Vulnerability Name CVE Severity
Grafana Snapshot Authentication Bypass (CVE-2021-39226) CVE-2021-39226
Grafana URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29170) CVE-2022-29170
Grails database console
Grandnode Path Traversal (CVE-2019-12276) CVE-2019-12276
GraphiQL Explorer/Playground Enabled
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
GraphQL Field Suggestions Enabled
GraphQL Introspection Query Enabled
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
GraphQL Unauthenticated Mutation Detected
GraphQL Unhandled Error Leakage
Grav CMS Unauthenticated RCE (CVE-2021-21425)
GSAP CVE-2020-28478 Vulnerability (CVE-2020-28478) CVE-2020-28478
Gunicorn Improper Neutralization of CRLF Sequences ('CRLF Injection') Vulnerability (CVE-2018-1000164) CVE-2018-1000164
H2 console publicly accessible
Hadoop cluster web interface
Hadoop YARN ResourceManager publicly accessible
Handlebars CVE-2021-23369 Vulnerability (CVE-2021-23369) CVE-2021-23369
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920) CVE-2019-20920
Handlebars Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-8861) CVE-2015-8861
Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2019-19919) CVE-2019-19919
Handlebars Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20922) CVE-2019-20922
Handlebars Other Vulnerability (CVE-2021-23383) CVE-2021-23383
Harbor Unauthorized Access Vulnerability CVE-2022-46463
Hashicorp Consul API is accessible without authentication
Hasura GraphQL API without authentication
Hesk Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3743) CVE-2011-3743
Hesk Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-5287) CVE-2011-5287
Hesk Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13897) CVE-2020-13897
Hiawatha Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-8358) CVE-2019-8358
Hibernate Query Language (HQL) Injection
Highcharts JS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-29489) CVE-2021-29489
Highcharts JS Incorrect Regular Expression Vulnerability (CVE-2018-20801) CVE-2018-20801
HipChat for JIRA plugin - Velocity template injection CVE-2015-5603
Horde/IMP Plesk webmail exploit
Horde Imp Unauthenticated Remote Command Execution CVE-2018-19518
Horde remote code execution CVE-2014-1691
Host header attack
Hostile subdomain takeover
HSQLDB CVE-2022-41853 Vulnerability (CVE-2022-41853) CVE-2022-41853
HTML Attribute Injection
HTML Form found in redirect page
HTML form susceptible to spam
HTML Injection
HTTP.sys remote code execution vulnerability CVE-2015-1635
HTTP/2 pseudo-header server side request forgery
HTTP Header Injection
HTTP header reflected in cached response
Httpoxy vulnerability
HTTP parameter pollution
Http redirect security bypass
HTTP response splitting with cloud storage
HTTPS connection uses outdated TLS version
HTTPS connection with weak key length
HTTP Strict Transport Security (HSTS) Errors and Warnings
HTTP Strict Transport Security (HSTS) Policy Not Enabled
HTTP verb tampering via POST
IBM Aspera Faspex RCE (CVE-2022-47986) CVE-2022-47986
IBMHttpServer CVE-2012-5955 Vulnerability (CVE-2012-5955) CVE-2012-5955
IBMHttpServer Improper Input Validation Vulnerability (CVE-2023-26281) CVE-2023-26281
IBMHttpServer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-1360) CVE-2011-1360
IBMHttpServer Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2015-4947) CVE-2015-4947
IBMHttpServer Observable Discrepancy Vulnerability (CVE-2023-32342) CVE-2023-32342
IBMHttpServer Other Vulnerability (CVE-2000-0505) CVE-2000-0505
IBMHttpServer Other Vulnerability (CVE-2000-1168) CVE-2000-1168
IBMHttpServer Other Vulnerability (CVE-2001-0122) CVE-2001-0122
IBMHttpServer Other Vulnerability (CVE-2002-1822) CVE-2002-1822
IBMHttpServer Other Vulnerability (CVE-2004-0263) CVE-2004-0263
IBMHttpServer Other Vulnerability (CVE-2004-0492) CVE-2004-0492
IBMHttpServer Other Vulnerability (CVE-2004-0493) CVE-2004-0493
IBMHttpServer Other Vulnerability (CVE-2004-1082) CVE-2004-1082