Maven incidents

Recent Maven vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

CRITICALMaven

Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover

Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover

com.linecorp.centraldogma:centraldogma-server: before 0.84.0

4 days ago
HIGHMaven

Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)

Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)

com.linecorp.centraldogma:centraldogma-server-mirror-git: before 0.84.0

4 days ago
MODERATEMaven

Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion

Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion

com.linecorp.centraldogma:centraldogma-server-auth-shiro: before 0.84.0

4 days ago
HIGHMaven

GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

org.geonetwork-opensource:gn-web-app: 4.4.0 → 4.4.12

6 days ago
MODERATEMaven

Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing

Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing

io.netty:netty-handler: 4.2.0.Final → 4.2.17.Final

1 week ago
CRITICALMaven

Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext

Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext

io.netty:netty-handler: 4.2.0.Final → 4.2.17.Final

1 week ago
HIGHMaven

Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass

Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass

com.github.jknack:handlebars-springmvc: before 4.5.3

1 week ago
CRITICALMaven

Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`

Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`

org.yamcs:yamcs-core: 5.13.0 → 5.13.2

2 weeks ago
MEDIUMMaven

Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets

Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets

org.yamcs:yamcs-core: 5.13.0 → 5.13.2

2 weeks ago
MEDIUMMaven

Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields

Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields

org.graylog2:graylog2-server: 7.1.0 → 7.1.4

2 weeks ago
CRITICALMaven

Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities

Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities

org.yamcs:yamcs-core: 5.13.0 → 5.13.2

2 weeks ago
HIGHMaven

PowSyBl Core has Command Injection in LocalCommandExecutor-s

PowSyBl Core has Command Injection in LocalCommandExecutor-s

com.powsybl:powsybl-computation-local: before 7.2.2

2 weeks ago
HIGHMaven

Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce

Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce

org.yamcs:yamcs-core: before 5.12.8

2 weeks ago
HIGHMaven

org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output

org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output

org.mariadb:r2dbc-mariadb: before 1.4.1

2 weeks ago
CRITICALMaven

Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)

Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)

org.yamcs:yamcs-core: 5.13.0 → 5.13.2

2 weeks ago
MODERATEMaven

Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens

Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens

org.graylog2:graylog2-server: 6.2.0 → 6.3.12

2 weeks ago
HIGHMaven

org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)

org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)

org.mariadb:r2dbc-mariadb: before 1.4.1

2 weeks ago
CRITICALMaven

Spinnaker: Improper yaml processing on kustomize bake operations

Spinnaker: Improper yaml processing on kustomize bake operations

io.spinnaker.rosco:rosco-manifests: before 2025.3.4

2 weeks ago
HIGHMaven

MapFish Print has XXE that allows reading arbitrary files of certain types

MapFish Print has XXE that allows reading arbitrary files of certain types

org.mapfish.print:print-lib: 3.0.0 → 3.28.30

2 weeks ago
CRITICALMaven

Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)

Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)

org.yamcs:yamcs-core: 5.13.0 → 5.13.2

2 weeks ago
HIGHMaven

org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context

org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context

org.mariadb.jdbc:mariadb-java-client: before 2.7.14

2 weeks ago
HIGHMaven

Yamcs has Reflected XSS in the URL of the Authorize Endpoint

Yamcs has Reflected XSS in the URL of the Authorize Endpoint

org.yamcs:yamcs-core: before 5.9.4

2 weeks ago
MEDIUMMaven

Yamcs has DOM XSS in Extension Routing

Yamcs has DOM XSS in Extension Routing

org.yamcs:yamcs-core: 5.13.0 → 5.13.2

2 weeks ago
HIGHMaven

Yamcs has Unauthenticated Directory Traversal

Yamcs has Unauthenticated Directory Traversal

org.yamcs:yamcs-core: before 5.12.0

2 weeks ago
MEDIUMMaven

Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration

Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration

org.yamcs:yamcs-core: 5.13.0 → 5.13.2

2 weeks ago
HIGHMaven

Fortigate syslog message parser can be exploited to modify or delete fields from the original message

Fortigate syslog message parser can be exploited to modify or delete fields from the original message

org.graylog2:graylog2-server: before 6.3.12

2 weeks ago
HIGHMaven

org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials

org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials

org.mariadb.jdbc:mariadb-java-client: before 2.7.14

2 weeks ago
HIGHMaven

MariaDB has cleartext password disclosure to a MITM on the initial-handshake

MariaDB has cleartext password disclosure to a MITM on the initial-handshake

org.mariadb.jdbc:mariadb-java-client: before 2.7.14

2 weeks ago
HIGHMaven

http4s has HTTP/2 Denial of Service with Ember Backend

http4s has HTTP/2 Denial of Service with Ember Backend

org.http4s:http4s-ember-core_2.12: before 0.23.35

2 weeks ago
HIGHMaven

IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries

IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries

org.codehaus.izpack:izpack-installer: all versions

2 weeks ago
CRITICALMaven

Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability

Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability

org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.25

2 weeks ago
MEDIUMMaven

AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

org.asynchttpclient:async-http-client: 3.0.0.Beta1 → 3.0.11

2 weeks ago
HIGHMaven

Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability

Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability

org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.25

2 weeks ago
HIGHMaven

Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability

Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability

org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.25

2 weeks ago
CRITICALMaven

Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes

Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes

org.apache.camel:camel-undertow: 4.11.0 → 4.14.9

3 weeks ago
HIGHMaven

Sakai Profile Image Deletion has an IDOR

Sakai Profile Image Deletion has an IDOR

org.sakaiproject.profile2:profile2-api: 23.0 → 23.5

3 weeks ago
HIGHMaven

Sakai Conversations has a Stored XSS Issue

Sakai Conversations has a Stored XSS Issue

org.sakaiproject.conversations:sakai-conversations-impl: ≥ 23.0

3 weeks ago
HIGHMaven

Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir

Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir

org.apache.camel:camel-azure-storage-datalake: 4.0.0 → 4.14.9

3 weeks ago
HIGHMaven

Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted

Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted

org.apache.camel:camel-platform-http-main: 4.8.0 → 4.22.0

3 weeks ago
MEDIUMMaven

Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy

Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy

org.apache.camel:camel-knative: 3.15.0 → 4.14.9

3 weeks ago
HIGHMaven

Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir

Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir

org.apache.camel:camel-azure-storage-blob: 4.0.0 → 4.14.9

3 weeks ago
HIGHMaven

Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result

Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result

org.apache.camel:camel-google-storage: 4.0.0 → 4.14.9

3 weeks ago
MEDIUMMaven

Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled

Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled

org.apache.camel:camel-mail: 2.17.0 → 4.14.9

3 weeks ago
CRITICALMaven

Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace

Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace

org.apache.camel:camel-atmosphere-websocket: 4.0.0 → 4.14.9

3 weeks ago
CRITICALMaven

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

org.geotools.jdbc:gt-jdbc-postgis: 35.0 → 35.1

3 weeks ago
HIGHMaven

netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service

netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service

io.netty.incubator:netty-incubator-codec-ohttp: before 0.0.23.Final

3 weeks ago
HIGHMaven

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

3 weeks ago
HIGHMaven

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl: before 0.0.23.Final

3 weeks ago
HIGHMaven

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

3 weeks ago
MEDIUMMaven

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

3 weeks ago
HIGHMaven

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

3 weeks ago
CRITICALMaven

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

org.geoserver:gs-main: before 2.27.0

3 weeks ago
HIGHMaven

XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing

XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing

org.xwiki.platform:xwiki-platform-livedata-livetable: 13.4-rc-1 → 16.10.17

3 weeks ago
LOWMaven

RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max

RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max

com.rabbitmq:amqp-client: before 5.33.0

4 weeks ago
MODERATEMaven

RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM

RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM

com.rabbitmq:amqp-client: before 5.33.0

4 weeks ago
HIGHMaven

Keycloak: Unauthenticated account takeover via reset-credentials flow bypass

Keycloak: Unauthenticated account takeover via reset-credentials flow bypass

org.keycloak:keycloak-services: 26.0.0 → 26.4.15

4 weeks ago
HIGHMaven

RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS

RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS

com.rabbitmq:amqp-client: before 5.33.1

4 weeks ago
HIGHMaven

RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading

RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading

com.rabbitmq:amqp-client: before 5.33.0

4 weeks ago
MODERATEMaven

RabbitMQ Java client malformed body frame triggers raw command assembler exception

RabbitMQ Java client malformed body frame triggers raw command assembler exception

