Vulnerability Name CVE Severity
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-42029) CVE-2022-42029
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4223) CVE-2023-4223
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4224) CVE-2023-4224
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4225) CVE-2023-4225
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4226) CVE-2023-4226
Chart.js Improper Input Validation Vulnerability (CVE-2020-7746) CVE-2020-7746
Check for apache versions up to 1.3.25, 2.0.38 CVE-2002-0392
Cherokee Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-20798) CVE-2019-20798
Cherokee Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2019-20799) CVE-2019-20799
Cherokee NULL Pointer Dereference Vulnerability (CVE-2020-12845) CVE-2020-12845
CherryPy Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-0252) CVE-2008-0252
Cisco Adaptive Security Appliance (ASA) Path Traversal (CVE-2018-0296) CVE-2018-0296
Cisco Adaptive Security Appliance (ASA) Path Traversal CVE-2020-3452 CVE-2020-3452
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability CVE-2018-15440
Citrix ADC/Gateway Unauthenticated Remote Code Execution CVE-2019-19781
Citrix Gateway Open Redirect and XSS CVE-2023-24488 CVE-2023-24487
Citrix XenMobile Server Path Traversal CVE-2020-8209
CKEditor 4.0.1 cross-site scripting vulnerability
CKEditor Other Vulnerability (CVE-2022-24729) CVE-2022-24729
Claroline Other Vulnerability (CVE-2005-1375) CVE-2005-1375
Claroline Other Vulnerability (CVE-2005-1376) CVE-2005-1376
Claroline Other Vulnerability (CVE-2005-1377) CVE-2005-1377
Claroline Other Vulnerability (CVE-2006-1594) CVE-2006-1594
Claroline Other Vulnerability (CVE-2006-1596) CVE-2006-1596
Claroline Other Vulnerability (CVE-2006-5256) CVE-2006-5256
Claroline Other Vulnerability (CVE-2006-7048) CVE-2006-7048
Client-Side Prototype Pollution
Client Side Template Injection
ClipBucket Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-5849) CVE-2012-5849
ClipBucket Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-6643) CVE-2012-6643
Cloud metadata publicly exposed
Cmd hijack vulnerability
Code Evaluation (Apache Struts) S2-046 CVE-2017-5638
CodeIgniter 2.1.3 xss_clean() filter bypass CVE-2013-4891
CodeIgniter session decoding vulnerability
CodeIgniter weak encryption key
ColdFusion 8 FCKEditor file upload vulnerability CVE-2009-2265
ColdFusion 9 solr service exposed CVE-2010-0185
ColdFusion Access Control bypass (CVE-2023-29298/CVE-2023-38205) CVE-2023-29298 CVE-2023-38205
ColdFusion AMF Deserialization RCE CVE-2017-3066
ColdFusion Arbitrary File Upload CVE-2018-15961
ColdFusion CFC Deserialization RCE (CVE-2023-26359/CVE-2023-26360) CVE-2023-26359 CVE-2023-26360
ColdFusion directory traversal CVE-2010-2861
ColdFusion FlashGateway Deserialization RCE CVE-2019-7091 CVE-2019-7091
ColdFusion JNDI injection RCE CVE-2018-15957
ColdFusion PMS Arbitrary File Read (CVE-2024-20767) CVE-2024-20767
ColdFusion User-Agent cross-site scripting CVE-2007-0817
Collabtive Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4269) CVE-2010-4269
Collabtive Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2015-0258) CVE-2015-0258
concrete5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-4724) CVE-2015-4724
concrete5 Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-13790) CVE-2018-13790
concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11476) CVE-2020-11476
concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-24986) CVE-2020-24986
Configuration file disclosure
Configuration file source code disclosure
Confluence Widget Connector SSTI CVE-2019-3396
Consul API publicly exposed
Contao Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10642) CVE-2019-10642
Contao Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-37626) CVE-2021-37626
Contao Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2017-10993) CVE-2017-10993
Contao Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-4383) CVE-2012-4383
Contao Improper Privilege Management Vulnerability (CVE-2021-37627) CVE-2021-37627
Contao Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-19745) CVE-2019-19745
Coppermine Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3481) CVE-2008-3481
Coppermine Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-3486) CVE-2008-3486
Core dump file
CouchDB REST API publicly accessible
Craft CMS CVE-2024-21622 Vulnerability (CVE-2024-21622) CVE-2024-21622
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30130) CVE-2023-30130
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30179) CVE-2023-30179
Craft CMS Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2021-41824) CVE-2021-41824
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-9757) CVE-2020-9757
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-32679) CVE-2023-32679
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-36260) CVE-2023-36260
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-40035) CVE-2023-40035