Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial Of Service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File-upload File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Prompt Leakage Llm Sensitive Information Disclosure Malware Missing Update Privilege Escalation RCE SSRF Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Uncontrolled format string CWE-134 CWE-134 High Underscore.js Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-27601) CVE-2026-27601 CWE-770 CWE-770 High Underscore.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-23358) CVE-2021-23358 CWE-94 CWE-94 High Undertow CVE-2022-1259 Vulnerability (CVE-2022-1259) CVE-2022-1259 High Undertow CVE-2023-3223 Vulnerability (CVE-2023-3223) CVE-2023-3223 High Undertow Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-3859) CVE-2021-3859 CWE-668 CWE-668 High Undertow Improper Input Validation Vulnerability (CVE-2020-1757) CVE-2020-1757 CWE-20 CWE-20 High Undertow Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2020-10705) CVE-2020-10705 CWE-119 CWE-119 High Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2017-12165) CVE-2017-12165 CWE-444 CWE-444 High Undertow Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2017-2670) CVE-2017-2670 CWE-835 CWE-835 High Undertow Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2023-1108) CVE-2023-1108 CWE-835 CWE-835 High Undertow Missing Authorization Vulnerability (CVE-2019-10184) CVE-2019-10184 CWE-862 CWE-862 High Undertow Unchecked Return Value Vulnerability (CVE-2022-1319) CVE-2022-1319 CWE-252 CWE-252 High Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2019-14888) CVE-2019-14888 CWE-400 CWE-400 High Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2019-19343) CVE-2019-19343 CWE-400 CWE-400 High Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2021-3629) CVE-2021-3629 CWE-400 CWE-400 High Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2021-3690) CVE-2021-3690 CWE-400 CWE-400 High Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2022-2053) CVE-2022-2053 CWE-400 CWE-400 High Unprotected phpMyAdmin interface CWE-205 CWE-205 High Unrestricted access to Caddy API interface CWE-200 CWE-200 High Unrestricted access to Haproxy Data Plane API CWE-200 CWE-200 High Unrestricted access to Kong Gateway API CWE-200 CWE-200 High Unrestricted access to NGINX+ API interface (read write) CWE-200 CWE-200 High Unrestricted access to Odoo DB manager CWE-200 CWE-200 High Unrestricted File Upload CWE-434 CWE-434 High Unrestricted file upload vulnerability in ofc_upload_image.php CVE-2009-4140 CWE-434 CWE-434 High Unsafe use of Reflection CWE-470 CWE-470 High Unvalidated JWT jku parameter CWE-287 CWE-287 High Unvalidated JWT x5u parameter CWE-287 CWE-287 High Uploadify arbitrary file upload CWE-434 CWE-434 High User controllable script source CWE-79 CWE-79 High uWSGI Path Traversal vulnerability CVE-2018-7490 CWE-22 CWE-22 High uWSGI Unauthorized Access Vulnerability CWE-78 CWE-78 High Vanilla Forums Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000432) CVE-2017-1000432 CWE-352 CWE-352 High Vanilla Forums CVE-2013-3528 Vulnerability (CVE-2013-3528) CVE-2013-3528 High Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499) CVE-2018-19499 CWE-502 CWE-502 High Vanilla Forums Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3613) CVE-2011-3613 CWE-200 CWE-200 High Vanilla Forums Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-10073) CVE-2016-10073 CWE-200 CWE-200 High Vanilla Forums Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2013-3527) CVE-2013-3527 CWE-138 CWE-138 High Varnish Cache Integer Overflow or Wraparound Vulnerability (CVE-2017-12425) CVE-2017-12425 CWE-190 CWE-190 High Varnish Cache Other Vulnerability (CVE-2013-4090) CVE-2013-4090 High Varnish Cache Other Vulnerability (CVE-2015-8852) CVE-2015-8852 High Varnish Cache Reachable Assertion Vulnerability (CVE-2019-15892) CVE-2019-15892 CWE-617 CWE-617 High vBSEO 3.6.0 PHP code injection CVE-2012-5223 CWE-94 CWE-94 High vBulletin 4 (up to 4.1.2) search.php SQL injection CWE-89 CWE-89 High vBulletin 5 CONNECT remote code execution CWE-94 CWE-94 High vBulletin 5.1.2 SQL injection CVE-2014-5102 CWE-89 CWE-89 High vBulletin 5.6.1 nodeId SQL injection CVE-2020-12720 CWE-94 CWE-94 High vBulletin 5.x 0day pre-auth RCE CWE-94 CWE-94 High vBulletin customer number disclosure CVE-2013-6129 CWE-200 CWE-200 High vBulletin PHP object injection vulnerability CWE-915 CWE-915 High vBulletin Pre-Auth RCE Vulnerability CVE-2020-17496 CWE-94 CWE-94 High vBulletin routestring Local File Inclusion CWE-98 CWE-98 High Vertical Broken Function Level Authorization (BFLA) CWE-639 CWE-639 High Vertical IDOR/BOLA (Broken Object Level Authorization) CWE-639 CWE-639 High Virtual Host locations misconfiguration CWE-200 CWE-200 High VirtueMart access control bypass CWE-287 CWE-287 High Vite Arbitrary File Read (CVE-2025-30208, CVE-2025-31125) CVE-2025-30208 CVE-2025-31125 CWE-200 CWE-200 High VMware directory traversal and privilege escalation vulnerabilities CVE-2009-2267 CVE-2009-3733 CWE-22 CWE-22 High VMware Horizon Log4Shell RCE CVE-2021-44228 CWE-78 CWE-78 High VMware vCenter Log4Shell RCE CVE-2021-44228 CWE-78 CWE-78 High VMware vCenter Server Unauthorized Remote Code Execution CVE-2021-21972 CWE-78 CWE-78 High VMware vCenter vcavbootstrap Arbitrary File Read CWE-22 CWE-918 CWE-22 CWE-918 High VMware vRealize Operations Server Side Request Forgery (SSRF) vulnerability CVE-2021-21975 CWE-918 CWE-918 High VMware Workspace ONE Access SSTI (CVE-2022-22954) CVE-2022-22954 CWE-94 CWE-94 High Vulnerabilities in SharePoint could allow elevation of privilege CVE-2012-1859 CWE-79 CWE-79 High Vulnerable package dependencies [high] CWE-1104 CWE-1104 High Vulnerable project dependencies CWE-1395 CWE-1395 High W3 Total Cache CVE-2019-6715 Vulnerability (CVE-2019-6715) CVE-2019-6715 High Weak password CWE-200 CWE-200 High Weak Secret is Used to Sign JWT CWE-347 CWE-347 High Weak WordPress security key CWE-326 CWE-326 High web.xml configuration file disclosure CWE-538 CWE-538 High webadmin.php script CWE-552 CWE-552 High Web application default/weak credentials CWE-200 CWE-200 High 1...60616263...179 61 / 179