vulnti.work

Vulnerability list

Filter public vulnerability entries by severity / channel / vendor / time.

Clear
Apache Tomcat Path Equivalence Vulnerability
High KEV

CVE-2025-24813 · 2026-09-02 · pending_review

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.

PHP-CGI OS Command Injection Vulnerability
High KEV

CVE-2024-4577 · 2026-09-02 · pending_review

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

Apache OFBiz Forced Browsing Vulnerability
High KEV

CVE-2024-45195 · 2026-09-02 · pending_review

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

Apache HTTP Server Improper Escaping of Output Vulnerability
High KEV

CVE-2024-38475 · 2026-09-02 · pending_review

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/…

Oracle WebLogic Server Unspecified Vulnerability
High KEV

CVE-2024-21182 · 2026-09-02 · pending_review

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resul…

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
High KEV

CVE-2023-46604 · 2026-09-02 · pending_review

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire pro…

Apache RocketMQ Command Execution Vulnerability
High KEV

CVE-2023-33246 · 2026-09-02 · pending_review

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configurat…

Microsoft SharePoint Server Privilege Escalation Vulnerability
High KEV

CVE-2023-29357 · 2026-09-02 · pending_review

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This atta…

Oracle WebLogic Server Unspecified Vulnerability
High KEV

CVE-2023-21839 · 2026-09-02 · pending_review

Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.

Apache Spark Command Injection Vulnerability
High KEV

CVE-2022-33891 · 2026-09-03 · pending_review

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

Grafana Path Traversal Vulnerability
High KEV

CVE-2021-43798 · 2026-09-02 · pending_review

Grafana contains a path traversal vulnerability that could allow access to local files.

Grafana Authentication Bypass Vulnerability
High KEV

CVE-2021-39226 · 2026-09-03 · pending_review

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

Oracle WebLogic Server Unspecified Vulnerability
High KEV

CVE-2020-2883 · 2026-09-02 · pending_review

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.

Apache Flink Improper Access Control Vulnerability
High KEV

CVE-2020-17519 · 2026-09-02 · pending_review

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

Oracle WebLogic Server Unspecified Vulnerability
High KEV

CVE-2020-14883 · 2026-09-04 · pending_review

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

Apache Airflow Command Injection
High KEV

CVE-2020-11978 · 2026-09-04 · pending_review

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

WordPress Snap Creek Duplicator Plugin File Download Vulnerability
High KEV

CVE-2020-11738 · 2026-09-04 · pending_review

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard.…

Apache HTTP Server Privilege Escalation Vulnerability
High KEV

CVE-2019-0211 · 2026-09-04 · pending_review

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileg…

Oracle WebLogic Server Unspecified Vulnerability
High KEV

CVE-2018-2628 · 2026-09-03 · pending_review

Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.

Laravel Deserialization of Untrusted Data Vulnerability
High KEV

CVE-2018-15133 · 2026-09-02 · pending_review

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption ke…

Next page →