CVE-2025-59287: Microsoft Windows Server Update Service (WSUS) Remote Code Execution [9.3 / Critical]
CVE-2025-56132: LiquidFiles User Enumeration [5.5 / Medium]
CVE-2025-55748: XWiki Platform Path Traversal [8.7 / High]
CVE-2025-32970: XWiki WYSIWYG API Open Redirect [6.1 / Medium]
CVE-2025-24813: Apache Tomcat Path Equivalence Remote Code Execution [9.3 / Critical]
CVE-2025-4388: Liferay Portal Reflected XSS [6.9 / Medium]
CVE-2025-1661: WordPress Plugin "HUSKY / Products Filter Professional for WooCommerce" (woocommerce-products-filter) Local File Inclusion [9.2 / Critical]
CVE-2024-55218: IceWarp Server 10.2.1 Reflected XSS [6.3 / Medium]
CVE-2024-54767: AVM FRITZ!Box 7530 AX Unauthorized Access And Configuration Exposure [8.7 / High]
CVE-2024-50498: WordPress Plugin "WP Query Console" (wp-query-console) Remote Code Execution [9.3 / Critical]
CVE-2024-45440: Drupal 11.x Core Full Path Disclosure [5.3 / Medium]
CVE-2024-38524: Geoserver Information Disclosure [6.9 / Medium]
CVE-2024-38472: Apache HTTP Server Windows UNC Server-Side Request Forgery [7.7 / High]
CVE-2024-31851: CData Sync And Other CData Products Path Traversal [8.8 / High]
CVE-2024-31621: Flowise 1.6.5 Authentication Bypass [8.7 / High]
CVE-2024-29198: GeoServer "Demo Request Endpoint" Server Side Request Forgery [8.7 / High]
CVE-2024-27956: WordPress Plugin "WP Automatic" ("wp-automatic") SQL Injection Allowing Admin Account Creation [6.9 / Medium]
CVE-2024-27198: JetBrains TeamCity Authentication Bypass [9.3 / Critical]
CVE-2024-23055: Plone Host Header Injection [6.3 / Medium]
CVE-2024-10914: D-Link NAS DNS-320/DNS-320LW/DNS-325/DNS-340L Command Injection Via "Name" Parameter [9.2 / Critical]
CVE-2024-8752: WebIQ 2.15.9 Runtime on Windows Directory Traversal [8.7 / High]
CVE-2024-6235: Citrix NetScaler Console Sensitive Information Disclosure And Authentication Bypass [8.7 / High]
CVE-2023-50968: Apache OFBiz Server-Side Request Forgery [8.8 / High]
CVE-2023-49785: ChatGPT-Next-Web (NextChat) SSRF And Reflected XSS [7.8 / High]
CVE-2023-39026: FileMage Gateway Directory Traversal [8.7 / High]
CVE-2023-29300: Adobe ColdFusion Pre-Authentication Remote Code Execution Via Deserialization [9.3 / Critical]
CVE-2023-28432: MinIO Cluster Deployment Information Disclosure [8.7 / High]
CVE-2023-6063: WordPress Plugin "WP Fastest Cache" (wp-fastest-cache) Unauthenticated SQL Injection [9.2 / Critical]
CVE-2023-2227: Modoboa < 2.1.0 Authentication And Authorization Bypass [9.3 / Critical]
CVE-2023-1496: Imgproxy "SVG" Sanitization Bypass XSS [6.3 / Medium]
CVE-2022-44877: CentOS Web Panel (CWP) OS Command Injection Leading To Remote Code Execution [9.3 / Critical]
CVE-2022-30777: Parallels H-Sphere 3.6.1713 Reflected XSS [6.3 / Medium]
CVE-2022-28987: Zoho ManageEngine ADSelfService User Enumeration [6.9 / Medium]
CVE-2022-28005: 3CX Phone System Management Console Local File Inclusion [8.6 / High]
CVE-2022-27926: "Synacor Zimbra Collaboration Suite (ZCS)" XSS [6.3 / Medium]
CVE-2022-25568: MotionEye Configuration File Information Disclosure [8.7 / High]
CVE-2022-24816: OSGeo GeoServer "JAI-EXT" "JT-JIFFLE" Code Injection [9.3 / Critical]
CVE-2022-22972: VMware Workspace ONE Access/Identity Manager/vRealize Automation Authentication Bypass [9.3 / Critical]
CVE-2022-21587: Oracle E-Business Suite Remote Code Execution [9.3 / Critical]
CVE-2022-3123: Reflected XSS in Dokuwiki [7.8 / High]
CVE-2022-2552: WordPress "Duplicator / Backups & Migration Plugin / Cloud Backups, Scheduled Backups, & More" (duplicator) Unauthenticated Public Backup Metadata Endpoints Information Disclosure [6.9 / Medium]
