Skip to content
Noroxi

CWE-917 · 179 records

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

CVEs in this class

179 records

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerJun 3, 2022

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerAug 30, 2021

  • Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 96%

    apache · strutsDec 10, 2020

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    apache · log4jDec 14, 2021

  • Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    sonatype · nexusApr 1, 2020

  • JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for

    HighCVSS 8.8KEVWeaponizedEPSS 83%

    redhat · jboss enterprise application platformAug 5, 2010

  • CVE-2021-31805
    65This week

    Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

    CriticalCVSS 9.8Proof of conceptEPSS 85%

    apache · strutsApr 12, 2022

  • A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    HighCVSS 7.5No exploitEPSS 54%

    hp · intelligent management centerJun 5, 2019

  • JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbit

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    redhat · richfacesJun 18, 2018

  • A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expres

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    vmware · spring data mongodbJun 23, 2022

  • VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly han

    HighCVSS 8.8Proof of conceptEPSS 21%

    vmware · vcloud directorMay 20, 2020

  • A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    CriticalCVSS 9.8No exploitEPSS 8%

    hp · intelligent management centerJun 5, 2019

  • A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    CriticalCVSS 9.8No exploitEPSS 8%

    hp · intelligent management centerJun 5, 2019

  • A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    CriticalCVSS 9.8No exploitEPSS 8%

    hp · intelligent management centerJun 5, 2019

  • A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    CriticalCVSS 9.8No exploitEPSS 8%

    hp · intelligent management centerJun 5, 2019

  • JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper

    CriticalCVSS 9.8No exploitEPSS 7%

    redhat · richfacesJun 18, 2018

  • A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

  • A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · intelligent management centerOct 19, 2020

All vulnerability classes