Vulnerability Name CVE Severity
AngularJS client-side template injection
Apache Tomcat JK connector security bypass CVE-2007-1860
Authentication bypass via MongoDB operator injection
Client-Side Prototype Pollution
Cross-site Scripting via File Upload
Database User Has Admin Privileges
Deserialization of Untrusted Data (.NET BinaryFormatter Object Deserialization)
Deserialization of Untrusted Data (Java JSON Deserialization) Fastjson
Deserialization of Untrusted Data (Java JSON Deserialization) Genson
Deserialization of Untrusted Data (Java JSON Deserialization) Jackson
Deserialization of Untrusted Data (Java JSON Deserialization) JsonIO
Deserialization of Untrusted Data (Java Object Deserialization)
Deserialization of Untrusted Data (XStream)
DotNetNuke multiple vulnerabilities CVE-2012-1030
Email Header Injection
Email Header Injection (AcuSensor)
Email injection
File upload XSS (Java applet)
Http redirect security bypass
Java Debug Wire Protocol remote code execution
JIRA Security Advisory 2013-02-21
JSP authentication bypass
MediaWiki chunked uploads security issue CVE-2013-2114
MongoDB $where operator JavaScript injection
MongoDB injection
Multiple vulnerabilities reported in Parallels Plesk Sitebuilder
node-serialize Insecure Deserialization CVE-2017-5941
Prototype pollution
Python pickle serialization
Rails mass assignment
Server-side JavaScript injection
TCPDF arbitrary file read
Uncontrolled format string
Unprotected phpMyAdmin interface
Unrestricted access to Haproxy Data Plane API
Unrestricted file upload vulnerability in ofc_upload_image.php CVE-2009-4140
Unsafe use of Reflection
VirtueMart access control bypass
webadmin.php script
Web Cache Deception
WordPress MailPoet Newsletters (wysija-newsletters) unauthenticated file upload
WordPress plugin All in One SEO Pack privilege escalation vulnerabilities
WordPress plugin Custom Contact Forms critical vulnerability
WordPress plugin WPtouch insecure nonce generation
XSLT injection