Category: KEV Catalog

KEV Catalog: VMware Spring Cloud Gateway Code Injection Vulnerability (CVE-2022-22947)

Wyatt Dahlenburg found this Expression Language injection vulnerability.  Applications using Spring Cloud Gateway are vulnerable to a code...

by Cody Rubio
Read More

KEV Catalog: Apache Airflow “Example DAG” Command Injection (CVE-2020-11978)

CVE-2020-11978 is a remote code injection vulnerability related to Apache Airflow versions 1.10.10 and below.

by Cody Rubio
Read More

KEV Catalog: Debian-specific Redis Server Lua Sandbox Escape Vulnerability (CVE-2022-0543)

Reginaldo Silva discovered a Debian-specific Lua sandbox escape in Redis, a persistent key-value database.

by Cody Rubio
Read More

KEV Catalog: “Spring4Shell” Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)

The “Spring4Shell” vulnerability, CVE-2022-22965, is a remote code execution vulnerability. It affects Spring Core applications running on...

by Cody Rubio
Read More

KEV Catalog: “Drupalgeddon2”: Drupal Module Configuration Vulnerability CVE-2018-7600

On March 28, 2018 Drupal announced a remote code execution vulnerability on specific Drupal versions of 6,...

by Cody Rubio
Read More

KEV Catalog: “Ghostcat” Apache Tomcat Improper Privilege Management Vulnerability (CVE-2020-1938)

CVE-2020-1938, dubbed Tomcat Ghost or Ghostcat, is a Local File Inclusion (LFI) vulnerability in Apache Tomcat’s Apache...

by Cody Rubio
Read More

KEV Catalog: Apache CouchDB Remote Privilege Escalation (CVE-2022-24706)

The Apache CouchDB Remote Privilege Escalation vulnerability is due to an open distribution port that also uses...

by codyrubio
Read More