Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-28369 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28369)
vulnerability in io.undertow:undertow-parent (CVE-2026-28369). Confidential information can be exposed externally.
|
| CVE-2026-28367 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28367)
vulnerability in io.undertow:undertow-parent (CVE-2026-28367). Confidential information can be exposed externally.
|
| CVE-2026-28368 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28368)
vulnerability in io.undertow:undertow-parent (CVE-2026-28368). Confidential information can be exposed externally.
|
| CVE-2026-4874 |
|
SSRF (Server-Side Request Forgery) in org.keycloak:keycloak-services (CVE-2026-4874)
SSRF in org.keycloak:keycloak-services (CVE-2026-4874). Risk of unauthorized operations or information disclosure. Exploitable via ``client_session_host``. Mitigation: upgrade to `26.4.13` or later.
|
| CVE-2026-4366 |
|
SSRF (Server-Side Request Forgery) in redhat (CVE-2026-4366)
SSRF in redhat (CVE-2026-4366). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3009 |
|
Authorization Flaw in redhat (CVE-2026-3009)
vulnerability in redhat (CVE-2026-3009). Confidential information can be exposed externally.
|
| CVE-2025-12543 |
|
Vulnerability in redhat (CVE-2025-12543)
vulnerability in redhat (CVE-2025-12543). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2025-9784 |
|
Vulnerability in io.undertow:undertow-core (CVE-2025-9784)
vulnerability in io.undertow:undertow-core (CVE-2025-9784). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.20.Final` or later.
|
| CVE-2025-23368 |
|
Vulnerability in redhat (CVE-2025-23368)
vulnerability in redhat (CVE-2025-23368). Successful exploitation can lead to full system takeover.
|
| CVE-2025-23367 |
|
Vulnerability in redhat (CVE-2025-23367)
vulnerability in redhat (CVE-2025-23367). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-10234 |
|
Cross-Site Scripting (XSS) in redhat (CVE-2024-10234)
cross-site scripting in redhat (CVE-2024-10234). Confidential information can be exposed externally.
|
| CVE-2024-7885 |
|
Vulnerability in redhat (CVE-2024-7885)
vulnerability in redhat (CVE-2024-7885). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-1635 |
|
Vulnerability in netapp (CVE-2024-1635)
vulnerability in netapp (CVE-2024-1635). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-48795 |
|
Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
|
| CVE-2023-5379 |
|
Vulnerability in dos (CVE-2023-5379)
vulnerability in dos (CVE-2023-5379). Confidential information can be exposed externally.
|
| CVE-2023-44487 KEV |
|
[KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
|
| CVE-2010-1428 KEV |
|
[KEV] Vulnerability in Red hat red-hat (CVE-2010-1428)
vulnerability in Red hat red-hat (CVE-2010-1428). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2010-0738 KEV |
|
[KEV] Vulnerability in Red hat red-hat (CVE-2010-0738)
vulnerability in Red hat red-hat (CVE-2010-0738). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-12617 KEV |
|
[KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12617)
vulnerability in Apache tomcat (CVE-2017-12617). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-4104 |
|
Unsafe Deserialization in apache (CVE-2021-4104)
vulnerability in apache (CVE-2021-4104). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12149 KEV |
|
[KEV] Unsafe Deserialization in Red hat red-hat (CVE-2017-12149)
vulnerability in Red hat red-hat (CVE-2017-12149). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-10219 |
|
Cross-Site Scripting (XSS) in redhat (CVE-2019-10219)
cross-site scripting in redhat (CVE-2019-10219). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12174 |
|
Vulnerability in apache (CVE-2017-12174)
vulnerability in apache (CVE-2017-12174). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-8610 |
|
Vulnerability in dos (CVE-2016-8610)
vulnerability in dos (CVE-2016-8610). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-7501 |
|
Unsafe Deserialization in apache (CVE-2015-7501)
vulnerability in apache (CVE-2015-7501). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12629 |
|
XXE (XML External Entity) in c (CVE-2017-12629)
vulnerability in c (CVE-2017-12629). Successful exploitation can lead to full system takeover.
|
| CVE-2015-1849 |
|
Information Disclosure in redhat (CVE-2015-1849)
vulnerability in redhat (CVE-2015-1849). Confidential information can be exposed externally.
|
| CVE-2017-7561 |
|
Vulnerability in redhat (CVE-2017-7561)
vulnerability in redhat (CVE-2017-7561). Data can be tampered with by attackers.
|
| CVE-2016-6311 |
|
Information Disclosure in redhat (CVE-2016-6311)
vulnerability in redhat (CVE-2016-6311). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-6796 |
|
Vulnerability in apache (CVE-2016-6796)
vulnerability in apache (CVE-2016-6796). Data can be tampered with by attackers.
|
| CVE-2016-5018 |
|
Vulnerability in apache (CVE-2016-5018)
vulnerability in apache (CVE-2016-5018). Confidential information can be exposed externally.
|
| CVE-2017-9788 |
|
Vulnerability in apache (CVE-2017-9788)
vulnerability in apache (CVE-2017-9788). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2016-3690 |
|
Unsafe Deserialization in redhat (CVE-2016-3690)
vulnerability in redhat (CVE-2016-3690). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7504 |
|
Unsafe Deserialization in deserialization (CVE-2017-7504)
vulnerability in deserialization (CVE-2017-7504). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7503 |
|
XXE (XML External Entity) in ssrf (CVE-2017-7503)
vulnerability in ssrf (CVE-2017-7503). Successful exploitation can lead to full system takeover.
|
| CVE-2016-4978 |
|
Unsafe Deserialization in apache (CVE-2016-4978)
vulnerability in apache (CVE-2016-4978). Successful exploitation can lead to full system takeover.
|
| CVE-2016-2183 |
|
Information Disclosure in redhat (CVE-2016-2183)
vulnerability in redhat (CVE-2016-2183). Confidential information can be exposed externally.
|
| CVE-2012-4550 |
|
Vulnerability in redhat (CVE-2012-4550)
vulnerability in redhat (CVE-2012-4550). Risk of unauthorized operations or information disclosure.
|
| CVE-2012-4549 |
|
Vulnerability in redhat (CVE-2012-4549)
vulnerability in redhat (CVE-2012-4549). Risk of unauthorized operations or information disclosure.
|