CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi…
AntiSamy: XSS via HTML attributes
Apache Ant ZIP, and ZIP based, archive denial of service vulerability
Apache Ant TAR archive denial of service vulnerability
batik: SSRF due to improper input validation by the NodePickerPanel
ant: insecure temporary file vulnerability
CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux
RFD Attack via "Content-Disposition" Header Sourced from Request Input by Spring MVC or Spring WebFlux Application
hibernate-validator: safeHTML validator allows XSS
apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default
libquartz: XXE attacks via job description
jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection
batik: information disclosure when deserializing
spring-security-core: Unauthorized Access with Spring Security Method Security
Vulnerability in the Oracle Retail Central Office component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13…
spring-framework: Multipart content pollution
spring-framework: Directory traversal vulnerability with static resources on Windows filesystems
spring-framework: Possible RCE via spring messaging
tomcat: Remote Code Execution bypass for CVE-2017-12615
Showing 1 to 20 CVEs · page 1