com.rabbitmq:amqp-client: before 5.31.0

4 weeks ago
HIGHMaven

RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation

RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation

com.rabbitmq:amqp-client: before 5.33.1

4 weeks ago
HIGHMaven

Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection

Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection

io.kestra:kestra: before 1.3.24

4 weeks ago
HIGHMaven

Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite

Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite

io.netty:netty-codec-http: 4.2.0.Final → 4.2.17.Final

4 weeks ago
HIGHMaven

Netty: Memory Exhaustion in SctpMessageCompletionHandler

Netty: Memory Exhaustion in SctpMessageCompletionHandler

io.netty:netty-transport-sctp: 4.2.0.Final → 4.2.17.Final

4 weeks ago
HIGHMaven

OpenAM Insecure SSO Cookie Initialization

OpenAM Insecure SSO Cookie Initialization

org.openidentityplatform.openam:openam-core: before 16.1.1

4 weeks ago
CRITICALMaven

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

com.mchange:mchange-commons-java: before 0.6.0

4 weeks ago
CRITICALMaven

Apache Ranger has a Command Injection vulnerability

Apache Ranger has a Command Injection vulnerability

org.apache.ranger:ranger: ≥ 0.6.0

1 month ago
MEDIUMMaven

Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state

Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state

io.netty:netty-codec-redis: before 4.1.136.Final

1 month ago
MEDIUMMaven

jsoup: Cleaner may expose markup with custom raw-text elements

jsoup: Cleaner may expose markup with custom raw-text elements

org.jsoup:jsoup: 1.14.3 → 1.23.1

1 month ago
HIGHMaven

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

1 month agoEPSS 0%
MEDIUMMaven

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

org.apache.httpcomponents.client5:httpclient5: 5.0-alpha1 → 5.6.3

1 month ago
HIGHMaven

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

io.netty:netty-codec-http2: 4.2.0 → 4.2.16.Final

1 month agoEPSS 0%
MODERATEMaven

core-geonetwork has an Open Redirect Bypass

core-geonetwork has an Open Redirect Bypass

org.geonetwork-opensource:geonetwork: ≥ 3.12.0

1 month agoEPSS 0%
HIGHMaven

veraPDF Validation XXE via Rich Text

veraPDF Validation XXE via Rich Text

org.verapdf:validation-model: 1.25.73 → 1.30.2

1 month agoEPSS 0%
MODERATEMaven

veraPDF Parser DoS via PostScript CMap Streams

veraPDF Parser DoS via PostScript CMap Streams

org.verapdf:parser: before 1.30.2

1 month agoEPSS 0%
MODERATEMaven

veraPDF Parser DoS via PostScript Type 1 Font Programs

veraPDF Parser DoS via PostScript Type 1 Font Programs

org.verapdf:parser: before 1.30.2

1 month agoEPSS 0%
HIGHMaven

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.28.0-alpha

1 month agoEPSS 0%
HIGHMaven

veraPDF Validation XXE via XFA

veraPDF Validation XXE via XFA

org.verapdf:validation-model: 1.17.35 → 1.30.2

1 month agoEPSS 0%
HIGHMaven

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

io.quarkus:quarkus-vertx-http: before 3.20.6.2

1 month agoEPSS 0%
MEDIUMMaven

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

org.verapdf:validation-model: 1.17.35 → 1.30.2

1 month agoEPSS 0%
MEDIUMMaven

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.27.0

1 month agoEPSS 0%
HIGHMaven

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

1 month agoEPSS 0%
CRITICALMaven

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

com.cedarpolicy:cedar-java: before 2.3.6

1 month ago
MEDIUMMaven

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

io.netty:netty-codec-dns: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

org.http4s:http4s-blaze-server_2.13: before 0.23.18

1 month ago
HIGHMaven

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

org.http4s:http4s-blaze-server_2.13: before 0.23.18

1 month ago
HIGHMaven

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

io.netty:netty-codec-xml: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

org.http4s:blaze-http_2.13: before 0.23.18

1 month ago
HIGHMaven

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

org.openidentityplatform.opendj:opendj-server-legacy: before 5.1.2

1 month ago
HIGHMaven

LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges

LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges

at.yawk.lz4:lz4-java: before 1.11.1

1 month ago
CRITICALMaven

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

org.openidentityplatform.openam:openam-core: before 16.1.2

1 month ago
CRITICALMaven

fastjson has a remote code execution (RCE) vulnerability

fastjson has a remote code execution (RCE) vulnerability

com.alibaba:fastjson: ≥ 1.2.68

1 month ago
HIGHMaven

Netty: Security Control Bypass via CORS Short-Circuit Failure

Netty: Security Control Bypass via CORS Short-Circuit Failure

io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final

1 month ago
MODERATEMaven

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types

Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types

io.netty:netty-codec-http3: before 4.2.16.Final

1 month ago
HIGHMaven

Netty: TOCTOU in OcspServerCertificateValidator

Netty: TOCTOU in OcspServerCertificateValidator

io.netty:netty-handler-ssl-ocsp: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling

Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling

io.netty:netty-codec-xml: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion

Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion

io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

io.netty:netty-codec-compression: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

io.netty:netty-handler-ssl-ocsp: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation

Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation

io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final

1 month ago
MODERATEMaven

Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections

Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections

org.eclipse.jetty:jetty-server: 12.0.0 → 12.0.36

1 month ago
MODERATEMaven

Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service

Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service

io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final

1 month ago
MEDIUMMaven

Eclipse Jetty: Path parameter traversal

Eclipse Jetty: Path parameter traversal

org.eclipse.jetty:jetty-util: 12.0.0 → 12.0.35

1 month ago
HIGHMaven

Netty SPDY SETTINGS frame count materializes unbounded settings map

Netty SPDY SETTINGS frame count materializes unbounded settings map

io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final

1 month ago
MODERATEMaven

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

io.netty:netty-codec-http2: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution

Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution

org.eclipse.jetty:jetty-security: 9.4.0.v20161208 → 9.4.63

1 month ago
HIGHMaven

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

io.netty:netty-codec-stomp: 4.2.0.Final → 4.2.16.Final

1 month agoEPSS 0%
HIGHMaven

Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

io.netty:netty-handler-ssl-ocsp: 4.2.0.Final → 4.2.16.Final

1 month ago
HIGHMaven

Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion

Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion

io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.16.Final

1 month ago
MEDIUMMaven

Eclipse Jetty: HTTP Authority/Host mismatch

Eclipse Jetty: HTTP Authority/Host mismatch

org.eclipse.jetty:jetty-server: ≥ 9.4.0.v20161208

1 month ago
HIGHMaven

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

com.fasterxml.jackson.core:jackson-core: before 2.18.8

1 month ago
MEDIUMMaven

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

com.fasterxml.jackson.core:jackson-databind: 2.15.0 → 2.18.8

1 month ago
HIGHMaven

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

org.postgresql:postgresql: 42.7.4 → 42.7.12

1 month ago
HIGHMaven

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.5

1 month agoEPSS 0%
MEDIUMMaven

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

com.fasterxml.jackson.core:jackson-databind: 2.18.0 → 2.18.9

1 month ago
HIGHMaven

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

com.arcadedb:arcadedb-engine: before 26.7.2

2 months agoEPSS 1%
HIGHMaven

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

com.arcadedb:arcadedb-server: before 26.7.2

2 months agoEPSS 0%
HIGHMaven

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

com.arcadedb:arcadedb-engine: before 26.7.2

2 months agoEPSS 0%
HIGHMaven

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

com.datadoghq:dd-java-agent: before 1.62.0

2 months ago
HIGHMaven

Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder

Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder

io.netty:netty-codec-stomp: 4.2.0.Alpha1 → 4.2.16.Final

2 months ago
MODERATEMaven

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

org.apache.logging.log4j:log4j-api: 2.13.1 → 2.25.5

2 months ago
HIGHMaven

Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers

Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers

io.micronaut:micronaut-http-client: 1.2.8 → 3.10.6

2 months ago
HIGHMaven

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

io.micronaut:micronaut-http-client: before 3.10.7

2 months ago
MEDIUMMaven

Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input

Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input

org.apache.camel:camel-couchdb: 4.0.0 → 4.14.8

2 months ago
CRITICALMaven

Apache Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter

Apache Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter

org.apache.camel:camel-pqc: 4.18.0 → 4.18.3

2 months ago
CRITICALMaven

Apache Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers

Apache Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers

org.apache.camel:camel-cometd: 4.0.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)

Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)

org.apache.camel:camel-neo4j: 4.10.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters

Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters

org.apache.camel:camel-langchain4j-tools: 4.8.0 → 4.18.3

2 months ago
CRITICALMaven

Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure

Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure

org.apache.camel:camel-jms: 4.14.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy

Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy

org.apache.camel:camel-atmosphere-websocket: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter

Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter

org.apache.camel:camel-irc: 4.0.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy

Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy

org.apache.camel:camel-vertx-websocket: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body

Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body

org.apache.camel:camel-netty-http: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body

Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body

org.apache.camel:camel-undertow: 4.0.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields

Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields

org.apache.camel:camel-solr: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel JMS deserialization filter bypass

Apache Camel JMS deserialization filter bypass

org.apache.camel:camel-jms: 3.0.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer

Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer

org.apache.camel:camel-docling: 4.15.0 → 4.18.3

2 months ago
MEDIUMMaven

Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input

Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input

org.apache.camel:camel-couchbase: 4.0.0 → 4.14.8

2 months ago
CRITICALMaven

Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution

Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution

org.apache.camel:camel-hazelcast: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter

Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter

org.apache.camel:camel-kafka: 4.0.0 → 4.14.8

2 months ago
CRITICALMaven

Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted

Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted

org.apache.camel:camel-keycloak: 4.18.0 → 4.18.3

2 months ago
MEDIUMMaven

Apache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation

Apache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation

org.apache.camel:camel-elasticsearch-rest-client: 4.3.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy

Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy

org.apache.camel:camel-iggy: 4.17.0 → 4.18.3

2 months ago
HIGHMaven

Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation

Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation

org.apache.camel:camel-cxf-soap: 4.0.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query

Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query

org.apache.camel:camel-lucene: 4.0.0 → 4.14.8

2 months ago
HIGHMaven

Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers

Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers

org.apache.camel:camel-nats: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties

Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties

org.apache.camel:camel-mail: 4.0.0 → 4.14.8

2 months ago
CRITICALMaven

Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers

Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers

org.apache.camel:camel-aws2-sqs: 4.0.0 → 4.14.8

2 months ago
CRITICALMaven

Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled

Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled

org.apache.camel:camel-vertx-http: 4.0.0 → 4.14.8

2 months ago
CRITICALMaven

Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy

Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy

org.apache.camel:camel-aws2-sns: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers

Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers

org.apache.camel:camel-dapr: 4.12.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter

Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter

org.apache.camel:camel-jira: 4.0.0 → 4.14.8

2 months ago
MEDIUMMaven

Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter

Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter

org.apache.camel:camel-salesforce: 4.0.0 → 4.14.8

2 months ago
CRITICALMaven

Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)

Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)

org.apache.camel:camel-pqc: 4.18.0 → 4.18.3

2 months ago
HIGHMaven

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

org.keycloak:keycloak-services: all versions

2 months ago
HIGHMaven

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

org.apache.httpcomponents.core5:httpcore5: before 5.4.3

2 months ago
HIGHMaven

Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK

Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK

org.apache.httpcomponents.core5:httpcore5-h2: before 5.4.3

2 months ago
HIGHMaven

JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution

JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution

org.jetbrains.kotlin:kotlin-gradle-plugin: before 2.4.20-Beta1

2 months ago
MEDIUMMaven

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

com.fasterxml.jackson.core:jackson-databind: 2.0.0 → 2.18.8

2 months ago
MEDIUMMaven

jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields

jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields

com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.4

2 months ago
CRITICALMaven

jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation

jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation

com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8

2 months ago
MEDIUMMaven

jackson-databind has a @JsonView bypass for unwrapped creator parameters

jackson-databind has a @JsonView bypass for unwrapped creator parameters

com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.4

2 months ago
HIGHMaven

jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()

jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()

com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.14.0

2 months ago
MEDIUMMaven

jackson-databind has @JsonView bypass for setterless creator properties

jackson-databind has @JsonView bypass for setterless creator properties

com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.4

2 months ago
MEDIUMMaven

jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties

jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties

com.fasterxml.jackson.core:jackson-databind: 3.1.0 → 3.1.4

2 months ago
CRITICALMaven

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8

2 months agoEPSS 1%
MEDIUMMaven

Apache Atlas UI: Authenticated User XSS

Apache Atlas UI: Authenticated User XSS

org.apache.atlas:atlas-dashboardv2: before 2.5.0

2 months ago
HIGHMaven

Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types

Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types

io.spinnaker.rosco:rosco-core: before 2025.3.3

2 months ago
HIGHMaven

Apache NiFi: Missing authorization when replacing Process Groups with restricted components

Apache NiFi: Missing authorization when replacing Process Groups with restricted components

org.apache.nifi:nifi-web-api: 1.12.0 → 2.9.0

2 months ago
MEDIUMMaven

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

org.apache.nifi:nifi-jetty: before 2.10.0

2 months ago
LOWMaven

Apache NiFi allows read-only users to submit component configuration verification request

Apache NiFi allows read-only users to submit component configuration verification request

org.apache.nifi:nifi-web-api: 1.15.0 → 2.10.0

2 months ago
HIGHMaven

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

org.jline:jline-remote-telnet: 4.1.0 → 4.2.1

2 months ago
HIGHMaven

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

org.jline:jline-remote-telnet: 4.1.0 → 4.2.1

2 months ago
HIGHMaven

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

org.apache.shiro:shiro-core: before 2.2.1

3 months ago
CRITICALMaven

SNMP4J-Agent allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component

SNMP4J-Agent allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component

org.snmp4j:snmp4j-agent: all versions

3 months ago
HIGHMaven

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final

3 months agoEPSS 0%
HIGHMaven

Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length

Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length

io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores

Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores

org.springframework.ai:spring-ai-opensearch-store: 1.0.0 → 1.0.9

3 months ago
MEDIUMMaven

Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted

Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted

io.netty:netty-codec-http: 4.2.0.Final → 4.2.15.Final

3 months ago
MEDIUMMaven

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

io.netty:netty-codec-classes-quic: 4.2.0.Final → 4.2.15.Final

3 months ago
MEDIUMMaven

Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature

Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature

io.netty:netty-codec-http2: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability

Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability

org.springframework.cloud:spring-cloud-sleuth-instrumentation: ≥ 3.1.0

3 months ago
HIGHMaven

Netty: Wrapping plain trust manager silently disables hostname verification

Netty: Wrapping plain trust manager silently disables hostname verification

io.netty:netty-handler: 4.2.0.Final → 4.2.15.Final

3 months ago
MEDIUMMaven

Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry

Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry

org.apache.cxf:cxf-rt-rs-security-jose-jaxrs: 4.2.0 → 4.2.2

3 months ago
CRITICALMaven

Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator

Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

3 months ago
CRITICALMaven

Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl

Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl

org.apache.cxf:cxf-integration-jca: 4.2.0 → 4.2.2

3 months ago
MEDIUMMaven

Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService

Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

3 months ago
HIGHMaven

Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier

Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

3 months ago
HIGHMaven

Apache cxf-core: No restriction on attachment headers per message

Apache cxf-core: No restriction on attachment headers per message

org.apache.cxf:cxf-core: 4.2.0 → 4.2.2

3 months ago
CRITICALMaven

Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control

Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

3 months ago
HIGHMaven

Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing

Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

3 months ago
CRITICALMaven

Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory

Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory

org.apache.cxf:cxf-rt-transports-jms: 4.2.0 → 4.2.2

3 months ago
MEDIUMMaven

Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection

Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

3 months ago
MEDIUMMaven

Spring Boot: Predictable Temp Directory in Artemis Auto-configuration

Spring Boot: Predictable Temp Directory in Artemis Auto-configuration

org.springframework.boot:spring-boot-autoconfigure: 4.0.0 → 4.0.7

3 months ago
MEDIUMMaven

Spring Web Services: SOAP security faults leak Spring Security account state

Spring Web Services: SOAP security faults leak Spring Security account state

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

3 months ago
MEDIUMMaven

Spring Web Services: X.509 authentication bypasses Spring Security account checks

Spring Web Services: X.509 authentication bypasses Spring Security account checks

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

3 months ago
MEDIUMMaven

Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default

Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

3 months ago
HIGHMaven

Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource

Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource

org.springframework.ws:spring-xml: 5.0.0 → 5.0.2

3 months ago
HIGHMaven

Spring for GraphQL: Cross-Site WebSocket Hijacking

Spring for GraphQL: Cross-Site WebSocket Hijacking

org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4

3 months ago
CRITICALMaven

Spring for GraphQL: Unsafe Deserialization

Spring for GraphQL: Unsafe Deserialization

org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4

3 months ago
HIGHMaven

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final

3 months agoEPSS 1%
HIGHMaven

Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Spring Web Flow has Data Binding Vulnerability with Unified EL Parser

Spring Web Flow has Data Binding Vulnerability with Unified EL Parser

org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1

3 months ago
HIGHMaven

Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default

Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

3 months ago
MEDIUMMaven

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

io.netty:netty-codec-http2: before 4.1.135.Final

3 months agoEPSS 1%
HIGHMaven

Spring for GraphQL: Annotation Detection Vulnerability

Spring for GraphQL: Annotation Detection Vulnerability

org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4

3 months ago
HIGHMaven

Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks

Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks

org.keycloak:keycloak-rest-admin-ui-ext: before 26.7.0

3 months ago
MEDIUMMaven

Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification

Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification

org.springframework.boot:spring-boot-starter-mail: 4.0.0 → 4.0.7

3 months ago
HIGHMaven

Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations

Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations

org.springframework.ws:spring-ws-core: 5.0.0 → 5.0.2

3 months ago
HIGHMaven

Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML

Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML

org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1

3 months ago
HIGHMaven

Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem

Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem

org.springframework.integration:spring-integration-file: 7.0.0 → 7.0.5

3 months ago
MEDIUMMaven

Spring Web Services: WSS4J validation does not use configured replay cache

Spring Web Services: WSS4J validation does not use configured replay cache

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

3 months ago
CRITICALMaven

Jenkins: Stored XSS vulnerability in node offline cause description

Jenkins: Stored XSS vulnerability in node offline cause description

org.jenkins-ci.main:jenkins-core: 2.483 → 2.568

3 months ago
MEDIUMMaven

Jenkins: Missing permission check allows unauthorized cancellation of queue items

Jenkins: Missing permission check allows unauthorized cancellation of queue items

org.jenkins-ci.main:jenkins-core: before 2.555.3

3 months ago
MEDIUMMaven

Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean

Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean

org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4

3 months ago
HIGHMaven

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

3 months ago
HIGHMaven

Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods

Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods

org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6

3 months ago
HIGHMaven

Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference

Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference

org.springframework.restdocs:spring-restdocs-webtestclient: 4.0.0 → 4.0.1

3 months ago
CRITICALMaven

Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization

Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization

org.springframework.pulsar:spring-pulsar: 2.0.0 → 2.0.6

3 months ago
HIGHMaven

Spring Data REST has Improper Access Control in its JSON Patch Implementation

Spring Data REST has Improper Access Control in its JSON Patch Implementation

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

3 months ago
HIGHMaven

Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)

Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

3 months ago
CRITICALMaven

Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection

Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection

org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6

3 months ago
MEDIUMMaven

Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter

Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter

org.springframework.security:spring-security-oauth2-authorization-server: 7.0.0 → 7.0.6

3 months ago
MEDIUMMaven

Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations

Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

3 months ago
MEDIUMMaven

Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference

Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference

org.springframework.data:spring-data-relational: 4.0.0 → 4.0.6

3 months ago
HIGHMaven

Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository

Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

3 months ago
MEDIUMMaven

Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue

Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue

org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4

3 months ago
MEDIUMMaven

Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads

Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

3 months ago
HIGHMaven

Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation

Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation

org.springframework.kafka:spring-kafka: 4.0.0 → 4.0.6

3 months ago
MEDIUMMaven

Spring Data REST potentially exposes persistence-layer internals to HTTP clients

Spring Data REST potentially exposes persistence-layer internals to HTTP clients

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

3 months ago
HIGHMaven

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

3 months ago
HIGHMaven

Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)

Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

3 months ago
MEDIUMMaven

Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL

Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL

org.jenkins-ci.main:jenkins-core: before 2.555.3

3 months ago
MEDIUMMaven

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations

org.jenkins-ci.main:jenkins-core: before 2.555.3

3 months ago
HIGHMaven

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

org.springframework.security:spring-security-web: 6.5.0 → 6.5.11

3 months ago
HIGHMaven

Spring Data Commons: Denial of Service via excessive memory allocation in projection binding

Spring Data Commons: Denial of Service via excessive memory allocation in projection binding

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

3 months ago
MEDIUMMaven

Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL

Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL

org.jenkins-ci.main:jenkins-core: 2.556 → 2.568

3 months ago
MEDIUMMaven

Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache

Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache

org.springframework.security:spring-security-web: 7.0.0 → 7.0.6

3 months ago
HIGHMaven

Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries

Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries

org.springframework.data:spring-data-keyvalue: 4.0.0 → 4.0.6

3 months ago
MEDIUMMaven

Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"

Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"

org.jenkins-ci.main:jenkins-core: before 2.555.3

3 months ago
MEDIUMMaven

Jenkins exposes other users' timezone and view names to users with Overall/Read permission

