Vulnerability Name CVE Severity
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-1410) CVE-2023-1410
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-22462) CVE-2023-22462
Grafana Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2024-9264) CVE-2024-9264
Grafana Improper Preservation of Permissions Vulnerability (CVE-2022-36062) CVE-2022-36062
Grafana Improper Synchronization Vulnerability (CVE-2023-2801) CVE-2023-2801
Grafana Improper Verification of Cryptographic Signature Vulnerability (CVE-2022-31123) CVE-2022-31123
Grafana Incorrect Authorization Vulnerability (CVE-2021-28146) CVE-2021-28146
Grafana Incorrect Authorization Vulnerability (CVE-2022-21713) CVE-2022-21713
Grafana Incorrect Authorization Vulnerability (CVE-2022-31107) CVE-2022-31107
Grafana Incorrect Authorization Vulnerability (CVE-2023-6152) CVE-2023-6152
Grafana Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-27962) CVE-2021-27962
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635) CVE-2019-15635
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2022-31130) CVE-2022-31130
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2019-15043) CVE-2019-15043
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2022-28660) CVE-2022-28660
Grafana Missing Authorization Vulnerability (CVE-2023-2183) CVE-2023-2183
Grafana Other Vulnerability (CVE-2021-28147) CVE-2021-28147
Grafana Plugin Dir Traversal (CVE-2021-43798) CVE-2021-43798
Grafana Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-13379) CVE-2020-13379
Grafana Signature Verification Vulnerability (CVE-2020-27846) CVE-2020-27846
Grafana Snapshot Authentication Bypass (CVE-2021-39226) CVE-2021-39226
Grafana URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29170) CVE-2022-29170
Grails database console
Grandnode Path Traversal (CVE-2019-12276) CVE-2019-12276
GraphiQL Explorer/Playground Enabled
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
GraphQL Field Suggestions Enabled
GraphQL Introspection Query Enabled
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
GraphQL Unauthenticated Mutation Detected
GraphQL Unhandled Error Leakage
Grav CMS Unauthenticated RCE (CVE-2021-21425) CVE-2021-21425
GSAP CVE-2020-28478 Vulnerability (CVE-2020-28478) CVE-2020-28478
Gunicorn Improper Neutralization of CRLF Sequences ('CRLF Injection') Vulnerability (CVE-2018-1000164) CVE-2018-1000164
H2 console publicly accessible
Hadoop cluster web interface
Hadoop YARN ResourceManager publicly accessible
Handlebars CVE-2021-23369 Vulnerability (CVE-2021-23369) CVE-2021-23369
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920) CVE-2019-20920
Handlebars Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-8861) CVE-2015-8861
Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2019-19919) CVE-2019-19919
Handlebars Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20922) CVE-2019-20922
Handlebars Other Vulnerability (CVE-2021-23383) CVE-2021-23383
Harbor Unauthorized Access Vulnerability CVE-2022-46463
Hashicorp Consul API is accessible without authentication
Hasura GraphQL API without authentication
Hesk Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3743) CVE-2011-3743
Hesk Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-5287) CVE-2011-5287
Hesk Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13897) CVE-2020-13897
Hiawatha Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-8358) CVE-2019-8358
Hibernate Query Language (HQL) Injection
Highcharts JS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-29489) CVE-2021-29489
Highcharts JS Incorrect Regular Expression Vulnerability (CVE-2018-20801) CVE-2018-20801
HipChat for JIRA plugin - Velocity template injection CVE-2015-5603
Horde/IMP Plesk webmail exploit
Horde Imp Unauthenticated Remote Command Execution CVE-2018-19518
Horde remote code execution CVE-2014-1691
Horizontal Broken Function Level Authorization (BFLA)
Horizontal IDOR/BOLA (Broken Object Level Authorization)
Host header attack
Hostile subdomain takeover
HSQLDB CVE-2022-41853 Vulnerability (CVE-2022-41853) CVE-2022-41853
HTML Attribute Injection
HTML Form found in redirect page
HTML form susceptible to spam
HTML Injection
HTTP.sys remote code execution vulnerability CVE-2015-1635
HTTP/2 pseudo-header server side request forgery
HTTP Header Injection
HTTP header reflected in cached response
Httpoxy vulnerability