CVE-2022-1442: WordPress Plugin "MetForm / Contact Form, Survey, Quiz, & Custom Form Builder for Elementor" (metform) < 2.1.4 Unauthenticated API Keys and Secrets Disclosure [8.7 / High]
CVE-2022-0288: WordPress Plugin "Ad Inserter / Ad Manager & AdSense Ads" (ad-inserter) < 2.7.10 Reflected XSS [6.3 / Medium]
CVE-2021-46417: Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 Local File Inclusion [8.7 / High]
CVE-2021-44529: Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Remote Code Execution [9.3 / Critical]
CVE-2021-44228: Apache Log4j2 Remote Code Execution [10.0 / Critical]
CVE-2021-40150: Reolink E1 Zoom Camera <=3.0.0.716 "Nginx Configuration" Information Disclosure [6.9 / Medium]
CVE-2021-36580: IceWarp Mail Server Open Redirect [6.1 / Medium]
CVE-2021-34429: Eclipse Jetty Path Traversal Information Disclosure [6.9 / Medium]
CVE-2021-24522: WordPress "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content / ProfilePress" (wp-user-avatar) Avatar Handling Stored XSS [6.3 / Medium]
CVE-2021-22122: FortiWeb Reflected XSS [6.3 / Medium]
CVE-2021-21800: Advantech R-SeeNet 2.4.12 XSS [6.3 / Medium]
CVE-2021-3223: Node-RED Dashboard (<2.26.2) Path Traversal Leading To Local File Inclusion [8.7 / High]
CVE-2020-17496: vBulletin PHP Module Remote Code Execution [9.4 / Critical]
CVE-2020-15500: TileServer GL <=3.0.0 XSS [5.1 / Medium]
CVE-2020-15081: PrestaShop Information Exposure [6.9 / Medium]
CVE-2020-12116: Zoho ManageEngine OpManager Unauthenticated Arbitrary File Read [7.5 / High]
CVE-2020-11710: Kong <=2.03 "Admin REST API" Exposure [9.3 / Critical]
CVE-2020-11547: PRTG Network Monitor Information Disclosure [6.9 / Medium]
CVE-2020-7741: hello.js XSS [9.3 / Critical]
CVE-2020-4782: IBM WebSphere Directory Traversal [7.1 / High]
CVE-2019-9053: CMS Made Simple < 2.2.10 SQL Injection [9.2 / Critical]
CVE-2019-8451: Atlassian Jira "<8.4.0" Server-Side Request Forgery [6.9 / Medium]
CVE-2019-8086: Adobe Experience Manager XML External Entity (XXE) Injection [8.7 / High]
CVE-2019-7655: Wowza Streaming Engine Manager XSS [6.2 / Medium]
CVE-2019-7238: Sonatype Nexus Repository Manager Incorrect Access Control And Remote Code Execution [9.3 / Critical]
CVE-2019-1653: Cisco RV320/RV325 Routers Configuration Export Information Disclosure [8.7 / High]
CVE-2018-17246: Kibana File Inclusion [8.1 / High]
CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal [8.7 / High]
CVE-2018-12923: BWS Systems HA-Bridge Information Disclosure [6.9 / Medium]
CVE-2018-11759: JK Status Manager Bypass [10.0 / Critical]
CVE-2018-8711: WordPress Plugin "HUSKY / Products Filter Professional for WooCommerce" (woocommerce-products-filter) Local File Inclusion [9.2 / Critical]
CVE-2018-5712: PHP Phar XSS [6.3 / Medium]
CVE-2017-10974: Yaws 1.91 Path Traversal And Local File Inclusion [6.9 / Medium]
CVE-2017-9841: PHPUnit Remote Code Execution [9.3 / Critical]
CVE-2017-9140: Telerik Reporting ReportViewer Reflected XSS [6.3 / Medium]
CVE-2017-5616: cPanel Reflected XSS [7.8 / High]
CVE-2017-5615: cPanel CRLF Injection [7.8 / High]
CVE-2012-4000: FCKEditor "spellchecker.php" XSS [7.8 / High]
CVE-2011-4367: Apache MyFaces "ln" Directory Traversal And Information Disclosure [5.1 / Medium]
CVE-2010-1870: Apache Struts2 Remote Command Execution [9.3 / Critical]
CVE-2008-6551: e-Vision CMS 2.0.2 Path Traversal And Local File Inclusion [2.1 / Low]
CVE-2008-0252: CherryPy Path Traversal [8.7 / High]
CVE-2007-6368: EZContents 1.4.5 "index.php?link" Path Traversal Remote File Disclosure [6.9 / Medium]
Ribbon SBC Installer Exposure [7.8 / High]