Jenkins exposes other users' timezone and view names to users with Overall/Read permission

org.jenkins-ci.main:jenkins-core: before 2.555.3

3 months ago
CRITICALMaven

Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation

Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation

org.jenkins-ci.main:jenkins-core: before 2.555.3

3 months ago
HIGHMaven

Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys

Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

3 months ago
MEDIUMMaven

Spring Framework Denial of Service via AntPathMatcher

Spring Framework Denial of Service via AntPathMatcher

org.springframework:spring-core: 7.0.0 → 7.0.8

3 months agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

org.springframework:spring-expression: all versions

3 months agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

3 months agoEPSS 0%
MEDIUMMaven

Spring Framework Denial of Service via Unbounded Cache in SpEL

Spring Framework Denial of Service via Unbounded Cache in SpEL

org.springframework:spring-expression: 7.0.0 → 7.0.8

3 months agoEPSS 0%
HIGHMaven

Spring Framework Algorithmic Denial of Service via SpEL Expressions

Spring Framework Algorithmic Denial of Service via SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

3 months agoEPSS 0%
MEDIUMMaven

Spring Framework Escalation via Session Fixation in WebFlux

Spring Framework Escalation via Session Fixation in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

3 months agoEPSS 0%
MEDIUMMaven

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

org.springframework:spring-webflux: all versions

3 months agoEPSS 0%
MEDIUMMaven

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

3 months agoEPSS 0%
HIGHMaven

Spring Framework Predictable Session ID in WebSocket Module

Spring Framework Predictable Session ID in WebSocket Module

org.springframework:spring-websocket: 7.0.0 → 7.0.8

3 months agoEPSS 0%
MEDIUMMaven

Spring Framework Server-Side Request Forgery via UriComponentsBuilder

Spring Framework Server-Side Request Forgery via UriComponentsBuilder

org.springframework:spring-web: 7.0.0 → 7.0.8

3 months ago
HIGHMaven

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

3 months agoEPSS 0%
HIGHMaven

Micrometer HTTP server instrumentations DoS

Micrometer HTTP server instrumentations DoS

io.micrometer:micrometer-core: 1.16.0 → 1.16.6

3 months ago
HIGHMaven

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

org.springframework.retry:spring-retry: 2.0.0 → 2.0.13

3 months agoEPSS 0%
MEDIUMMaven

Spring Framework Arbitrary Method Invocation in SpEL Expressions

Spring Framework Arbitrary Method Invocation in SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

3 months agoEPSS 0%
MEDIUMMaven

Spring Framework Open Redirect in Spring MVC and WebFlux

Spring Framework Open Redirect in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

3 months agoEPSS 0%
HIGHMaven

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

3 months agoEPSS 0%
MEDIUMMaven

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

io.projectreactor.netty:reactor-netty: 1.3.0 → 1.3.6

3 months agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JSP Form Tags

Spring Framework Cross-site Scripting via JSP Form Tags

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

3 months agoEPSS 0%
CRITICALMaven

Spring Framework Unsafe Deserialization via Jackson JMS Converters

Spring Framework Unsafe Deserialization via Jackson JMS Converters

org.springframework:spring-jms: all versions

3 months ago
HIGHMaven

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

3 months agoEPSS 0%
HIGHMaven

Spring HATEOAS heap exhaustion through unbounded internal caching

Spring HATEOAS heap exhaustion through unbounded internal caching

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

3 months agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JavaScriptUtils

Spring Framework Cross-site Scripting via JavaScriptUtils

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

3 months agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Multipart Requests in WebFlux

Spring Framework Denial of Service via Multipart Requests in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

3 months agoEPSS 0%
HIGHMaven

Spring LDAP has Authentication Bypass with Empty Password

Spring LDAP has Authentication Bypass with Empty Password

org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4

3 months agoEPSS 0%
HIGHMaven

Micrometer gRPC server instrumentation DoS

Micrometer gRPC server instrumentation DoS

io.micrometer:micrometer-core: 1.16.0 → 1.16.6

3 months ago
HIGHMaven

Netty has Insufficient Bailiwick Validation for NS Records

Netty has Insufficient Bailiwick Validation for NS Records

io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final

3 months agoEPSS 0%
HIGHMaven

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final

3 months agoEPSS 0%
HIGHMaven

Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes

Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes

io.netty:netty-handler: 4.2.0.Final → 4.2.15.Final

3 months ago
MEDIUMMaven

Netty: Unix-socket fd receive leaks descriptors when peer sends two at once

Netty: Unix-socket fd receive leaks descriptors when peer sends two at once

io.netty:netty-transport-native-epoll: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port

Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port

io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length

Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length

io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Netty has Unbounded Direct Memory Consumption in its RedisDecoder

Netty has Unbounded Direct Memory Consumption in its RedisDecoder

io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Netty's Default QUIC token handler accepts any client-supplied token

Netty's Default QUIC token handler accepts any client-supplied token

io.netty:netty-codec-classes-quic: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Netty: SCTP reassembly nests buffers without bound

Netty: SCTP reassembly nests buffers without bound

io.netty:netty-transport-sctp: 4.2.0.Final → 4.2.15.Final

3 months ago
HIGHMaven

Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays

Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays

io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final

3 months ago
CRITICALMaven

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking

io.netty:netty-handler: 4.2.0.Final → 4.2.15.Final

3 months ago
MEDIUMMaven

Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced

Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced

io.netty:netty-codec-http2: 4.2.0.Final → 4.2.15.Final

3 months ago
CRITICALMaven

Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass

Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass

org.apache.mina:mina-core: 2.2.0 → 2.2.8

3 months ago
MEDIUMMaven

Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes

Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes

org.apache.calcite:calcite-core: 1.5.0 → 1.42.0

3 months ago
HIGHMaven

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability

org.apache.activemq:apache-activemq: before 5.19.7

3 months ago
LOWMaven

Logback vulnerable to Object Injection through HardenedObjectInputStream modules

Logback vulnerable to Object Injection through HardenedObjectInputStream modules

ch.qos.logback:logback-core: before 1.5.34

3 months ago
HIGHMaven

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue

org.apache.activemq:activemq-broker: before 5.19.7

3 months ago
CRITICALMaven

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue

org.apache.activemq:activemq-broker: before 5.19.7

3 months ago
MEDIUMMaven

Keycloak has an Authentication Bypass by Primary Weakness

Keycloak has an Authentication Bypass by Primary Weakness

org.keycloak:keycloak-services: all versions

3 months ago
HIGHMaven

Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition

Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition

org.keycloak:keycloak-server: before 26.6.4

3 months ago
MEDIUMMaven

Apache Artemis has an Incorrect Authorization issue

Apache Artemis has an Incorrect Authorization issue

org.apache.artemis:artemis-stomp-protocol: 2.50.0 → 2.54.0

3 months ago
LOWMaven

QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability

QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability

ch.qos.logback:logback-core: before 1.5.33

3 months ago
HIGHMaven

Apache Ignite REST API Has a Relative Path Traversal Vulnerability

Apache Ignite REST API Has a Relative Path Traversal Vulnerability

org.apache.ignite:ignite-core: 2.0.0 → 2.18.0

3 months ago
HIGHMaven

Keycloak has an Improper Verification of Cryptographic Signature issue

Keycloak has an Improper Verification of Cryptographic Signature issue

org.keycloak:keycloak-services: all versions

3 months ago
MEDIUMMaven

Keycloak Services has Improper Validation of Consistency within Input

Keycloak Services has Improper Validation of Consistency within Input

org.keycloak:keycloak-services: ≥ 26.5.0

3 months ago
HIGHMaven

Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass

Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass

org.keycloak:keycloak-services: before 26.6.2

3 months ago
HIGHMaven

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

com.squareup.wire:wire-runtime-jvm: before 6.3.0

3 months ago
CRITICALMaven

Keycloak: Session fixation in OIDC login flow that can lead to account takeover

Keycloak: Session fixation in OIDC login flow that can lead to account takeover

org.keycloak:keycloak-services: before 26.6.2

3 months ago
HIGHMaven

Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers

Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers

org.keycloak:keycloak-services: before 26.6.2

3 months ago
HIGHMaven

Keycloak: Access token disclosure and implicit flow bypass via forged client data

Keycloak: Access token disclosure and implicit flow bypass via forged client data

