Vulnerability Name CVE Severity
Undertow Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-7816) CVE-2014-7816
Undertow Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') Vulnerability (CVE-2018-1067) CVE-2018-1067
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2017-7559) CVE-2017-7559
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2020-10687) CVE-2020-10687
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2020-10719) CVE-2020-10719
Undertow Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2021-20220) CVE-2021-20220
Undertow Incorrect Authorization Vulnerability (CVE-2017-12196) CVE-2017-12196
Unicode Transformation (Best-Fit Mapping)
Unprotected Apache NiFi API interface
Unprotected JSON file leaking secrets
Unprotected Kong Gateway Admin API interface
Unrestricted access to AnythingLLM API CVE-2024-6842
Unrestricted access to MLflow
Unrestricted access to NGINX+ API interface (read only)
Unrestricted access to NGINX+ Dashboard
Unrestricted access to NGINX+ Upstream HTTP interface
Unsafe value for session tracking in WEB-INF/web.xml
URL rewrite vulnerability CVE-2018-14773
User-controlled form action
User controllable charset
User controllable tag parameter
User controllable tag parameter (DOM-based)
Vanilla Forums Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2018-15833) CVE-2018-15833
Vanilla Forums Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3812) CVE-2011-3812
Vanilla Forums Improper Input Validation Vulnerability (CVE-2011-0908) CVE-2011-0908
Vanilla Forums Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-0526) CVE-2011-0526
Vanilla Forums Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-0909) CVE-2011-0909
Vanilla Forums Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-1009) CVE-2011-1009
Vanilla Forums Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-9685) CVE-2014-9685
Vanilla Forums Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17571) CVE-2018-17571
Vanilla Forums Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-8279) CVE-2019-8279
Vanilla Forums Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-8825) CVE-2020-8825
Vanilla Forums Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-16410) CVE-2018-16410
Vanilla Forums Other Vulnerability (CVE-2011-0910) CVE-2011-0910
Varnish Cache Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2013-4484) CVE-2013-4484
Verb tampering via misconfigured security constraint
VideoJS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-23414) CVE-2021-23414
ViewState MAC Disabled
ViewStateMac is Not Enabled
Virtual host directory listing
Vulnerable JavaScript libraries
Vulnerable package dependencies [medium]
W3 total cache debug mode
Web2py weak secret key
Webalizer script
Web Cache Poisoning DoS
Web Cache Poisoning DoS (for javascript)
Web Cache Poisoning DoS through HTTP/2 headers
WebDAV directory listing
WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-20420) CVE-2018-20420
WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-22474) CVE-2020-22474
WeBid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3815) CVE-2011-3815
WeBid Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-5101) CVE-2014-5101
WeBid Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1000868) CVE-2018-1000868
WeBid Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-11592) CVE-2019-11592
WeBid Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7117) CVE-2008-7117
WeBid Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7118) CVE-2008-7118
WebLogic Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2018-10237) CVE-2018-10237
WebLogic Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-5397) CVE-2020-5397
WebLogic CVE-2008-2578 Vulnerability (CVE-2008-2578) CVE-2008-2578
WebLogic CVE-2010-2375 Vulnerability (CVE-2010-2375) CVE-2010-2375
WebLogic CVE-2010-4453 Vulnerability (CVE-2010-4453) CVE-2010-4453
WebLogic CVE-2016-0675 Vulnerability (CVE-2016-0675) CVE-2016-0675
WebLogic CVE-2016-0696 Vulnerability (CVE-2016-0696) CVE-2016-0696
WebLogic CVE-2016-0700 Vulnerability (CVE-2016-0700) CVE-2016-0700
WebLogic CVE-2016-3416 Vulnerability (CVE-2016-3416) CVE-2016-3416
WebLogic CVE-2016-3445 Vulnerability (CVE-2016-3445) CVE-2016-3445
WebLogic CVE-2016-5488 Vulnerability (CVE-2016-5488) CVE-2016-5488
WebLogic CVE-2017-10063 Vulnerability (CVE-2017-10063) CVE-2017-10063
WebLogic CVE-2017-10123 Vulnerability (CVE-2017-10123) CVE-2017-10123
WebLogic CVE-2017-10148 Vulnerability (CVE-2017-10148) CVE-2017-10148
WebLogic CVE-2017-10178 Vulnerability (CVE-2017-10178) CVE-2017-10178
WebLogic CVE-2017-10336 Vulnerability (CVE-2017-10336) CVE-2017-10336
WebLogic CVE-2018-1257 Vulnerability (CVE-2018-1257) CVE-2018-1257
WebLogic CVE-2018-1313 Vulnerability (CVE-2018-1313) CVE-2018-1313