VulnScope — package-centric CVE lookup- HIGH8.8CVE-2022-33891⚠ KEVEPSS 93.5%Apache Spark UI can allow impersonation if ACLs enabled
- CRITICAL9.8⚠ KEVEPSS 94.4%Deserialization of Untrusted Data in Liferay Portal
- HIGH8.1⚠ KEVEPSS 85.3%Elasticsearch Improper Access Control vulnerability
- —⚠ KEVEPSS 92.3%Improper Access Control in Elasticsearch
- CRITICAL9.8⚠ KEVEPSS 94.3%Improper Access Control in Apache Shiro
- CRITICAL9.8⚠ KEVEPSS 94.3%Improper Input Validation in Apache ActiveMQ
- HIGH8.1⚠ KEVEPSS 94.4%tomcat7 - security update
- HIGH7.5⚠ KEVEPSS 39.7%Jenkins discloses project names via fingerprints
- CRITICAL9.8⚠ KEVEPSS 94.1%Code execution in Apache Struts 1 plugin
- CRITICAL9.8⚠ KEVEPSS 89.5%Richfaces vulnerable to arbitrary code execution
- CRITICAL9.8⚠ KEVEPSS 93.8%Apache Tomcat Improper Access Control vulnerability
- CRITICAL9.9⚠ KEVEPSS 91.8%Sandbox bypass in Jenkins Pipeline: Groovy Plugin
- CRITICAL9.8⚠ KEVEPSS 94.3%Code injection in Apache Struts
- CRITICAL9.8⚠ KEVEPSS 94.5%Deserialization of Untrusted Data in Jenkins
- CRITICAL9.8⚠ KEVEPSS 94.5%Deserialization of Untrusted Data in Jenkins
- CRITICAL9.9⚠ KEVEPSS 92.6%Sandbox bypass in Script Security Plugin
- CRITICAL9.8⚠ KEVEPSS 87.5%Apache Struts Remote Java Code Execution
- HIGH7.5⚠ KEVEPSS 15.7%Improper Input Validation in Apache Struts
- CRITICAL9.8⚠ KEVEPSS 94.5%Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
- CRITICAL9.8⚠ KEVEPSS 94.4%Remote Code Execution in Spring Framework
- CRITICAL10.0⚠ KEVEPSS 94.5%Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured
- CRITICAL9.8⚠ KEVEPSS 94.4%Remote code execution in Apache Struts
- CRITICAL9.0⚠ KEVEPSS 94.3%apache-log4j2 - security update
- CRITICAL10.0⚠ KEVEPSS 94.4%apache-log4j2 - security update
- CRITICAL9.8⚠ KEVEPSS 94.4%Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)