org.keycloak:keycloak-services: before 26.6.2

3 months ago
HIGHMaven

Keycloak: Open redirect when using wildcard valid redirect URIs in Keycloak

Keycloak: Open redirect when using wildcard valid redirect URIs in Keycloak

org.keycloak:keycloak-services: before 26.6.2

3 months ago
HIGHMaven

Keycloak: Denial of Service via specially crafted SAML input

Keycloak: Denial of Service via specially crafted SAML input

org.keycloak:keycloak-saml-core: before 26.6.2

3 months ago
HIGHMaven

Keycloak: Unauthorized account takeover via WebAuthn token replay

Keycloak: Unauthorized account takeover via WebAuthn token replay

org.keycloak:keycloak-services: before 26.6.2

3 months ago
HIGHMaven

Keycloak: Information Disclosure via evaluate-scopes Admin API

Keycloak: Information Disclosure via evaluate-scopes Admin API

org.keycloak:keycloak-services: before 26.6.2

3 months ago
CRITICALMaven

GlassFish's Administration Console is Vulnerable to RCE

GlassFish's Administration Console is Vulnerable to RCE

org.glassfish.main.admingui:console-common: before 8.0.2

3 months ago
CRITICALMaven

GlassFish's gadget handler is vulnerable to RCE

GlassFish's gadget handler is vulnerable to RCE

org.glassfish.main.admingui:admingui: before 8.0.2

3 months ago
MEDIUMMaven

Keycloak Account Resources user lookup contains broken access control

Keycloak Account Resources user lookup contains broken access control

org.keycloak:keycloak-services: before 26.4.12

3 months ago
HIGHMaven

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

ca.uhn.hapi.fhir:org.hl7.fhir.dstu2: before 6.9.7

4 months ago
HIGHMaven

async-http-client: Cookie header not stripped on cross-origin redirect

async-http-client: Cookie header not stripped on cross-origin redirect

org.asynchttpclient:async-http-client: 3.0.0.Beta1 → 3.0.10

4 months ago
MEDIUMMaven

Apache Commons Configuration: StackOverflowError for YAML input with cycles

Apache Commons Configuration: StackOverflowError for YAML input with cycles

org.apache.commons:commons-configuration2: 2.2 → 2.15.0

4 months ago
MEDIUMMaven

Apache Tomcat - WebSocket authentication header exposure

Apache Tomcat - WebSocket authentication header exposure

org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118

4 months ago
HIGHMaven

Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage

Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage

org.springframework.ai:spring-ai-client-chat: before 1.0.7

4 months ago
HIGHMaven

Security feature bypass vulnerability in Azure Key Vault Keys library for Java

Security feature bypass vulnerability in Azure Key Vault Keys library for Java

com.azure:azure-security-keyvault-keys: before 4.10.6

4 months ago
HIGHMaven

Apache Tomcat: LockOutRealm treats user names as case-sensitive

Apache Tomcat: LockOutRealm treats user names as case-sensitive

org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118

4 months ago
HIGHMaven

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118

4 months ago
CRITICALMaven

Apache Tomcat - HTTP/2 request headers not validated

Apache Tomcat - HTTP/2 request headers not validated

org.apache.tomcat.embed:tomcat-embed-core: 8.5.0 → 9.0.118

4 months ago
HIGHMaven

Apache Tomcat - Security constraints not correctly applied

Apache Tomcat - Security constraints not correctly applied

org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118

4 months ago
MEDIUMMaven

Apache Tomcat - AJP secret compared in non-constant time

Apache Tomcat - AJP secret compared in non-constant time

org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118

4 months ago
CRITICALMaven

Apache Tomcat - Digest authenticator will authenticate any unknown user

Apache Tomcat - Digest authenticator will authenticate any unknown user

org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118

4 months ago
HIGHMaven

Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer

Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer

com.ritense.valtimo:web: 12.4.0 → 12.33.0

4 months ago
MEDIUMMaven

Vert.x has a DoS via unbounded server-side SNI SslContext cache growth

Vert.x has a DoS via unbounded server-side SNI SslContext cache growth

io.vertx:vertx-core: ≥ 4.3.4

4 months ago
MODERATEMaven

Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryption

Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryption

org.bouncycastle:bcprov-lts8on: 2.73.0 → 2.73.11

4 months ago
MEDIUMMaven

Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
HIGHMaven

Netty Redis Codec Encoder has a CRLF Injection Issue

Netty Redis Codec Encoder has a CRLF Injection Issue

io.netty:netty-codec-redis: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
HIGHMaven

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

com.microsoft.kiota:microsoft-kiota-abstractions: before 1.9.1

4 months ago
HIGHMaven

Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)

Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)

io.netty:netty-codec-dns: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
HIGHMaven

Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS

Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS

io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
LOWMaven

Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)

Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)

io.netty:netty-handler-proxy: before 4.1.133.Final

4 months ago
HIGHMaven

Netty Lz4FrameDecoder is vulnerable to resource exhaustion

Netty Lz4FrameDecoder is vulnerable to resource exhaustion

io.netty:netty-codec-compression: before 4.2.13.Final

4 months ago
MEDIUMMaven

Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding

Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding

io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
MEDIUMMaven

Netty has HttpClientCodec response desynchronization

Netty has HttpClientCodec response desynchronization

io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
MEDIUMMaven

Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing

Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing

io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
HIGHMaven

Netty HTTP/3 QPACK literal unbounded allocation

Netty HTTP/3 QPACK literal unbounded allocation

io.netty:netty-codec-http3: 4.2.0.Final → 4.2.13.Final

4 months ago
MEDIUMMaven

Netty MQTT: Resource exhaustion in MqttDecoder

Netty MQTT: Resource exhaustion in MqttDecoder

io.netty:netty-codec-mqtt: 4.2.0.Alpha1 → 4.2.13.Final

4 months ago
HIGHMaven

Netty epoll transport denial of service via RST on half-closed TCP connection

Netty epoll transport denial of service via RST on half-closed TCP connection

io.netty:netty-transport-classes-epoll: 4.2.0.Final → 4.2.13.Final

4 months ago
HIGHMaven

axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification

axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification

com.getaxonflow:axonflow-sdk: before 7.0.0

4 months ago
CRITICALMaven

Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users

Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users

com.ritense.valtimo:document: 12.0.0 → 12.32.0

4 months ago
MEDIUMMaven

Apache Wicket has a Path Traversal issue

Apache Wicket has a Path Traversal issue

org.apache.wicket:wicket-core: ≥ 8.0.0-M1

4 months ago
MEDIUMMaven

Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection

Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection

io.netty:netty-codec-http: before 4.1.133.Final

4 months ago
HIGHMaven

pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS

pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS

org.postgresql:postgresql: 42.2.0 → 42.7.11

4 months ago
MEDIUMMaven

Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability

Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability

org.apache.thrift:libthrift: before 0.23.0

4 months ago
CRITICALMaven

ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases

ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases

com.arcadedb:arcadedb-server: 21.10.1 → 26.4.2

4 months agoEPSS 0%
HIGHMaven

Quarkus has Authentication/Authorization bypasses

Quarkus has Authentication/Authorization bypasses

io.quarkus:quarkus-vertx-http: before 3.20.6.1

4 months ago
HIGHMaven

Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing

Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing

org.apache.opennlp:opennlp-tools: before 2.5.9

4 months ago
CRITICALMaven

Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest

Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest

org.apache.opennlp:opennlp-tools: 2.0.0 → 2.5.9

4 months ago
HIGHMaven

Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation

Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation

org.apache.opennlp:opennlp-tools: before 2.5.9

4 months ago
HIGHMaven

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization

org.apache.neethi:neethi: before 3.2.2

4 months ago
CRITICALMaven

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)

org.apache.mina:mina-core: 2.1.0 → 2.1.12

4 months ago
HIGHMaven

Apache Neethi does not properly detect circular references in policy definitions.

Apache Neethi does not properly detect circular references in policy definitions.

org.apache.neethi:neethi: before 3.2.2

4 months ago
MEDIUMMaven

Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API

Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API

org.apache.neethi:neethi: before 3.2.2

4 months ago
CRITICALMaven

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)

org.apache.mina:mina-core: 2.1.0 → 2.1.12

4 months ago
MEDIUMMaven

Keycloak has a Forced Browsing issue

Keycloak has a Forced Browsing issue

org.keycloak:keycloak-services: all versions

4 months ago
MEDIUMMaven

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

org.springframework:spring-webflux: 7.0.0 → 7.0.7

4 months ago
MEDIUMMaven

Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths

Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths

org.jenkins-ci.plugins:script-security: before 1402.v94c9ce464861

4 months ago
CRITICALMaven

Jenkins GitHub Plugin has an XSS vulnerability

Jenkins GitHub Plugin has an XSS vulnerability

com.coravy.hudson.plugins.github:github: before 1.46.0.1

4 months ago
MEDIUMMaven

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

org.springframework:spring-webflux: 7.0.0 → 7.0.7

4 months ago
HIGHMaven

Spring Framework DoS with Multipart Temp Files in WebFlux

Spring Framework DoS with Multipart Temp Files in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.7

4 months ago
HIGHMaven

Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors

Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors

org.jenkins-ci.plugins:matrix-auth: 2.0-beta-1 → 3.2.10

4 months ago
HIGHMaven

Spring Boot's default security filter chain has no authorization rule with Actuator but without Health

Spring Boot's default security filter chain has no authorization rule with Actuator but without Health

org.springframework.boot:spring-boot: 4.0.0 → 4.0.6

4 months ago
CRITICALMaven

Spring Boot accepts predictable temp directory without ownership verification

Spring Boot accepts predictable temp directory without ownership verification

org.springframework.boot:spring-boot: 4.0.0 → 4.0.6

4 months ago
CRITICALMaven

Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)

Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)

org.apache.mina:mina-core: 2.0.0 → 2.0.28

4 months ago
HIGHMaven

Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel

Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel

org.apache.camel:camel-platform-http-main: 4.14.1 → 4.14.6

4 months ago
CRITICALMaven

Camel-PQC Vulnerable to Deserialization of Untrusted Data

Camel-PQC Vulnerable to Deserialization of Untrusted Data

org.apache.camel:camel-pqc: before 4.18.2

4 months ago
CRITICALMaven

Apache MINA vulnerable to Deserialization of Untrusted Data

Apache MINA vulnerable to Deserialization of Untrusted Data

org.apache.mina:mina-core: 2.0.0 → 2.0.28

4 months ago
CRITICALMaven

Apache Camel has an incomplete fix for CVE-2025-27636

Apache Camel has an incomplete fix for CVE-2025-27636

org.apache.camel:camel-coap: 3.0.0 → 4.14.6

4 months ago
CRITICALMaven

Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage

Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage

org.apache.camel:camel-jms: 3.0.0 → 4.14.7

4 months ago
MEDIUMMaven

Apache ActiveMQ Vulnerable to Cross-site Scripting

Apache ActiveMQ Vulnerable to Cross-site Scripting

org.apache.activemq:apache-activemq: before 5.19.6

4 months ago
CRITICALMaven

Apache ActiveMQ Vulnerable to Improper Input Validation and Code Injection

Apache ActiveMQ Vulnerable to Improper Input Validation and Code Injection

org.apache.activemq:apache-activemq: before 5.19.6

4 months ago
CRITICALMaven

Apache ActiveMQ Vulnerable to Code Injection

Apache ActiveMQ Vulnerable to Code Injection

org.apache.activemq:apache-activemq: before 5.19.6

4 months ago
HIGHMaven

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers

org.springframework.security:spring-security-config: 7.0.0 → 7.0.5

4 months ago
HIGHMaven

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules

org.springframework.security:spring-security-config: 7.0.0 → 7.0.5

4 months ago
HIGHMaven

Spring Security has Potential Security Misconfiguration when Using withIssuerLocation

