-27880
Grafana Plugin Dir Traversal (CVE-2021-43798) CVE-2021-43798
Grafana Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-13379) CVE-2020-13379
Grafana Snapshot Authentication Bypass (CVE-2021-39226) CVE-2021-39226
Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-21720) CVE-2026-21720
Grafana URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29170) CVE-2022-29170
Grandnode Path Traversal (CVE-2019-12276) CVE-2019-12276
Grav CMS Unauthenticated RCE (CVE-2021-21425) CVE-2021-21425
GSAP CVE-2020-28478 Vulnerability (CVE-2020-28478) CVE-2020-28478
Gunicorn Improper Neutralization of CRLF Sequences ('CRLF Injection') Vulnerability (CVE-2018-1000164) CVE-2018-1000164
Hadoop YARN ResourceManager publicly accessible
Handlebars Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2026-33939) CVE-2026-33939
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920) CVE-2019-20920
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-33938) CVE-2026-33938
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-33940) CVE-2026-33940
Handlebars Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-33941) CVE-2026-33941
Handlebars Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20922) CVE-2019-20922
Harbor Unauthorized Access Vulnerability CVE-2022-46463
Hiawatha Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-8358) CVE-2019-8358
Hibernate Query Language (HQL) Injection
Highcharts JS Incorrect Regular Expression Vulnerability (CVE-2018-20801) CVE-2018-20801
HipChat for JIRA plugin - Velocity template injection CVE-2015-5603
Horde/IMP Plesk webmail exploit
Horde Imp Unauthenticated Remote Command Execution CVE-2018-19518
Horde remote code execution CVE-2014-1691
Horizontal Broken Function Level Authorization (BFLA)
Horizontal IDOR/BOLA (Broken Object Level Authorization)
HTTP.sys remote code execution vulnerability CVE-2015-1635
HTTP/2 pseudo-header server side request forgery
Http redirect security bypass
HTTP verb tampering via POST
IBMHttpServer Expired Pointer Dereference Vulnerability (CVE-2026-8854) CVE-2026-8854
IBMHttpServer Heap-based Buffer Overflow Vulnerability (CVE-2026-8834) CVE-2026-8834
IBMHttpServer Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-9170) CVE-2026-9170
IBMHttpServer Improper Input Validation Vulnerability (CVE-2023-26281) CVE-2023-26281
IBMHttpServer NULL Pointer Dereference Vulnerability (CVE-2026-8850) CVE-2026-8850
IBMHttpServer Observable Discrepancy Vulnerability (CVE-2023-32342) CVE-2023-32342
IBMHttpServer Other Vulnerability (CVE-2000-1168) CVE-2000-1168
IBMHttpServer Other Vulnerability (CVE-2004-1082) CVE-2004-1082
IBMHttpServer Reachable Assertion Vulnerability (CVE-2026-8852) CVE-2026-8852
IBMHttpServer Untrusted Pointer Dereference Vulnerability (CVE-2026-8835) CVE-2026-8835
IBM Lotus Domino web server Cross-Site Scripting vulnerabilities CVE-2012-3301 CVE-2012-3302
IBM RTC Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-4252) CVE-2019-4252
IBM RTC Improper Privilege Management Vulnerability (CVE-2021-29774) CVE-2021-29774
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2016-9707) CVE-2016-9707
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-1103) CVE-2017-1103
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-20502) CVE-2021-20502
IBM RTC Inadequate Encryption Strength Vulnerability (CVE-2017-1701) CVE-2017-1701
IBM RTC Inadequate Encryption Strength Vulnerability (CVE-2020-4965) CVE-2020-4965
IBM RTC Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-7440) CVE-2015-7440
IBM RTC Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-29844) CVE-2021-29844
IBM Web Content Manager XPath injection CVE-2013-6735
IBM WebSEAL 7PK - Security Features Vulnerability (CVE-2016-3025) CVE-2016-3025
IBM WebSEAL CVE-2018-1850 Vulnerability (CVE-2018-1850) CVE-2018-1850
IBM WebSEAL CVE-2019-4135 Vulnerability (CVE-2019-4135) CVE-2019-4135
IBM WebSEAL CVE-2019-4145 Vulnerability (CVE-2019-4145) CVE-2019-4145
IBM WebSEAL Improper Input Validation Vulnerability (CVE-2019-4036) CVE-2019-4036
IBM WebSEAL Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-4707) CVE-2019-4707
IBM WebSEAL Inadequate Encryption Strength Vulnerability (CVE-2018-1814) CVE-2018-1814
IBM WebSEAL Insufficiently Protected Credentials Vulnerability (CVE-2021-20439) CVE-2021-20439
IBM WebSEAL Other Vulnerability (CVE-2023-30997) CVE-2023-30997
IBM WebSEAL Other Vulnerability (CVE-2023-30998) CVE-2023-30998
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2023-38371) CVE-2023-38371
IBM WebSEAL Use of Hard-coded Credentials Vulnerability (CVE-2018-1887) CVE-2018-1887
IBM WebSphere/WebLogic application source file exposure
IBM WebSphere administration console weak password
IBM WebSphere RCE Java Deserialization Vulnerability CVE-2015-7450