CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2021-45105 HIGH

Apache Log4j2 does not always protect from infinite recursion in lookup evaluation

CVSS 8.6 EPSS 100.00% Dec 18, 2021
CVE-2021-2351 HIGH

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi…

CVSS 8.3 EPSS 2.43% Jul 20, 2021
CVE-2021-35043 HIGH

AntiSamy: XSS via HTML attributes

CVSS 8.8 EPSS 1.51% Jul 19, 2021
CVE-2021-36374 MEDIUM

Apache Ant ZIP, and ZIP based, archive denial of service vulerability

CVSS 5.5 EPSS 2.63% Jul 14, 2021
CVE-2021-36373 MEDIUM

Apache Ant TAR archive denial of service vulnerability

CVSS 5.5 EPSS 2.52% Jul 14, 2021
CVE-2020-11987 HIGH

batik: SSRF due to improper input validation by the NodePickerPanel

CVSS 8.2 EPSS 13.28% Feb 24, 2021
CVE-2020-1945 MEDIUM

ant: insecure temporary file vulnerability

CVSS 6.3 EPSS 1.77% May 14, 2020
CVE-2020-5397 MEDIUM

CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux

CVSS 5.3 EPSS 2.43% Jan 17, 2020
CVE-2020-5398 HIGH

RFD Attack via "Content-Disposition" Header Sourced from Request Input by Spring MVC or Spring WebFlux Application

CVSS 8.0 EPSS 88.77% Jan 16, 2020
CVE-2019-10219 MEDIUM

hibernate-validator: safeHTML validator allows XSS

CVSS 6.1 EPSS 2.16% Nov 8, 2019
CVE-2019-10086 HIGH

apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default

CVSS 7.3 EPSS 28.38% Aug 20, 2019
CVE-2019-13990 CRITICAL

libquartz: XXE attacks via job description

CVSS 9.8 EPSS 16.20% Jul 26, 2019
CVE-2019-11358 MEDIUM

jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection

CVSS 6.1 EPSS 86.82% Apr 19, 2019
MavenNuGetPackagistPyPIRubyGemsnpm
CVE-2018-8013 CRITICAL

batik: information disclosure when deserializing

CVSS 9.8 EPSS 18.93% May 24, 2018
CVE-2018-1258 HIGH

spring-security-core: Unauthorized Access with Spring Security Method Security

CVSS 8.8 EPSS 2.46% May 11, 2018
CVE-2018-2738 MEDIUM

Vulnerability in the Oracle Retail Central Office component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13…

CVSS 6.5 EPSS 1.05% Apr 19, 2018
CVE-2018-1272 HIGH

spring-framework: Multipart content pollution

CVSS 7.5 EPSS 3.06% Apr 6, 2018
CVE-2018-1271 MEDIUM

spring-framework: Directory traversal vulnerability with static resources on Windows filesystems

CVSS 5.9 EPSS 34.44% Apr 6, 2018
CVE-2018-1270 CRITICAL

spring-framework: Possible RCE via spring messaging

CVSS 9.8 EPSS 77.48% Apr 6, 2018
CVE-2017-12617 KEV HIGH

tomcat: Remote Code Execution bypass for CVE-2017-12615

CVSS 8.1 EPSS 99.97% Oct 3, 2017

Showing 1 to 20 CVEs · page 1