Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aris MEDIUM 6.8
CVE-2025-66837

A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

Fix: after 10.0.23.0.3587512
Fix from $1,600 2026-01-07
Aris MEDIUM 6.5
CVE-2025-66838

In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files…

Fix: after 10.0.23.0.3587512
Fix from $1,600 2026-01-07
Webmethods MEDIUM 6.5
CVE-2023-6578

A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.serve…

Fix: after 10.15.4
Fix from $1,600 2023-12-07
Webmethods CRITICAL 9.8
CVE-2023-0925

Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 b…

Mitigation only
Fix from $2,300 2023-09-06
Quartz CRITICAL 9.8
CVE-2023-39017

quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.exec…

Fix: after 2.3.2
Fix from $2,300 2023-07-28
Connx MEDIUM 6.5
CVE-2021-40650

In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

No fix yet
Fix from $1,600 2022-06-14
Connx MEDIUM 6.5
CVE-2021-40649

In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

No fix yet
Fix from $1,600 2022-06-14
Mashzone Nextgen CRITICAL 9.8
CVE-2021-33207

The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.

Fix: after 10.7
Fix from $2,300 2022-04-05
Mashzone Nextgen HIGH 7.2
CVE-2021-33523

MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can execute a…

Fix: after 10.7
Fix from $1,950 2022-03-30
Mashzone Nextgen HIGH 7.2
CVE-2021-33208

The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration f…

Fix: after 10.7
Fix from $1,950 2022-03-30
Mashzone Nextgen HIGH 7.2
CVE-2021-33581

MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to…

Fix: after 10.7
Fix from $1,950 2022-03-30
Terracotta Server Oss CRITICAL 9.8
CVE-2020-35469

The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the…

Mitigation only
Fix from $2,300 2020-12-16