Spring Security has Potential Security Misconfiguration when Using withIssuerLocation

org.springframework.security:spring-security-oauth2-jose: ≥ 6.3.0

4 months ago
CRITICALMaven

camel-infinispan Vulnerable to Deserialization of Untrusted Data

camel-infinispan Vulnerable to Deserialization of Untrusted Data

org.apache.camel:camel-infinispan: before 4.20.0

4 months ago
MEDIUMMaven

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

org.springframework.security:spring-security-core: ≥ 5.7.0

4 months ago
HIGHMaven

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

org.springframework.security:spring-security-web: 7.0.0 → 7.0.5

4 months ago
MEDIUMMaven

Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification

Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification

org.apache.httpcomponents.client5:httpclient5: 5.6-alpha1 → 5.6.1

4 months ago
CRITICALMaven

Spinnaker: RCE via expression parsing due to unrestricted context handling

Spinnaker: RCE via expression parsing due to unrestricted context handling

io.spinnaker.echo:echo-pipelinetriggers: 2026.0-0 → 2026.0.1

4 months ago
MEDIUMMaven

Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured

Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured

org.springframework.security:spring-security-core: 6.5.0 → 6.5.10

4 months ago
CRITICALMaven

Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths

Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths

io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo: before 2026.0.1

4 months ago
HIGHMaven

Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation

Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation

org.apache.kafka:kafka-clients: 4.1.0 → 4.1.2

4 months ago
MEDIUMMaven

Apache Kafka exposes sensitive information in its DEBUG logs

Apache Kafka exposes sensitive information in its DEBUG logs

org.apache.kafka:kafka-clients: 0.11.0 → 3.9.2

4 months ago
HIGHMaven

Bouncy Castle Has Covert Timing Channel Vulnerability

Bouncy Castle Has Covert Timing Channel Vulnerability

org.bouncycastle:bcprov-jdk15to18: 1.71 → 1.80.2

5 months ago
HIGHMaven

Bouncy Castle Uncontrolled Resource Consumption vulnerability

Bouncy Castle Uncontrolled Resource Consumption vulnerability

org.bouncycastle:bcpg-jdk12: all versions

5 months ago
MODERATEMaven

Bouncy Castle has an LDAP injection

Bouncy Castle has an LDAP injection

org.bouncycastle:bcprov-jdk14: 1.74 → 1.84

5 months ago
CRITICALMaven

Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks

Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks

org.bouncycastle:bcprov-jdk14: ≥ 1.59

5 months ago
HIGHMaven

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

org.pac4j:pac4j-core: before 5.7.10

5 months ago
HIGHMaven

Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService

Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService

com.ritense.valtimo:inbox: 13.0.0.RELEASE → 13.22.0.RELEASE

5 months ago
MODERATEMaven

Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules

Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules

org.bouncycastle:bcpkix-jdk18on: 1.49 → 1.84

5 months ago
MODERATEMaven

Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache

Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache

dev.dsf:dsf-bpe-process-api-v2: all versions

5 months ago
HIGHMaven

AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects

AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects

org.asynchttpclient:async-http-client: 3.0.0.Beta1 → 3.0.9

5 months ago
HIGHMaven

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

org.eclipse.jetty:jetty-http: 12.1.0 → 12.1.7

5 months ago
MODERATEMaven

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

org.apache.logging.log4j:log4j-core: 2.12.0 → 2.25.4

5 months ago
MODERATEMaven

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

org.apache.logging.log4j:log4j-core: 2.0-alpha1 → 2.25.4

5 months ago
MODERATEMaven

Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

org.apache.logging.log4j:log4j-1.2-api: 2.7 → 2.25.4

5 months ago
MODERATEMaven

Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout

Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout

org.apache.logging.log4j:log4j-layout-template-json: 2.14.0 → 2.25.4

5 months ago
MODERATEMaven

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

org.apache.logging.log4j:log4j-core: 2.21.0 → 2.25.4

5 months ago
HIGHMaven

Apache ActiveMQ: Denial of Service via Out of Memory vulnerability

Apache ActiveMQ: Denial of Service via Out of Memory vulnerability

org.apache.activemq:activemq-client: before 5.19.4

5 months ago
HIGHMaven

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

org.apache.tomcat:tomcat-coyote-ffm: 9.0.83 → 9.0.116

5 months ago
HIGHMaven

Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve

Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve

org.apache.tomcat:tomcat-catalina: 9.0.40 → 9.0.116

5 months ago
HIGHMaven

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

org.apache.tomcat:tomcat-tribes: 11.0.20 → 11.0.21

5 months ago
HIGHMaven

Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor

Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor

org.apache.tomcat:tomcat-tribes: 9.0.13 → 9.0.116

5 months ago
MEDIUMMaven

Apache Tomcat has an Improper Input Validation vulnerability

Apache Tomcat has an Improper Input Validation vulnerability

org.apache.tomcat:tomcat-coyote: 9.0.113 → 9.0.116

5 months ago
HIGHMaven

Apache Tomcat: Configured cipher preference order not preserved

Apache Tomcat: Configured cipher preference order not preserved

org.apache.tomcat:tomcat-coyote: 9.0.114 → 9.0.116

5 months ago
HIGHMaven

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

org.apache.tomcat:tomcat-tribes: 9.0.13 → 9.0.117

5 months ago
MEDIUMMaven

Apache Tomcat has an Open Redirect vulnerability

Apache Tomcat has an Open Redirect vulnerability

org.apache.tomcat:tomcat-catalina: 8.5.30 → 9.0.116

5 months ago
HIGHMaven

Apache Tomcat has an HTTP Request/Response Smuggling vulnerability

Apache Tomcat has an HTTP Request/Response Smuggling vulnerability

org.apache.tomcat:tomcat-coyote: 7.0.0 → 9.0.116

5 months ago
HIGHMaven

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

org.apache.tomcat:tomcat-coyote-ffm: 9.0.92 → 9.0.117

5 months ago
MODERATEMaven

quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class

quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class

io.quarkiverse.openapi.generator:quarkus-openapi-generator: before 2.16.0

5 months ago
CRITICALMaven

Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans

Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans

org.apache.activemq:activemq-broker: before 5.19.5

5 months ago
MEDIUMMaven

Apache ActiveMQ: Improper validation and restriction of a classpath path name

Apache ActiveMQ: Improper validation and restriction of a classpath path name

org.apache.activemq:activemq-client: before 5.19.3

5 months ago
HIGHMaven

Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

org.apache.kafka:kafka-clients: 2.8.0 → 3.9.2

5 months ago
HIGHMaven

Java-SDK has a DNS Rebinding Vulnerability

Java-SDK has a DNS Rebinding Vulnerability

io.modelcontextprotocol.sdk:mcp-core: before 1.0.0

5 months ago
HIGHMaven

Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers

Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers

tools.jackson.core:jackson-core: 3.0.0 → 3.1.1

5 months ago
HIGHMaven

Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants

Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants

org.keycloak:keycloak-services: before 26.5.7

5 months ago
HIGHMaven

Keycloak: Replay of action tokens via improper handling of single-use entries

Keycloak: Replay of action tokens via improper handling of single-use entries

org.keycloak:keycloak-services: before 26.5.7

5 months ago
HIGHMaven

Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw

Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw

org.keycloak:keycloak-services: before 26.5.7

5 months ago
HIGHMaven

Keycloak: Application-Level DoS via Scope Processing

Keycloak: Application-Level DoS via Scope Processing

org.keycloak:keycloak-services: before 26.5.7

5 months ago
HIGHMaven

Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

org.keycloak:keycloak-services: before 26.5.7

5 months ago
MEDIUMMaven

MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

io.modelcontextprotocol.sdk:mcp-core: 1.0.0 → 1.0.1

5 months ago
HIGHMaven

Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON

Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON

io.trino:trino-iceberg: 439 → 480

5 months ago
HIGHMaven

Undertow is Vulnerable to HTTP Request/Response Smuggling

Undertow is Vulnerable to HTTP Request/Response Smuggling

io.undertow:undertow-parent: all versions

5 months ago
HIGHMaven

Undertow is Vulnerable to HTTP Request/Response Smuggling

Undertow is Vulnerable to HTTP Request/Response Smuggling

io.undertow:undertow-parent: all versions

5 months ago
HIGHMaven

AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities

AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities

software.amazon.awssdk:cloudfront: 2.18.33 → 2.41.30

5 months ago
HIGHMaven

Undertow is Vulnerable to HTTP Request/Response Smuggling

Undertow is Vulnerable to HTTP Request/Response Smuggling

io.undertow:undertow-parent: all versions

5 months ago
MEDIUMMaven

Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation

Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation

org.keycloak:keycloak-services: 26.5.0 → 26.6.3

5 months ago
HIGHMaven

Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

io.netty:netty-codec-http: before 4.1.132.Final

5 months ago
HIGHMaven

Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

io.netty:netty-codec-http2: before 4.1.132.Final

5 months ago
HIGHMaven

pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names

pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names

org.pf4j:pf4j: before 3.14.1

5 months ago
CRITICALMaven

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.26.1

5 months agoEPSS 1%
HIGHMaven

Plexus-Utils has a Directory Traversal vulnerability in its extractFile method

Plexus-Utils has a Directory Traversal vulnerability in its extractFile method

org.codehaus.plexus:plexus-utils: 4.0.0 → 4.0.3

5 months ago
HIGHMaven

Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests

Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests

io.undertow:undertow-core: all versions

5 months ago
MEDIUMMaven

Keycloak's identity-first login flow exposes user information

Keycloak's identity-first login flow exposes user information

org.keycloak:keycloak-services: 26.5.0 → 26.6.1

5 months ago
MEDIUMMaven

Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false

Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false

org.keycloak:keycloak-services: all versions

5 months ago
HIGHMaven

Spring Framework Improper Path Limitation with Script View Templates

Spring Framework Improper Path Limitation with Script View Templates

org.springframework:spring-webmvc: 7.0.0-M1 → 7.0.6

5 months ago
HIGHMaven

Spring Security HTTP Headers Are not Written Under Some Conditions

Spring Security HTTP Headers Are not Written Under Some Conditions

org.springframework.security:spring-security-web: all versions

5 months ago
MEDIUMMaven

Spring MVC and WebFlux has Server Sent Event stream corruption

Spring MVC and WebFlux has Server Sent Event stream corruption

org.springframework:spring-webmvc: 7.0.0-M1 → 7.0.6

5 months ago
HIGHMaven

Spring Boot has an Authentication Bypass under Actuator Health groups paths

Spring Boot has an Authentication Bypass under Actuator Health groups paths

org.springframework.boot:spring-boot-starter-actuator: ≥ 3.4.0

5 months ago
HIGHMaven

Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints

Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints

org.springframework.boot:spring-boot-starter-actuator: 4.0.0-M1 → 4.0.4

5 months ago
HIGHMaven

Keycloak: Unauthorized authentication via disabled SAML Identity Provider

Keycloak: Unauthorized authentication via disabled SAML Identity Provider

org.keycloak:keycloak-services: before 26.5.5

6 months ago
CRITICALMaven

Jenkins has a link following vulnerability allows arbitrary file creation

Jenkins has a link following vulnerability allows arbitrary file creation

org.jenkins-ci.main:jenkins-core: before 2.555

6 months ago
MEDIUMMaven

Keycloak: Denial of Service due to excessive SAMLRequest decompression

Keycloak: Denial of Service due to excessive SAMLRequest decompression

org.keycloak:keycloak-saml-adapter-core: before 26.5.4

6 months ago
HIGHMaven

Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices

Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices

io.micronaut:micronaut-json-core: 4.0.0-M1 → 4.10.16

6 months ago
HIGHMaven

Micronaut Framework vulnerable to a Denial of Service in HTML error response caching

