Products › Server applications and development
Server applications and development
Frameworks and libraries
Software components embedded in other applications: Java, .NET, Log4j, Spring, PHP…
For example: Java, Log4j, Apache Struts, Spring.
-
5 vulnerabilities added in the last 12 months
-
76 exploited vulnerabilities in the catalog, in total
-
1 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Adobe 1 vulnerability
- Ajax.NET Professional 1 vulnerability · 1 in the last 12 months
- Apache 11 vulnerabilities
- Artifex 1 vulnerability
- Erlang 1 vulnerability
- ExifTool 1 vulnerability
- FreeType 1 vulnerability
- ImageMagick 3 vulnerabilities
- jQuery 1 vulnerability
- Laravel 3 vulnerabilities · 1 in the last 12 months
- Microsoft 4 vulnerabilities
- OpenSSL 1 vulnerability
- Oracle 14 vulnerabilities
- PEAR 2 vulnerabilities
- PHP 3 vulnerabilities
- PHPMailer 1 vulnerability
- PrimeTek 1 vulnerability
- Progress 4 vulnerabilities
- Protocoles (IETF) 1 vulnerability
- React (Meta) 1 vulnerability · 1 in the last 12 months
- Red Hat 2 vulnerabilities
- Ruby on Rails 3 vulnerabilities
- Spreadsheet::ParseExcel 1 vulnerability
- Spring 5 vulnerabilities
- Starlette 1 vulnerability · 1 in the last 12 months
- systeminformation (npm) 1 vulnerability
- TanStack 1 vulnerability · 1 in the last 12 months
- ThinkPHP 2 vulnerabilities
- Treck 1 vulnerability
- XStream 1 vulnerability
- Yii Framework 1 vulnerability
- ZK Framework 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Web and application servers 67 vulnerabilities
- Development and CI/CD 34 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Starlette
CVE-2026-48710Recently added
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 2, 2026
- CISA deadline
- 14 days
- CVSS severity
- 6.5 (medium)
Rank 2React (Meta) React Server Components
CVE-2025-55182Ransomware
Meta React Server Components Remote Code Execution Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 5, 2025
- CISA deadline
- 7 days
- CVSS severity
- 10.0 (critical)
Rank 3Ajax.NET Professional
CVE-2021-23758CVE from 2021, added in 2026
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 26, 2026
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 4Laravel Livewire
CVE-2025-54068Laravel Livewire Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 5TanStack
CVE-2026-45321Ransomware
TanStack Unspecified Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 27, 2026
- CISA deadline
- 14 days
- CVSS severity
- 9.6 (critical)
Rank 6Erlang/OTP
CVE-2025-32433Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 9, 2025
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 7Spring Cloud Gateway
CVE-2022-22947VMware Spring Cloud Gateway Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 16, 2022
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 8Apache Log4j
CVE-2021-44228Ransomware
Apache Log4j2 Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 14 days
- CVSS severity
- 10.0 (critical)
Rank 9PHPMailer
CVE-2016-10033CVE from 2016, added in 2025
PHPMailer Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10Yii Framework Yii
CVE-2024-58136Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 2, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 66 more vulnerabilities
Rank 11Oracle ADF Faces
CVE-2022-21445CVE from 2022, added in 2024
Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12PHP
CVE-2024-4577Ransomware
PHP-CGI OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 12, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Red Hat JBoss RichFaces
CVE-2018-14667CVE from 2018, added in 2023
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 28, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14Laravel Ignition
CVE-2021-3129RansomwareCVE from 2021, added in 2023
Laravel Ignition File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Oracle Java SE (JRE / JDK)
CVE-2016-3427CVE from 2016, added in 2023
Oracle Java SE and JRockit Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 12, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 16Progress Telerik UI for ASP.NET AJAX
CVE-2017-11357RansomwareCVE from 2017, added in 2023
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 26, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 17Spring Cloud Function
CVE-2022-22963VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 18Oracle Java SE (JRE / JDK)
CVE-2010-0840CVE from 2010, added in 2022
Oracle JRE Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19Oracle Java SE (JRE / JDK)
CVE-2013-0422RansomwareCVE from 2013, added in 2022
Oracle JRE Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 20Progress Telerik UI for ASP.NET AJAX
CVE-2017-11317CVE from 2017, added in 2022
Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 11, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21Spring Framework
CVE-2022-22965Spring Framework JDK 9+ Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 4, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Oracle Java SE (JRE / JDK)
CVE-2012-5076CVE from 2012, added in 2022
Oracle Java SE Sandbox Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 23Oracle Java SE (JRE / JDK)
CVE-2013-2465RansomwareCVE from 2013, added in 2022
Oracle Java SE Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24PHP
CVE-2012-1823CVE from 2012, added in 2022
PHP-CGI Query String Parameter Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 25Apache Struts
CVE-2013-2251CVE from 2013, added in 2022
Apache Struts Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26Spring Data
CVE-2018-1273RansomwareCVE from 2018, added in 2022
VMware Tanzu Spring Data Commons Property Binder Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27PHP
CVE-2019-11043RansomwareCVE from 2019, added in 2022
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 28Oracle Java SE (JRE / JDK)
CVE-2011-3544CVE from 2011, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 29Oracle Java SE (JRE / JDK)
CVE-2012-0507RansomwareCVE from 2012, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 30Oracle Java SE (JRE / JDK)
CVE-2012-1723RansomwareCVE from 2012, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 31Oracle Java SE (JRE / JDK)
CVE-2012-4681RansomwareCVE from 2012, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 32Oracle Java SE (JRE / JDK)
CVE-2015-2590CVE from 2015, added in 2022
Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 33Apache Struts 1
CVE-2017-9791CVE from 2017, added in 2022
Apache Struts 1 Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 34Apache Struts
CVE-2012-0391CVE from 2012, added in 2022
