Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-46607 |
|
Vulnerability in thecosy (CVE-2024-46607)
vulnerability in thecosy (CVE-2024-46607). Confidential information can be exposed externally.
|
| CVE-2024-5971 |
|
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not s...
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource co...
|
| CVE-2024-23077 |
|
Vulnerability in jfree (CVE-2024-23077)
vulnerability in jfree (CVE-2024-23077). Confidential information can be exposed externally.
|
| CVE-2024-23076 |
|
Vulnerability in jfree (CVE-2024-23076)
vulnerability in jfree (CVE-2024-23076). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-25294 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2024-25294)
SSRF in ssrf (CVE-2024-25294). Confidential information can be exposed externally.
|
| CVE-2024-23680 |
|
Vulnerability in amazon (CVE-2024-23680)
vulnerability in amazon (CVE-2024-23680). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-23681 |
|
Vulnerability in ls1intum (CVE-2024-23681)
vulnerability in ls1intum (CVE-2024-23681). Successful exploitation can lead to full system takeover.
|
| CVE-2024-23682 |
|
Vulnerability in ls1intum (CVE-2024-23682)
vulnerability in ls1intum (CVE-2024-23682). Successful exploitation can lead to full system takeover.
|
| CVE-2024-23683 |
|
Vulnerability in ls1intum (CVE-2024-23683)
vulnerability in ls1intum (CVE-2024-23683). Successful exploitation can lead to full system takeover.
|
| CVE-2024-23684 |
|
Vulnerability in dos (CVE-2024-23684)
vulnerability in dos (CVE-2024-23684). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-48795 |
|
Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
|
| CVE-2023-42917 KEV |
|
[KEV] Out-of-Bounds Write in Apple java (CVE-2023-42917)
out-of-bounds write in Apple java (CVE-2023-42917). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
|
| CVE-2023-43856 |
|
Vulnerability in iteachyou (CVE-2023-43856)
vulnerability in iteachyou (CVE-2023-43856). Confidential information can be exposed externally.
|
| CVE-2023-41993 KEV |
|
[KEV] Vulnerability in Apple java (CVE-2023-41993)
vulnerability in Apple java (CVE-2023-41993). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.8.0, 8.0.411` or later.
|
| CVE-2022-47966 KEV |
|
[KEV] Vulnerability in Zoho manageengine (CVE-2022-47966)
vulnerability in Zoho manageengine (CVE-2022-47966). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-21626 |
|
Vulnerability in c (CVE-2022-21626)
vulnerability in c (CVE-2022-21626). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-21624 |
|
Unsafe Deserialization in c (CVE-2022-21624)
vulnerability in c (CVE-2022-21624). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-34169 |
|
Vulnerability in apache (CVE-2022-34169)
vulnerability in apache (CVE-2022-34169). Data can be tampered with by attackers.
|
| CVE-2022-21952 |
|
Vulnerability in dos (CVE-2022-21952)
vulnerability in dos (CVE-2022-21952). Risk of unauthorized operations or information disclosure.
|
| CVE-2013-0431 KEV |
|
[KEV] Vulnerability in Oracle java-runtime-environment-jre (CVE-2013-0431)
vulnerability in Oracle java-runtime-environment-jre (CVE-2013-0431). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2015-1916 |
|
Vulnerability in dos (CVE-2015-1916)
vulnerability in dos (CVE-2015-1916). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-7795 |
|
Cross-Site Scripting (XSS) in schneider-electric (CVE-2018-7795)
cross-site scripting in schneider-electric (CVE-2018-7795). Risk of unauthorized operations or information disclosure.
|
| CVE-2012-4681 KEV |
|
[KEV] Vulnerability in Oracle java-se (CVE-2012-4681)
vulnerability in Oracle java-se (CVE-2012-4681). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2012-1723 KEV |
|
[KEV] Vulnerability in Oracle java-se (CVE-2012-1723)
vulnerability in Oracle java-se (CVE-2012-1723). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2012-0507 KEV |
|
[KEV] Vulnerability in Oracle java-se (CVE-2012-0507)
vulnerability in Oracle java-se (CVE-2012-0507). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-23437 |
|
Vulnerability in apache (CVE-2022-23437)
vulnerability in apache (CVE-2022-23437). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-44832 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.
|
| CVE-2021-40690 |
|
Information Disclosure in apache (CVE-2021-40690)
vulnerability in apache (CVE-2021-40690). Confidential information can be exposed externally.
|
| CVE-2021-27084 |
|
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
|
| CVE-2020-17521 |
|
Vulnerability in apache (CVE-2020-17521)
vulnerability in apache (CVE-2020-17521). Confidential information can be exposed externally.
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-1258 |
|
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
|
| CVE-2017-8046 |
|
Vulnerability in spring (CVE-2017-8046)
vulnerability in spring (CVE-2017-8046). Successful exploitation can lead to full system takeover.
|
| CVE-2013-4578 |
|
Vulnerability in oracle (CVE-2013-4578)
vulnerability in oracle (CVE-2013-4578). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-3630 |
|
XXE (XML External Entity) in dos (CVE-2014-3630)
vulnerability in dos (CVE-2014-3630). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5641 |
|
Unsafe Deserialization in apache (CVE-2017-5641)
vulnerability in apache (CVE-2017-5641). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17745 |
|
Cross-Site Scripting (XSS) in tp-link (CVE-2017-17745)
cross-site scripting in tp-link (CVE-2017-17745). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17715 |
|
Path Traversal in path-traversal (CVE-2017-17715)
path traversal in path-traversal (CVE-2017-17715). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14589 |
|
Vulnerability in atlassian (CVE-2017-14589)
vulnerability in atlassian (CVE-2017-14589). Successful exploitation can lead to full system takeover.
|
| CVE-2017-13098 |
|
Vulnerability in bouncycastle (CVE-2017-13098)
vulnerability in bouncycastle (CVE-2017-13098). Confidential information can be exposed externally.
|
| CVE-2017-15708 |
|
Vulnerability in apache (CVE-2017-15708)
vulnerability in apache (CVE-2017-15708). Successful exploitation can lead to full system takeover.
|
| CVE-2017-16881 |
|
Cross-Site Scripting (XSS) in symphony-project (CVE-2017-16881)
cross-site scripting in symphony-project (CVE-2017-16881). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-1000209 |
|
Vulnerability in nv-websocket-client-project (CVE-2017-1000209)
vulnerability in nv-websocket-client-project (CVE-2017-1000209). Confidential information can be exposed externally.
|
| CVE-2017-12633 |
|
Unsafe Deserialization in apache (CVE-2017-12633)
vulnerability in apache (CVE-2017-12633). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12634 |
|
Unsafe Deserialization in apache (CVE-2017-12634)
vulnerability in apache (CVE-2017-12634). Successful exploitation can lead to full system takeover.
|
| CVE-2017-16821 |
|
Cross-Site Scripting (XSS) in b3log (CVE-2017-16821)
cross-site scripting in b3log (CVE-2017-16821). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-7501 |
|
Unsafe Deserialization in apache (CVE-2015-7501)
vulnerability in apache (CVE-2015-7501). Successful exploitation can lead to full system takeover.
|