Micronaut Framework vulnerable to a Denial of Service in HTML error response caching

io.micronaut:micronaut-http-server: 4.7.0 → 4.10.17

6 months ago
HIGHMaven

Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames

Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames

io.spinnaker.clouddriver:clouddriver-artifacts: 2025.1.6 → 2025.2.4

6 months ago
CRITICALMaven

Apache Spark: Spark History Server Code Execution Vulnerability

Apache Spark: Spark History Server Code Execution Vulnerability

org.apache.spark:spark-core_2.13: 4.0.0 → 4.0.1

6 months ago
MEDIUMMaven

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

org.keycloak:keycloak-services: all versions

6 months ago
MEDIUMMaven

Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API

Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API

org.keycloak:keycloak-services: all versions

6 months ago
MODERATEMaven

Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash

Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash

com.vaadin:flow-server: before 14.14.1

6 months ago
MEDIUMMaven

Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function

Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function

org.apache.pdfbox:pdfbox-examples: 2.0.24 → 3.0.7

6 months ago
HIGHMaven

Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager

Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager

org.apache.zookeeper:zookeeper: 3.8.0 → 3.8.6

6 months ago
HIGHMaven

Apache ZooKeeper has improper handling of configuration values

Apache ZooKeeper has improper handling of configuration values

org.apache.zookeeper:zookeeper: 3.9.0 → 3.9.5

6 months ago
CRITICALMaven

Keycloak SAML Broken has Authentication Bypass by Primary Weakness

Keycloak SAML Broken has Authentication Bypass by Primary Weakness

org.keycloak:keycloak-broker-saml: all versions

6 months ago
HIGHMaven

Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator

Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator

org.keycloak:keycloak-services: before 26.5.5

6 months ago
MEDIUMMaven

org.eclipse.jetty:jetty-http has different parsing of invalid URIs

org.eclipse.jetty:jetty-http has different parsing of invalid URIs

org.eclipse.jetty:jetty-http: ≥ 9.4.0

6 months ago
HIGHMaven

The Eclipse Jetty Server Artifact has a Gzip request memory leak

The Eclipse Jetty Server Artifact has a Gzip request memory leak

org.eclipse.jetty:jetty-server: 12.1.0 → 12.1.6

6 months ago
CRITICALMaven

Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions

Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions

org.apache.activemq:artemis-server: ≥ 2.11.0

6 months ago
CRITICALMaven

XWiki Blog Application home page vulnerable to Stored XSS via Post Title

XWiki Blog Application home page vulnerable to Stored XSS via Post Title

org.xwiki.contrib.blog:application-blog-ui: 9.15 → 9.15.7

6 months ago
HIGHMaven

jackson-core has Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion

jackson-core has Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion

tools.jackson.core:jackson-core: 3.0.0 → 3.1.0

6 months ago
MEDIUMMaven

Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound

Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound

org.apache.activemq:apache-activemq: before 5.19.2

6 months ago
CRITICALMaven

Apache Ranger has a Code Injection vulnerability

Apache Ranger has a Code Injection vulnerability

org.apache.ranger:ranger-plugins-common: before 2.8.0

6 months ago
MODERATEMaven

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

tools.jackson.core:jackson-core: 3.0.0 → 3.1.0

6 months ago
MEDIUMMaven

PSI Probe vulnerable to Server-Side Request Forgery

PSI Probe vulnerable to Server-Side Request Forgery

com.github.psi-probe:psi-probe-core: all versions

6 months ago
MEDIUMMaven

Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass

Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass

org.keycloak:keycloak-services: before 26.4.4

6 months ago
MEDIUMMaven

PSI Probe: Broken access control can lead to DoS

PSI Probe: Broken access control can lead to DoS

com.github.psi-probe:psi-probe-core: all versions

6 months ago
HIGHMaven

Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes

Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes

org.keycloak:keycloak-server-spi-private: before 26.5.2

6 months ago
HIGHMaven

mchange-commons-java: Remote Code Execution via JNDI Reference Resolution

mchange-commons-java: Remote Code Execution via JNDI Reference Resolution

com.mchange:mchange-commons-java: before 0.4.0

6 months ago
HIGHMaven

c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property

c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property

com.mchange:c3p0: before 0.12.0

6 months ago
MEDIUMMaven

Keycloak: Missing Check on Disabled Client for Docker Registry Protocol

Keycloak: Missing Check on Disabled Client for Docker Registry Protocol

org.keycloak:keycloak-services: all versions

6 months ago
CRITICALMaven

carbon-apimgt does not properly restrict uploaded files

carbon-apimgt does not properly restrict uploaded files

org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1: before 9.32.167

6 months ago
MEDIUMMaven

Jenkins has a build information disclosure vulnerability through Run Parameter

Jenkins has a build information disclosure vulnerability through Run Parameter

org.jenkins-ci.main:jenkins-core: 2.542 → 2.551

6 months ago
CRITICALMaven

Jenkins has a stored XSS vulnerability in node offline cause description

Jenkins has a stored XSS vulnerability in node offline cause description

org.jenkins-ci.main:jenkins-core: 2.542 → 2.551

6 months ago
HIGHMaven

Apache Tomcat - Client certificate verification bypass

Apache Tomcat - Client certificate verification bypass

org.apache.tomcat.embed:tomcat-embed-core: 11.0.0-M1 → 11.0.15

7 months ago
LOWMaven

Apache Tomcat - Security constraint bypass with HTTP/0.9

Apache Tomcat - Security constraint bypass with HTTP/0.9

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.15

7 months ago
HIGHMaven

Apache Tomcat has an Improper Input Validation vulnerability

Apache Tomcat has an Improper Input Validation vulnerability

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.18

7 months ago
MODERATEMaven

Apache Avro Java SDK is Vulnerable to Code Injection

Apache Avro Java SDK is Vulnerable to Code Injection

org.apache.avro:avro-compiler: 1.12.0 → 1.12.1

7 months ago
LOWMaven

Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability

Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability

org.apache.shiro:shiro-core: before 2.1.0

7 months ago
HIGHMaven

Keycloak logs sensitive headers

Keycloak logs sensitive headers

org.keycloak:keycloak-quarkus-server: before 26.5.6

7 months ago
MEDIUMMaven

Apache Shiro has an Authentication Bypass

Apache Shiro has an Authentication Bypass

org.apache.shiro:shiro-spring: before 2.1.0

7 months ago
LOWMaven

Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log

Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log

org.neo4j:neo4j: before 2026.01

7 months ago
MODERATEMaven

Neo4j Enterprise and Community vulnerable to a potential information disclosure

Neo4j Enterprise and Community vulnerable to a potential information disclosure

org.neo4j:neo4j: before 5.26.21

7 months ago
CRITICALMaven

JinJava Bypass through ForTag leads to Arbitrary Java Execution

JinJava Bypass through ForTag leads to Arbitrary Java Execution

com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.3

7 months ago
MEDIUMMaven

Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion

Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion

org.hibernate.reactive:hibernate-reactive-core: before 4.2.1

7 months ago
MEDIUMMaven

Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods

Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods

org.keycloak:keycloak-services: all versions

7 months ago
HIGHMaven

Hibernate vulnerable to SQL Injection

Hibernate vulnerable to SQL Injection

org.hibernate:hibernate-core: ≥ 5.2.8

7 months ago
LOWMaven

Logback allows an attacker to instantiate classes already present on the class path

Logback allows an attacker to instantiate classes already present on the class path

ch.qos.logback:logback-core: before 1.5.25

7 months ago
HIGHMaven

Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin

Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin

org.apache.solr:solr-core: 5.3.0 → 9.10.1

7 months ago
HIGHMaven

Apache Solr: Insufficient file-access checking in standalone core-creation requests

Apache Solr: Insufficient file-access checking in standalone core-creation requests

org.apache.solr:solr-core: 8.6.0 → 9.10.1

7 months ago
HIGHMaven

Keycloak services allows the issuance of access and refresh tokens for disabled users

Keycloak services allows the issuance of access and refresh tokens for disabled users

org.keycloak:keycloak-services: 26.5.0 → 26.5.2

7 months ago
MEDIUMMaven

risesoft-y9 Digital-Infrastructure has a SQL injection vulnerability

risesoft-y9 Digital-Infrastructure has a SQL injection vulnerability

net.risesoft:risenet-y9boot-support-platform-service: all versions

8 months ago
MODERATEMaven

Vert.x Web static handler component cache can be manipulated to deny the access to static files

