Vulnerabilities (CVE)

Filtered by vendor Stanford Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-39020 1 Stanford 1 Stanford Parser 2023-08-03 N/A 9.8 CRITICAL
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
CVE-2021-44550 1 Stanford 1 Corenlp 2022-07-12 7.5 HIGH 9.8 CRITICAL
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
CVE-2022-0239 1 Stanford 1 Corenlp 2022-01-22 7.5 HIGH 9.8 CRITICAL
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2021-3878 1 Stanford 1 Corenlp 2021-10-20 7.5 HIGH 9.8 CRITICAL
corenlp is vulnerable to Improper Restriction of XML External Entity Reference