VulnScope — package-centric CVE lookup- MEDIUM6.5CVE-2019-5786⚠ KEVEPSS 89.9%chromium - security update
- HIGH8.8⚠ KEVEPSS 93.7%Command Injection in Kylin
- CRITICAL9.8⚠ KEVEPSS 94.5%Improper Privilege Management in Tomcat
- HIGH7.5⚠ KEVEPSS 94.3%Directory traversal attack in Spring Cloud Config
- MEDIUM6.9⚠ KEVEPSS 34.7%Potential XSS vulnerability in jQuery
- HIGH8.8⚠ KEVEPSS 94.4%Nexus Repository Manager 3 - Remote Code Execution
- HIGH7.5⚠ KEVEPSS 94.5%Improper Input Validation in Apache Solr
- CRITICAL9.9⚠ KEVEPSS 94.4%Remote Code Execution Vulnerability in NPM mongo-express
- HIGH7.2⚠ KEVEPSS 93.1%lucene-solr - security update
- HIGH8.1⚠ KEVEPSS 94.4%Apache Struts vulnerable to remote command execution (RCE) due to improper input validation
- CRITICAL10.0⚠ KEVEPSS 94.3%Apache Struts vulnerable to remote arbitrary command execution due to improper input validation
- CRITICAL9.8⚠ KEVEPSS 94.3%Spring Data Commons remote code injection vulnerability
- HIGH8.1⚠ KEVEPSS 94.2%When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server
- HIGH8.1⚠ KEVEPSS 94.3%REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering