Vulnerability Name CVE Severity
Envoy Proxy Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2020-12604) CVE-2020-12604
Envoy Proxy Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2021-32781) CVE-2021-32781
Envoy Proxy Incomplete Cleanup Vulnerability (CVE-2023-35945) CVE-2023-35945
Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2023-27491) CVE-2023-27491
Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2023-27493) CVE-2023-27493
Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2023-35944) CVE-2023-35944
Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2024-23326) CVE-2024-23326
Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32777) CVE-2021-32777
Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32779) CVE-2021-32779
Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-39206) CVE-2021-39206
Envoy Proxy Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-8660) CVE-2020-8660
Envoy Proxy Integer Overflow or Wraparound Vulnerability (CVE-2021-28682) CVE-2021-28682
Envoy Proxy Integer Underflow (Wrap or Wraparound) Vulnerability (CVE-2024-32975) CVE-2024-32975
Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-18836) CVE-2019-18836
Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2024-32976) CVE-2024-32976
Envoy Proxy Missing Authentication for Critical Function Vulnerability (CVE-2022-29226) CVE-2022-29226
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2019-18838) CVE-2019-18838
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-28683) CVE-2021-28683
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-43824) CVE-2021-43824
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2022-29224) CVE-2022-29224
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-23327) CVE-2024-23327
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-45809) CVE-2024-45809
Envoy Proxy Origin Validation Error Vulnerability (CVE-2020-15104) CVE-2020-15104
Envoy Proxy Other Vulnerability (CVE-2020-25017) CVE-2020-25017
Envoy Proxy Other Vulnerability (CVE-2024-34363) CVE-2024-34363
Envoy Proxy Out-of-bounds Write Vulnerability (CVE-2019-18801) CVE-2019-18801
Envoy Proxy Out-of-bounds Write Vulnerability (CVE-2024-34364) CVE-2024-34364
Envoy Proxy Reachable Assertion Vulnerability (CVE-2021-29258) CVE-2021-29258
Envoy Proxy Reachable Assertion Vulnerability (CVE-2022-29228) CVE-2022-29228
Envoy Proxy Uncontrolled Recursion Vulnerability (CVE-2022-23606) CVE-2022-23606
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2019-15226) CVE-2019-15226
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-8663) CVE-2020-8663
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12603) CVE-2020-12603
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12605) CVE-2020-12605
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2023-44487) CVE-2023-44487
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2024-23323) CVE-2024-23323
Envoy Proxy Use After Free Vulnerability (CVE-2021-43825) CVE-2021-43825
Envoy Proxy Use After Free Vulnerability (CVE-2021-43826) CVE-2021-43826
Envoy Proxy Use After Free Vulnerability (CVE-2022-29227) CVE-2022-29227
Envoy Proxy Use After Free Vulnerability (CVE-2023-35942) CVE-2023-35942
Envoy Proxy Use After Free Vulnerability (CVE-2023-35943) CVE-2023-35943
Envoy Proxy Use After Free Vulnerability (CVE-2024-23322) CVE-2024-23322
Envoy Proxy Use After Free Vulnerability (CVE-2024-32974) CVE-2024-32974
Envoy Proxy Use After Free Vulnerability (CVE-2024-34362) CVE-2024-34362
Envoy Proxy Use of Incorrectly-Resolved Name or Reference Vulnerability (CVE-2019-9901) CVE-2019-9901
Envoy Wrong DOWNSTREAM_REMOTE_ADDRESS logged Issue (CVE-2020-35470) CVE-2020-35470
Error messages
Error page path disclosure
Error page web server version disclosure
EspoCRM Cleartext Transmission of Sensitive Information Vulnerability (CVE-2022-38846) CVE-2022-38846
EspoCRM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-7985) CVE-2014-7985
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38844) CVE-2022-38844
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38845) CVE-2022-38845
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-7987) CVE-2014-7987
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17301) CVE-2018-17301
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17302) CVE-2018-17302
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-13643) CVE-2019-13643
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14329) CVE-2019-14329
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14330) CVE-2019-14330
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14331) CVE-2019-14331
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14349) CVE-2019-14349
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14350) CVE-2019-14350
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14546) CVE-2019-14546
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14547) CVE-2019-14547
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14548) CVE-2019-14548
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14549) CVE-2019-14549
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14550) CVE-2019-14550
EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3539) CVE-2021-3539
EspoCRM Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2019-14351) CVE-2019-14351
EspoCRM Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7986) CVE-2014-7986
EspoCRM Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-46736) CVE-2023-46736
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-38843) CVE-2022-38843
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5965) CVE-2023-5965
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5966) CVE-2023-5966
Express cookie-session weak secret key