Перейти к содержимому
Noroxi

CWE-917 · 179 записей

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

CVE этого класса

179 записей

  • CVE-2022-26134
    99Срочно

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    atlassian · confluence data center3 июн. 2022 г.

  • CVE-2021-26084
    99Срочно

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    atlassian · confluence data center30 авг. 2021 г.

  • CVE-2020-17530
    98Срочно

    Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %

    apache · struts10 дек. 2020 г.

  • CVE-2021-45046
    96Срочно

    Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j14 дек. 2021 г.

  • CVE-2020-10199
    95Срочно

    Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %

    sonatype · nexus1 апр. 2020 г.

  • CVE-2010-1871
    90Срочно

    JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %

    redhat · jboss enterprise application platform5 авг. 2010 г.

  • CVE-2021-31805
    65На этой неделе

    Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

    КритическаяCVSS 9,8Proof of conceptEPSS 85 %

    apache · struts12 апр. 2022 г.

  • CVE-2019-5355
    46В плане

    A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 54 %

    hp · intelligent management center5 июн. 2019 г.

  • CVE-2018-12533
    45В плане

    JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbit

    КритическаяCVSS 9,8Proof of conceptEPSS 19 %

    redhat · richfaces18 июн. 2018 г.

  • CVE-2022-22980
    44В плане

    A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expres

    КритическаяCVSS 9,8Proof of conceptEPSS 18 %

    vmware · spring data mongodb23 июн. 2022 г.

  • CVE-2020-3956
    41В плане

    VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly han

    ВысокаяCVSS 8,8Proof of conceptEPSS 21 %

    vmware · vcloud director20 мая 2020 г.

  • CVE-2019-5352
    41В плане

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    hp · intelligent management center5 июн. 2019 г.

  • CVE-2019-11949
    41В плане

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    hp · intelligent management center5 июн. 2019 г.

  • CVE-2019-5358
    41В плане

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    hp · intelligent management center5 июн. 2019 г.

  • CVE-2019-5387
    41В плане

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    hp · intelligent management center5 июн. 2019 г.

  • CVE-2018-12532
    41В плане

    JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    redhat · richfaces18 июн. 2018 г.

  • CVE-2020-7169
    41В плане

    A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-7161
    41В плане

    A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-7153
    41В плане

    A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-7151
    41В плане

    A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-24652
    41В плане

    A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-7168
    41В плане

    A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-7141
    41В плане

    A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-7145
    41В плане

    A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

  • CVE-2020-7147
    41В плане

    A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    hp · intelligent management center19 окт. 2020 г.

Все классы уязвимостей