Apache Struts 2 Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 21, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 35PrimeTek PrimeFaces
CVE-2017-1000486CVE from 2017, added in 2022
Primetek Primefaces Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 36Apache Shiro
CVE-2016-4437CVE from 2016, added in 2021
Apache Shiro Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 37Apache Struts
CVE-2017-5638RansomwareCVE from 2017, added in 2021
Apache Struts Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 38Progress Telerik UI for ASP.NET AJAX
CVE-2017-9248CVE from 2017, added in 2021
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 39ThinkPHP
CVE-2018-20062CVE from 2018, added in 2021
ThinkPHP "noneCms" Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 40Progress Telerik UI for ASP.NET AJAX
CVE-2019-18935RansomwareCVE from 2019, added in 2021
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 41Microsoft .NET / Visual Studio
CVE-2020-0646Microsoft .NET Framework Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 42Apache Struts
CVE-2020-17530Apache Struts Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 43Apache Log4j
CVE-2021-45046RansomwareCVE from 2021, added in 2023
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 1, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.0 (critical)
Rank 44Red Hat JBoss Seam
CVE-2010-1871CVE from 2010, added in 2021
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 182 days
- CVSS severity
- 8.8 (high)
Rank 45ThinkPHP
CVE-2019-9082CVE from 2019, added in 2021
ThinkPHP Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 46XStream
CVE-2021-39144CVE from 2021, added in 2023
XStream Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.5 (high)
Rank 47ImageMagick
CVE-2016-3714CVE from 2016, added in 2024
ImageMagick Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.4 (high)
Rank 48FreeType
CVE-2025-27363FreeType Out-of-Bounds Write Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 6, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 49Laravel Framework
CVE-2018-15133CVE from 2018, added in 2024
Laravel Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 16, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 50Apache Struts
CVE-2017-9805CVE from 2017, added in 2021
Apache Struts Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.1 (high)
Rank 51Apache Struts
CVE-2018-11776CVE from 2018, added in 2021
Apache Struts Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.1 (high)
Rank 52Spreadsheet::ParseExcel
CVE-2023-7101Spreadsheet::ParseExcel Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 2, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 53PEAR Archive_Tar
CVE-2020-28949CVE from 2020, added in 2022
PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 54Artifex Ghostscript
CVE-2017-8291CVE from 2017, added in 2022
Artifex Ghostscript Type Confusion Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 55systeminformation (npm) systeminformation
CVE-2021-21315System Information Library for Node.JS Command Injection
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 56ExifTool
CVE-2021-22204ExifTool Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 17, 2021
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 57Microsoft .NET / Visual Studio
CVE-2017-8759CVE from 2017, added in 2021
Microsoft .NET Framework Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 58Ruby on Rails
CVE-2019-5418CVE from 2019, added in 2025
Rails Ruby on Rails Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 59Microsoft .NET / Visual Studio
CVE-2024-29059Microsoft .NET Framework Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 60Protocoles (IETF) Service Location Protocol (SLP)
CVE-2023-29552Service Location Protocol (SLP) Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 8, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 61Microsoft .NET / Visual Studio
CVE-2023-38180Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 9, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 62ZK Framework AuUploader
CVE-2022-36537Ransomware
ZK Framework AuUploader Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 27, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 63PEAR Archive_Tar
CVE-2020-36193CVE from 2020, added in 2022
PEAR Archive_Tar Improper Link Resolution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 64OpenSSL
CVE-2014-0160CVE from 2014, added in 2022
OpenSSL Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 4, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 65Ruby on Rails
CVE-2014-0130CVE from 2014, added in 2022
Ruby on Rails Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 66Ruby on Rails
CVE-2016-0752CVE from 2016, added in 2022
Ruby on Rails Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 67Spring Cloud Config
CVE-2020-5410CVE from 2020, added in 2022
VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 68Apache Struts 1
CVE-2006-1547CVE from 2006, added in 2022
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 21, 2022
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 69Adobe BlazeDS
CVE-2009-3960RansomwareCVE from 2009, added in 2022
Adobe BlazeDS Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 6.5 (medium)
Rank 70jQuery
CVE-2020-11023CVE from 2020, added in 2025
JQuery Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 23, 2025
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 71ImageMagick
CVE-2016-3715CVE from 2016, added in 2021
ImageMagick Arbitrary File Deletion Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 5.5 (medium)
Rank 72ImageMagick
CVE-2016-3718CVE from 2016, added in 2021
ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 5.5 (medium)
Rank 73Treck Pile TCP/IP
CVE-2020-11899CVE from 2020, added in 2022
Treck TCP/IP stack Out-of-Bounds Read Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 5.4 (medium)
Rank 74Oracle Java SE (JRE / JDK)
CVE-2013-0431RansomwareCVE from 2013, added in 2022
Oracle JRE Sandbox Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 75Oracle Java SE (JRE / JDK)
CVE-2015-4902CVE from 2015, added in 2022
Oracle Java SE Integrity Check Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 76Oracle Java SE (JRE / JDK)
CVE-2013-2423CVE from 2013, added in 2022
Oracle JRE Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 3.7 (low)
Filed under another category
This vulnerability also concerns this type of product, but is counted in its main category. My radar finds it when you follow this category.
Microsoft SharePoint Server
CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.