Products › Server applications and development
Server applications and development
Web and application servers
Web servers, application servers and hosting control panels.
For example: IIS, Apache Tomcat, Oracle WebLogic, ColdFusion.
-
10 vulnerabilities added in the last 12 months
-
67 exploited vulnerabilities in the catalog, in total
-
1 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 0 |
| Nov 3, 2025 to Dec 2, 2025 | 1 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 0 |
| Apr 2, 2026 to May 1, 2026 | 2 |
| May 2, 2026 to May 31, 2026 | 1 |
| Jun 1, 2026 to Jun 30, 2026 | 2 |
| Jul 1, 2026 to Jul 30, 2026 | 1 |
| Jul 31, 2026 to Aug 29, 2026 | 2 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 1 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Adobe 16 vulnerabilities · 1 in the last 12 months
- Apache 16 vulnerabilities · 2 in the last 12 months
- cPanel (WebPros) 1 vulnerability · 1 in the last 12 months
- CWP (Control Web Panel / CentOS Web Panel) 2 vulnerabilities · 1 in the last 12 months
- CyberPanel (CyberPersons) 2 vulnerabilities
- Embedthis 1 vulnerability
- IBM 1 vulnerability
- LiteSpeed 2 vulnerabilities · 2 in the last 12 months
- Microsoft 1 vulnerability
- Nostromo 1 vulnerability
- Oracle 17 vulnerabilities · 2 in the last 12 months
- Protocoles (IETF) 1 vulnerability
- Red Hat 3 vulnerabilities
- Webmin 1 vulnerability
- WSO2 2 vulnerabilities · 1 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Frameworks and libraries 76 vulnerabilities
- CMS, e-commerce and websites 46 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1WSO2 API Manager, Identity Server, Integrator
CVE-2026-5430Recently addedHunt for compromise (CISA)
WSO2 Multiple Products Path Traversal Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 24, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 2Oracle WebLogic Server
CVE-2026-21962Hunt for compromise (CISA)
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 24, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 3Adobe ColdFusion
CVE-2026-48282Hunt for compromise (CISA)
Adobe ColdFusion Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 4LiteSpeed cPanel Plugin
CVE-2026-48172LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 26, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 5cPanel (WebPros) cPanel & WHM (WP Squared)
CVE-2026-41940Ransomware
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 30, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 6CWP (Control Web Panel / CentOS Web Panel) Control Web Panel
CVE-2025-48703CWP Control Web Panel OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.0 (critical)
Rank 7Apache ActiveMQ
CVE-2026-34197Apache ActiveMQ Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 16, 2026
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 8LiteSpeed cPanel Plugin
CVE-2026-54420LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 15, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.5 (high)
Rank 9Apache Tomcat
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 4, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.5 (high)
Rank 10Oracle WebLogic Server
CVE-2024-21182CVE from 2024, added in 2026
Oracle WebLogic Server Unspecified Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 1, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.5 (high)
Show 57 more vulnerabilities
Rank 11Apache Tomcat
CVE-2025-24813Apache Tomcat Path Equivalence Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 1, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Adobe ColdFusion
CVE-2017-3066CVE from 2017, added in 2025
Adobe ColdFusion Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Oracle WebLogic Server
CVE-2020-2883CVE from 2020, added in 2025
Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14CyberPanel (CyberPersons) CyberPanel
CVE-2024-51378Ransomware
CyberPanel Incorrect Default Permissions Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 4, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Nostromo nhttpd
CVE-2019-16278CVE from 2019, added in 2024
Nostromo nhttpd Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 7, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 16CyberPanel (CyberPersons) CyberPanel
CVE-2024-51567Ransomware
CyberPanel Incorrect Default Permissions Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 7, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 17Oracle WebLogic Server
CVE-2020-14644CVE from 2020, added in 2024
Oracle WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 18Adobe ColdFusion
CVE-2023-29300Ransomware
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19Adobe ColdFusion
CVE-2023-38203Ransomware
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 20Oracle WebLogic Server
CVE-2020-2551CVE from 2020, added in 2023
Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 16, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21Apache ActiveMQ
CVE-2023-46604Ransomware
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 2, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Apache RocketMQ
CVE-2023-33246Apache RocketMQ Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 6, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 23Adobe ColdFusion
CVE-2023-26359Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 21, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24Apache Tomcat
CVE-2016-8735CVE from 2016, added in 2023
Apache Tomcat Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 12, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 25Adobe ColdFusion
CVE-2023-26360Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 15, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26CWP (Control Web Panel / CentOS Web Panel) Control Web Panel
CVE-2022-44877CWP Control Web Panel OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 17, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27Oracle WebLogic Server
CVE-2018-2628CVE from 2018, added in 2022
Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 28Apache APISIX
