Skip to main content

CWE archive

CWE-917 CVEs

Programmatic archive

205 CVEs tagged with CWE-91775 Critical, 116 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2020-7141

Published Oct 19, 2020

A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24652

Published Oct 19, 2020

A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24651

Published Oct 19, 2020

A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24650

Published Oct 19, 2020

A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15146

Published Aug 20, 2020

In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15143

Published Aug 20, 2020

In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven'…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9297

Published Jul 14, 2020

Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9296

Published Jun 16, 2020

Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-1959

Published May 4, 2020

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote C…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10199

Published Apr 1, 2020

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

CVSS 8.8 · High
Buzz score
29.9
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2020-7799

Published Jan 28, 2020

An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> T…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16469

Published Jan 15, 2020

Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-12822

Published Jun 14, 2019

In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 205 CVEsPage 6 of 9