CWE-917 · 179 records
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVEs in this class
179 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2022-26134Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Jun 3, 2022 |
99Now | CVE-2021-26084Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Aug 30, 2021 |
98Now | CVE-2020-17530Weaponized | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.apache · struts · CWE-917 | Critical9.8 | KEV | 95.9% | Dec 10, 2020 |
96Now | CVE-2021-45046Weaponized | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Critical9.0 | KEV | 100.0% | Dec 14, 2021 |
95Now | CVE-2020-10199Weaponized | Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).sonatype · nexus · CWE-917 | High8.8 | KEV | 99.1% | Apr 1, 2020 |
90Now | CVE-2010-1871Weaponized | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for redhat · jboss enterprise application platform · CWE-917 | High8.8 | KEV | 83.4% | Aug 5, 2010 |
65This week | CVE-2021-31805Proof of concept | Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.apache · struts · CWE-917 | Critical9.8 | — | 85.4% | Apr 12, 2022 |
46Plan | CVE-2019-5355No exploit | A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | High7.5 | — | 54.0% | Jun 5, 2019 |
45Plan | CVE-2018-12533Proof of concept | JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitredhat · richfaces · CWE-917 | Critical9.8 | — | 19.0% | Jun 18, 2018 |
44Plan | CVE-2022-22980Proof of concept | A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expresvmware · spring data mongodb · CWE-917 | Critical9.8 | — | 17.8% | Jun 23, 2022 |
41Plan | CVE-2020-3956Proof of concept | VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly hanvmware · vcloud director · CWE-917 | High8.8 | — | 21.1% | May 20, 2020 |
41Plan | CVE-2019-5352No exploit | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Critical9.8 | — | 8.1% | Jun 5, 2019 |
41Plan | CVE-2019-11949No exploit | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Critical9.8 | — | 8.1% | Jun 5, 2019 |
41Plan | CVE-2019-5358No exploit | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Critical9.8 | — | 8.1% | Jun 5, 2019 |
41Plan | CVE-2019-5387No exploit | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Critical9.8 | — | 8.1% | Jun 5, 2019 |
41Plan | CVE-2018-12532No exploit | JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapperredhat · richfaces · CWE-917 | Critical9.8 | — | 7.0% | Jun 18, 2018 |
41Plan | CVE-2020-7169No exploit | A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Centerhp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-7161No exploit | A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMhp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-7153No exploit | A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMhp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-7151No exploit | A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Centerhp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-24652No exploit | A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center hp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-7168No exploit | A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMChp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-7141No exploit | A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMChp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-7145No exploit | A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)hp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
41Plan | CVE-2020-7147No exploit | A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center hp · intelligent management center · CWE-917 | Critical9.8 | — | 7.0% | Oct 19, 2020 |
- CVE-2022-2613499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerJun 3, 2022
- CVE-2021-2608499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerAug 30, 2021
- CVE-2020-1753098Now
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 96%apache · strutsDec 10, 2020
- CVE-2021-4504696Now
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
CriticalCVSS 9.0KEVWeaponizedEPSS 100%apache · log4jDec 14, 2021
- CVE-2020-1019995Now
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
HighCVSS 8.8KEVWeaponizedEPSS 99%sonatype · nexusApr 1, 2020
- CVE-2010-187190Now
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for
HighCVSS 8.8KEVWeaponizedEPSS 83%redhat · jboss enterprise application platformAug 5, 2010
- CVE-2021-3180565This week
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
CriticalCVSS 9.8Proof of conceptEPSS 85%apache · strutsApr 12, 2022
- CVE-2019-535546Plan
A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
HighCVSS 7.5No exploitEPSS 54%hp · intelligent management centerJun 5, 2019
- CVE-2018-1253345Plan
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbit
CriticalCVSS 9.8Proof of conceptEPSS 19%redhat · richfacesJun 18, 2018
- CVE-2022-2298044Plan
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expres
CriticalCVSS 9.8Proof of conceptEPSS 18%vmware · spring data mongodbJun 23, 2022
- CVE-2020-395641Plan
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly han
HighCVSS 8.8Proof of conceptEPSS 21%vmware · vcloud directorMay 20, 2020
- CVE-2019-535241Plan
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CriticalCVSS 9.8No exploitEPSS 8%hp · intelligent management centerJun 5, 2019
- CVE-2019-1194941Plan
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CriticalCVSS 9.8No exploitEPSS 8%hp · intelligent management centerJun 5, 2019
- CVE-2019-535841Plan
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CriticalCVSS 9.8No exploitEPSS 8%hp · intelligent management centerJun 5, 2019
- CVE-2019-538741Plan
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CriticalCVSS 9.8No exploitEPSS 8%hp · intelligent management centerJun 5, 2019
- CVE-2018-1253241Plan
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper
CriticalCVSS 9.8No exploitEPSS 7%redhat · richfacesJun 18, 2018
- CVE-2020-716941Plan
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-716141Plan
A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-715341Plan
A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-715141Plan
A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-2465241Plan
A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-716841Plan
A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-714141Plan
A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-714541Plan
A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020
- CVE-2020-714741Plan
A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
CriticalCVSS 9.8No exploitEPSS 7%hp · intelligent management centerOct 19, 2020