CVE-2022-24112Apache APISIX Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 29Oracle Fusion Middleware
CVE-2012-1710RansomwareCVE from 2012, added in 2022
Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 30WSO2 API Manager, Identity Server, Integrator
CVE-2022-29464Ransomware
WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 31Adobe ColdFusion
CVE-2010-2861RansomwareCVE from 2010, added in 2022
Adobe ColdFusion Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 32Webmin
CVE-2019-15107RansomwareCVE from 2019, added in 2022
Webmin Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 33Adobe ColdFusion
CVE-2013-0625CVE from 2013, added in 2022
Adobe ColdFusion Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 9.8 (critical)
Rank 34Adobe ColdFusion
CVE-2013-0632CVE from 2013, added in 2022
Adobe ColdFusion Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 35Apache Tomcat
CVE-2020-1938CVE from 2020, added in 2022
Apache Tomcat Improper Privilege Management Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 36Apache ActiveMQ
CVE-2016-3088CVE from 2016, added in 2022
Apache ActiveMQ Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 37IBM WebSphere Application Server
CVE-2015-7450CVE from 2015, added in 2022
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 38Oracle WebLogic Server
CVE-2019-2725RansomwareCVE from 2019, added in 2022
Oracle WebLogic Server, Injection
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 39Red Hat JBoss Application Server / EAP
CVE-2017-12149RansomwareCVE from 2017, added in 2021
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 182 days
- CVSS severity
- 9.8 (critical)
Rank 40Oracle WebLogic Server
CVE-2015-4852CVE from 2015, added in 2021
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 41Microsoft IIS
CVE-2017-7269CVE from 2017, added in 2021
Microsoft Windows Server Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 42Adobe ColdFusion
CVE-2018-15961CVE from 2018, added in 2021
Adobe ColdFusion Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 43Adobe ColdFusion
CVE-2018-4939CVE from 2018, added in 2021
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 44Oracle WebLogic Server
CVE-2020-14750Oracle WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 45Oracle WebLogic Server
CVE-2020-14882Oracle WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 46Oracle Coherence
CVE-2020-2555Oracle Multiple Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 47Apache HTTP Server
CVE-2021-41773Ransomware
Apache HTTP Server Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 48Apache HTTP Server
CVE-2021-42013Ransomware
Apache HTTP Server Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 49Apache HTTP Server
CVE-2024-38475Apache HTTP Server Improper Escaping of Output Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 1, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 50Oracle Fusion Middleware
CVE-2012-3152CVE from 2012, added in 2021
Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.1 (critical)
Rank 51Apache HTTP Server
CVE-2021-40438Ransomware
Apache HTTP Server-Side Request Forgery (SSRF)
Added more than a year ago: ranked by severity.
- Added
- Dec 1, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.0 (critical)
Rank 52Apache Tomcat
CVE-2017-12615RansomwareCVE from 2017, added in 2022
Apache Tomcat on Windows Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 53Apache Tomcat
CVE-2017-12617CVE from 2017, added in 2022
Apache Tomcat Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 54Embedthis GoAhead
CVE-2017-17562CVE from 2017, added in 2021
Embedthis GoAhead Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 182 days
- CVSS severity
- 8.1 (high)
Rank 55Apache HTTP Server
CVE-2019-0211CVE from 2019, added in 2021
Apache HTTP Server Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 56Protocoles (IETF) HTTP/2
CVE-2023-44487HTTP/2 Rapid Reset Attack Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 57Adobe ColdFusion
CVE-2023-29298Adobe ColdFusion Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 20, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 58Adobe ColdFusion
CVE-2023-38205Adobe ColdFusion Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 20, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 59Oracle WebLogic Server
CVE-2023-21839Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 1, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 60Red Hat JBoss Application Server / EAP
CVE-2010-1428RansomwareCVE from 2010, added in 2022
Red Hat JBoss Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 61Adobe ColdFusion
CVE-2013-0629CVE from 2013, added in 2022
Adobe ColdFusion Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 7.5 (high)
Rank 62Adobe ColdFusion
CVE-2013-0631CVE from 2013, added in 2022
Adobe ColdFusion Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 7.5 (high)
Rank 63Oracle WebLogic Server
CVE-2017-10271RansomwareCVE from 2017, added in 2022
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 64Adobe ColdFusion
CVE-2024-20767Adobe ColdFusion Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 16, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.4 (high)
Rank 65Oracle WebLogic Server
CVE-2017-3506CVE from 2017, added in 2024
Oracle WebLogic Server OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 3, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.4 (high)
Rank 66Oracle WebLogic Server
CVE-2020-14883Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.2 (high)
Rank 67Red Hat JBoss Application Server / EAP
CVE-2010-0738RansomwareCVE from 2010, added in 2022
Red Hat JBoss Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Filed under another category
These 2 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.
Oracle ADF Faces
CVE-2022-21445CVE from 2022, added in 2024
Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe BlazeDS
CVE-2009-3960RansomwareCVE from 2009, added in 2022
Adobe BlazeDS Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 6.5 (medium)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.