| Allocation of Resources Without Limits or Throttling | |
| CVE-2024-27281 | |
| CVE-2024-27280 | |
| Double Free | |
| Reliance on Cookies without Validation and Integrity Checking | |
| Arbitrary Command Injection | |
| Arbitrary Code Injection | |
| CVE-2018-16396 | |
| Out-of-bounds Read | |
| Directory Traversal | |
| Improper Authentication | |
| Exposure of Resource to Wrong Sphere | |
| CVE-2019-15845 | |
| Use of Externally-Controlled Format String | |
| CVE-2018-16395 | |
| Inefficient Regular Expression Complexity | |
| Inadequate Encryption Strength | |
| XML External Entity (XXE) Injection | |
| Directory Traversal | |
| Arbitrary Code Injection | |
| Improper Input Validation | |
| Arbitrary Code Injection | |
| Origin Validation Error | |
| Inefficient Regular Expression Complexity | |
| Arbitrary Code Injection | |
| Integer Overflow or Wraparound | |
| Improper Input Validation | |
| Information Exposure | |
| Inefficient Regular Expression Complexity | |
| HTTP Request Smuggling | |
| CVE-2024-27282 | |
| Improper Input Validation | |
| Out-of-Bounds | |
| Improper Input Validation | |
| Resource Exhaustion | |
| Directory Traversal | |
| OS Command Injection | |
| Out-of-Bounds | |
| HTTP Response Splitting | |
| Use of Externally-Controlled Format String | |
| Improper Authentication | |