Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: java Clear
ID Title
CVE-2024-46607 Vulnerability in thecosy (CVE-2024-46607)
vulnerability in thecosy (CVE-2024-46607). Confidential information can be exposed externally.
CVE-2024-5971 A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not s...
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource co...
CVE-2024-23077 Vulnerability in jfree (CVE-2024-23077)
vulnerability in jfree (CVE-2024-23077). Confidential information can be exposed externally.
CVE-2024-23076 Vulnerability in jfree (CVE-2024-23076)
vulnerability in jfree (CVE-2024-23076). Risk of unauthorized operations or information disclosure.
CVE-2024-25294 SSRF (Server-Side Request Forgery) in ssrf (CVE-2024-25294)
SSRF in ssrf (CVE-2024-25294). Confidential information can be exposed externally.
CVE-2024-23680 Vulnerability in amazon (CVE-2024-23680)
vulnerability in amazon (CVE-2024-23680). Risk of unauthorized operations or information disclosure.
CVE-2024-23681 Vulnerability in ls1intum (CVE-2024-23681)
vulnerability in ls1intum (CVE-2024-23681). Successful exploitation can lead to full system takeover.
CVE-2024-23682 Vulnerability in ls1intum (CVE-2024-23682)
vulnerability in ls1intum (CVE-2024-23682). Successful exploitation can lead to full system takeover.
CVE-2024-23683 Vulnerability in ls1intum (CVE-2024-23683)
vulnerability in ls1intum (CVE-2024-23683). Successful exploitation can lead to full system takeover.
CVE-2024-23684 Vulnerability in dos (CVE-2024-23684)
vulnerability in dos (CVE-2024-23684). Risk of unauthorized operations or information disclosure.
CVE-2023-48795 Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
CVE-2023-42917 KEV [KEV] Out-of-Bounds Write in Apple java (CVE-2023-42917)
out-of-bounds write in Apple java (CVE-2023-42917). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
CVE-2023-43856 Vulnerability in iteachyou (CVE-2023-43856)
vulnerability in iteachyou (CVE-2023-43856). Confidential information can be exposed externally.
CVE-2023-41993 KEV [KEV] Vulnerability in Apple java (CVE-2023-41993)
vulnerability in Apple java (CVE-2023-41993). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
CVE-2022-47966 KEV [KEV] Vulnerability in Zoho manageengine (CVE-2022-47966)
vulnerability in Zoho manageengine (CVE-2022-47966). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2022-21626 Vulnerability in c (CVE-2022-21626)
vulnerability in c (CVE-2022-21626). Risk of unauthorized operations or information disclosure.
CVE-2022-21624 Unsafe Deserialization in c (CVE-2022-21624)
vulnerability in c (CVE-2022-21624). Risk of unauthorized operations or information disclosure.
CVE-2022-34169 Vulnerability in apache (CVE-2022-34169)
vulnerability in apache (CVE-2022-34169). Data can be tampered with by attackers.
CVE-2022-21952 Vulnerability in dos (CVE-2022-21952)
vulnerability in dos (CVE-2022-21952). Risk of unauthorized operations or information disclosure.
CVE-2013-0431 KEV [KEV] Vulnerability in Oracle java-runtime-environment-jre (CVE-2013-0431)
vulnerability in Oracle java-runtime-environment-jre (CVE-2013-0431). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2015-1916 Vulnerability in dos (CVE-2015-1916)
vulnerability in dos (CVE-2015-1916). Risk of unauthorized operations or information disclosure.
CVE-2018-7795 Cross-Site Scripting (XSS) in schneider-electric (CVE-2018-7795)
cross-site scripting in schneider-electric (CVE-2018-7795). Risk of unauthorized operations or information disclosure.
CVE-2012-4681 KEV [KEV] Vulnerability in Oracle java-se (CVE-2012-4681)
vulnerability in Oracle java-se (CVE-2012-4681). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2012-1723 KEV [KEV] Vulnerability in Oracle java-se (CVE-2012-1723)
vulnerability in Oracle java-se (CVE-2012-1723). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2012-0507 KEV [KEV] Vulnerability in Oracle java-se (CVE-2012-0507)
vulnerability in Oracle java-se (CVE-2012-0507). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2022-23437 Vulnerability in apache (CVE-2022-23437)
vulnerability in apache (CVE-2022-23437). Risk of unauthorized operations or information disclosure.
CVE-2021-44832 Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.
CVE-2021-40690 Information Disclosure in apache (CVE-2021-40690)
vulnerability in apache (CVE-2021-40690). Confidential information can be exposed externally.
CVE-2021-27084 Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
CVE-2020-17521 Vulnerability in apache (CVE-2020-17521)
vulnerability in apache (CVE-2020-17521). Confidential information can be exposed externally.
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10673 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2019-10086 Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
CVE-2018-1258 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CVE-2017-8046 Vulnerability in spring (CVE-2017-8046)
vulnerability in spring (CVE-2017-8046). Successful exploitation can lead to full system takeover.
CVE-2013-4578 Vulnerability in oracle (CVE-2013-4578)
vulnerability in oracle (CVE-2013-4578). Risk of unauthorized operations or information disclosure.
CVE-2014-3630 XXE (XML External Entity) in dos (CVE-2014-3630)
vulnerability in dos (CVE-2014-3630). Successful exploitation can lead to full system takeover.
CVE-2017-5641 Unsafe Deserialization in apache (CVE-2017-5641)
vulnerability in apache (CVE-2017-5641). Successful exploitation can lead to full system takeover.
CVE-2017-17745 Cross-Site Scripting (XSS) in tp-link (CVE-2017-17745)
cross-site scripting in tp-link (CVE-2017-17745). Risk of unauthorized operations or information disclosure.
CVE-2017-17715 Path Traversal in path-traversal (CVE-2017-17715)
path traversal in path-traversal (CVE-2017-17715). Successful exploitation can lead to full system takeover.
CVE-2017-14589 Vulnerability in atlassian (CVE-2017-14589)
vulnerability in atlassian (CVE-2017-14589). Successful exploitation can lead to full system takeover.
CVE-2017-13098 Vulnerability in bouncycastle (CVE-2017-13098)
vulnerability in bouncycastle (CVE-2017-13098). Confidential information can be exposed externally.
CVE-2017-15708 Vulnerability in apache (CVE-2017-15708)
vulnerability in apache (CVE-2017-15708). Successful exploitation can lead to full system takeover.
CVE-2017-16881 Cross-Site Scripting (XSS) in symphony-project (CVE-2017-16881)
cross-site scripting in symphony-project (CVE-2017-16881). Risk of unauthorized operations or information disclosure.
CVE-2017-1000209 Vulnerability in nv-websocket-client-project (CVE-2017-1000209)
vulnerability in nv-websocket-client-project (CVE-2017-1000209). Confidential information can be exposed externally.
CVE-2017-12633 Unsafe Deserialization in apache (CVE-2017-12633)
vulnerability in apache (CVE-2017-12633). Successful exploitation can lead to full system takeover.
CVE-2017-12634 Unsafe Deserialization in apache (CVE-2017-12634)
vulnerability in apache (CVE-2017-12634). Successful exploitation can lead to full system takeover.
CVE-2017-16821 Cross-Site Scripting (XSS) in b3log (CVE-2017-16821)
cross-site scripting in b3log (CVE-2017-16821). Risk of unauthorized operations or information disclosure.
CVE-2015-7501 Unsafe Deserialization in apache (CVE-2015-7501)
vulnerability in apache (CVE-2015-7501). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →