Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities Ldap Injection Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Envoy Proxy Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2020-12604) CVE-2020-12604 CWE-119 CWE-119 High Envoy Proxy Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2021-32781) CVE-2021-32781 CWE-119 CWE-119 High Envoy Proxy Incomplete Cleanup Vulnerability (CVE-2023-35945) CVE-2023-35945 CWE-459 CWE-459 High Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2023-27491) CVE-2023-27491 Critical Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2023-27493) CVE-2023-27493 Critical Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2023-35944) CVE-2023-35944 Medium Envoy Proxy Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2024-23326) CVE-2024-23326 High Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32777) CVE-2021-32777 CWE-863 CWE-863 High Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32779) CVE-2021-32779 CWE-863 CWE-863 High Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-39206) CVE-2021-39206 CWE-863 CWE-863 High Envoy Proxy Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-8660) CVE-2020-8660 CWE-345 CWE-345 Medium Envoy Proxy Integer Overflow or Wraparound Vulnerability (CVE-2021-28682) CVE-2021-28682 CWE-190 CWE-190 High Envoy Proxy Integer Underflow (Wrap or Wraparound) Vulnerability (CVE-2024-32975) CVE-2024-32975 CWE-191 CWE-191 High Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-18836) CVE-2019-18836 CWE-835 CWE-835 High Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2024-32976) CVE-2024-32976 CWE-835 CWE-835 High Envoy Proxy Missing Authentication for Critical Function Vulnerability (CVE-2022-29226) CVE-2022-29226 CWE-306 CWE-306 Critical Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2019-18838) CVE-2019-18838 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-28683) CVE-2021-28683 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-43824) CVE-2021-43824 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2022-29224) CVE-2022-29224 CWE-476 CWE-476 Medium Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-23327) CVE-2024-23327 CWE-476 CWE-476 High Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-45809) CVE-2024-45809 CWE-476 CWE-476 High Envoy Proxy Origin Validation Error Vulnerability (CVE-2020-15104) CVE-2020-15104 CWE-346 CWE-346 Medium Envoy Proxy Other Vulnerability (CVE-2020-25017) CVE-2020-25017 High Envoy Proxy Other Vulnerability (CVE-2024-34363) CVE-2024-34363 High Envoy Proxy Out-of-bounds Write Vulnerability (CVE-2019-18801) CVE-2019-18801 CWE-787 CWE-787 Critical Envoy Proxy Out-of-bounds Write Vulnerability (CVE-2024-34364) CVE-2024-34364 CWE-787 CWE-787 Medium Envoy Proxy Reachable Assertion Vulnerability (CVE-2021-29258) CVE-2021-29258 CWE-617 CWE-617 High Envoy Proxy Reachable Assertion Vulnerability (CVE-2022-29228) CVE-2022-29228 CWE-617 CWE-617 High Envoy Proxy Uncontrolled Recursion Vulnerability (CVE-2022-23606) CVE-2022-23606 CWE-674 CWE-674 Medium Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2019-15226) CVE-2019-15226 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-8663) CVE-2020-8663 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12603) CVE-2020-12603 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12605) CVE-2020-12605 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2023-44487) CVE-2023-44487 CWE-400 CWE-400 High Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2024-23323) CVE-2024-23323 CWE-400 CWE-400 Medium Envoy Proxy Use After Free Vulnerability (CVE-2021-43825) CVE-2021-43825 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2021-43826) CVE-2021-43826 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2022-29227) CVE-2022-29227 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2023-35942) CVE-2023-35942 CWE-416 CWE-416 Medium Envoy Proxy Use After Free Vulnerability (CVE-2023-35943) CVE-2023-35943 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2024-23322) CVE-2024-23322 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2024-32974) CVE-2024-32974 CWE-416 CWE-416 High Envoy Proxy Use After Free Vulnerability (CVE-2024-34362) CVE-2024-34362 CWE-416 CWE-416 Medium Envoy Proxy Use of Incorrectly-Resolved Name or Reference Vulnerability (CVE-2019-9901) CVE-2019-9901 CWE-706 CWE-706 Critical Envoy Wrong DOWNSTREAM_REMOTE_ADDRESS logged Issue (CVE-2020-35470) CVE-2020-35470 High Error messages CWE-209 CWE-209 Low Error page path disclosure CWE-200 CWE-200 Low Error page web server version disclosure CWE-200 CWE-200 Informational EspoCRM Cleartext Transmission of Sensitive Information Vulnerability (CVE-2022-38846) CVE-2022-38846 CWE-319 CWE-319 Medium EspoCRM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-7985) CVE-2014-7985 CWE-22 CWE-22 Critical EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38844) CVE-2022-38844 CWE-1236 CWE-1236 High EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38845) CVE-2022-38845 CWE-1236 CWE-1236 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-7987) CVE-2014-7987 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17301) CVE-2018-17301 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17302) CVE-2018-17302 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-13643) CVE-2019-13643 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14329) CVE-2019-14329 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14330) CVE-2019-14330 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14331) CVE-2019-14331 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14349) CVE-2019-14349 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14350) CVE-2019-14350 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14546) CVE-2019-14546 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14547) CVE-2019-14547 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14548) CVE-2019-14548 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14549) CVE-2019-14549 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14550) CVE-2019-14550 CWE-707 CWE-707 Medium EspoCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3539) CVE-2021-3539 CWE-707 CWE-707 Medium EspoCRM Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2019-14351) CVE-2019-14351 CWE-307 CWE-307 High EspoCRM Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7986) CVE-2014-7986 CWE-264 CWE-264 Medium EspoCRM Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-46736) CVE-2023-46736 CWE-918 CWE-918 Medium EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-38843) CVE-2022-38843 CWE-434 CWE-434 High EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5965) CVE-2023-5965 CWE-434 CWE-434 High EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5966) CVE-2023-5966 CWE-434 CWE-434 High Express cookie-session weak secret key CWE-693 CWE-693 Medium 1...35363738...303 36 / 303