Vert.x Web static handler component cache can be manipulated to deny the access to static files

io.vertx:vertx-core: before 4.5.24

8 months ago
HIGHMaven

Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests

Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests

io.undertow:undertow-core: 2.3.0.Alpha1 → 2.3.21.Final

8 months ago
HIGHMaven

Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write

Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write

io.quarkus:quarkus-rest: before 3.20.5

8 months ago
HIGHMaven

Spinnaker vulnerable to SSRF due to improper restrictions on http from user input

Spinnaker vulnerable to SSRF due to improper restrictions on http from user input

io.spinnaker.clouddriver:clouddriver-artifacts: before 2025.1.6

8 months ago
HIGHMaven

MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation

MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation

org.msgpack:msgpack-core: before 0.9.11

8 months ago
MODERATEMaven

Vaadin vulnerable to Cross-site Scripting

Vaadin vulnerable to Cross-site Scripting

com.vaadin:vaadin-server: 7.0.0 → 7.7.50

8 months ago
HIGHMaven

Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation

Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation

org.elasticsearch.plugin:x-pack-core: before 8.19.8

9 months ago
HIGHMaven

Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data

Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data

org.elasticsearch.plugin:x-pack-security: before 8.19.9

9 months ago
MODERATEMaven

Apache Log4j does not verify the TLS hostname in its Socket Appender

Apache Log4j does not verify the TLS hostname in its Socket Appender

org.apache.logging.log4j:log4j-core: 2.0-beta9 → 2.25.3

9 months ago
HIGHMaven

Amazon S3 Encryption Client for Java has a Key Commitment Issue

Amazon S3 Encryption Client for Java has a Key Commitment Issue

software.amazon.encryption.s3:amazon-s3-encryption-client-java: before 4.0.0

9 months ago
HIGHMaven

jose4j is vulnerable to DoS via compressed JWE content

jose4j is vulnerable to DoS via compressed JWE content

org.bitbucket.b_c:jose4j: before 0.9.6

9 months ago
MEDIUMMaven

Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder

Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder

io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.8.Final

9 months ago
HIGHMaven

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

org.elasticsearch:elasticsearch: 7.0.0-alpha1 → 8.19.8

9 months ago
HIGHMaven

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

io.airlift:aircompressor-v3: before 3.4

9 months ago
MEDIUMMaven

Jenkins is missing a permission check on password fields

Jenkins is missing a permission check on password fields

org.jenkins-ci.main:jenkins-core: 2.529 → 2.541

9 months ago
HIGHMaven

Jenkins has a Denial of service vulnerability in HTTP-based CLI

Jenkins has a Denial of service vulnerability in HTTP-based CLI

org.jenkins-ci.main:jenkins-core: 2.529 → 2.541

9 months ago
MEDIUMMaven

Jenkins's build authorization token is stored and displayed in plain text

Jenkins's build authorization token is stored and displayed in plain text

org.jenkins-ci.main:jenkins-core: 2.529 → 2.541

9 months ago
MEDIUMMaven

Jenkins's build authorization token is stored and displayed in plain text

Jenkins's build authorization token is stored and displayed in plain text

org.jenkins-ci.main:jenkins-core: 2.529 → 2.541

9 months ago
MEDIUMMaven

Jenkins has a CSRF vulnerability on the login form

Jenkins has a CSRF vulnerability on the login form

org.jenkins-ci.main:jenkins-core: 2.529 → 2.541

9 months ago
HIGHMaven

yawkat LZ4 Java has a possible information leak in Java safe decompressor

yawkat LZ4 Java has a possible information leak in Java safe decompressor

at.yawk.lz4:lz4-java: before 1.10.1

9 months ago
HIGHMaven

Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded

Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded

io.undertow:undertow-core: before 2.2.39.Final

9 months ago
MEDIUMMaven

Keycloak unable to restrict access to the admin console

Keycloak unable to restrict access to the admin console

org.keycloak:keycloak-quarkus-server: before 26.4.4

9 months ago
HIGHMaven

LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS

LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS

at.yawk.lz4:lz4-java: before 1.8.1

9 months ago
HIGHMaven

OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer: 20240325.1 → 20260101.1

9 months ago
HIGHMaven

OpenSearch is vulnerable to DoS via complex query_string inputs

OpenSearch is vulnerable to DoS via complex query_string inputs

org.opensearch:opensearch-common: 3.0.0 → 3.3.0

9 months ago
CRITICALMaven

Eclipse Jersey has a Race Condition

Eclipse Jersey has a Race Condition

org.glassfish.jersey.core:jersey-client: 2.45 → 2.46

10 months ago
HIGHMaven

CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection

CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection

org.cyclonedx:cyclonedx-core-java: 2.1.0 → 11.0.1

10 months ago
HIGHMaven

WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks

WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks

org.wso2.carbon.mediation:org.wso2.carbon.localentry: all versions

10 months ago
HIGHMaven

Keycloak vulnerable to session takeovers due to reuse of session identifiers

Keycloak vulnerable to session takeovers due to reuse of session identifiers

org.keycloak:keycloak-services: before 26.0.0

10 months ago
CRITICALMaven

Apache Tomcat Vulnerable to Relative Path Traversal

Apache Tomcat Vulnerable to Relative Path Traversal

org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.11

10 months ago
HIGHMaven

Apache Tomcat Vulnerable to Improper Resource Shutdown or Release

Apache Tomcat Vulnerable to Improper Resource Shutdown or Release

org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.12

10 months ago
CRITICALMaven

Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences

Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences

org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.11

10 months ago
MODERATEMaven

Bouncy Castle Vulnerable to Uncontrolled Resource Consumption

Bouncy Castle Vulnerable to Uncontrolled Resource Consumption

org.bouncycastle:bc-fips: 2.1.0 → 2.1.2

10 months ago
MEDIUMMaven

Keycloak does not invalidate sessions when "Remember Me" is disabled

Keycloak does not invalidate sessions when "Remember Me" is disabled

org.keycloak:keycloak-services: 26.3.0 → 26.4.1

10 months ago
MEDIUMMaven

Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names

Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names

io.vertx:vertx-web: before 4.5.22

10 months ago
MODERATEMaven

Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories

Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories

io.vertx:vertx-web: before 4.5.22

10 months ago
MEDIUMMaven

Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages

Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages

org.springframework:spring-websocket: 6.2.0 → 6.2.12

11 months ago
HIGHMaven

Netty has SMTP Command Injection Vulnerability that Allows Email Forgery

Netty has SMTP Command Injection Vulnerability that Allows Email Forgery

io.netty:netty-codec-smtp: 4.2.0.Alpha1 → 4.2.7.Final

11 months ago
HIGHMaven

JDBC Driver for SQL Server has improper input validation issue

JDBC Driver for SQL Server has improper input validation issue

com.microsoft.sqlserver:mssql-jdbc: 8.3.0.jre11-preview → 10.2.4.jre11

11 months ago
HIGHMaven

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

org.elasticsearch:elasticsearch: 7.0.0 → 8.18.8

11 months ago
HIGHMaven

Keycloak Potential Variable Reference in Model Storage Services

Keycloak Potential Variable Reference in Model Storage Services

org.keycloak:keycloak-model-storage-services: all versions

11 months ago
MODERATEMaven

QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing

QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing

ch.qos.logback:logback-core: 1.4.0 → 1.5.19

11 months ago
MEDIUMMaven

WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled

WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled

org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt: all versions

11 months ago
MODERATEMaven

Apache IoTDB: DoS Vulnerability

Apache IoTDB: DoS Vulnerability

org.apache.iotdb:iotdb-core: 1.3.3 → 2.0.5

11 months ago
MEDIUMMaven

Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands

Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands

org.apache.zookeeper:zookeeper: 3.9.0 → 3.9.4

11 months ago
MEDIUMMaven

WSO2 Identity Server Apps allows content spoofing in logs

WSO2 Identity Server Apps allows content spoofing in logs

org.wso2.identity.apps:authentication-portal: before 2.4.4

11 months ago
CRITICALMaven

jinjava has Sandbox Bypass via JavaType-Based Deserialization

jinjava has Sandbox Bypass via JavaType-Based Deserialization

com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.1

0 years agoEPSS 2%
MEDIUMMaven

Jenkins has a missing permission check, allowing users to obtain agent names

Jenkins has a missing permission check, allowing users to obtain agent names

org.jenkins-ci.main:jenkins-core: before 2.516.3

0 years ago
MEDIUMMaven

Jenkins is missing a permission check in the authenticated users' profile menu

Jenkins is missing a permission check in the authenticated users' profile menu

org.jenkins-ci.main:jenkins-core: before 2.516.3

0 years ago
MEDIUMMaven

Jenkins has a log message injection vulnerability

Jenkins has a log message injection vulnerability

org.jenkins-ci.main:jenkins-core: before 2.516.3

0 years ago
HIGHMaven

Spring Security annotation detection mechanism has authorization bypass

Spring Security annotation detection mechanism has authorization bypass

org.springframework.security:spring-security-core: 6.4.0 → 6.4.10

0 years ago
HIGHMaven

Spring Framework annotation detection mechanism may result in improper authorization

Spring Framework annotation detection mechanism may result in improper authorization

org.springframework:spring-core: ≥ 5.3.0

0 years ago
LOWMaven

Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions

Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions

io.netty:netty-codec-http: before 4.1.125.Final

1 year ago
MODERATEMaven

Vaadin Platform possible file bypass via upload validation on the server-side

Vaadin Platform possible file bypass via upload validation on the server-side

com.vaadin:vaadin: 14.0.0 → 14.13.1

1 year ago
MODERATEMaven

Vaadin Framework possible file bypass via upload validation on the server-side

Vaadin Framework possible file bypass via upload validation on the server-side

com.vaadin:vaadin-server: 7.0.0 → 7.7.48

1 year ago
MODERATEMaven

Netty's decoders vulnerable to DoS via zip bomb style attack

Netty's decoders vulnerable to DoS via zip bomb style attack

io.netty:netty-codec-compression: 4.2.0.Alpha1 → 4.2.5.Final

1 year ago
HIGHMaven

Undertow MadeYouReset HTTP/2 DDoS Vulnerability

Undertow MadeYouReset HTTP/2 DDoS Vulnerability

io.undertow:undertow-core: before 2.2.38.Final

1 year ago
CRITICALMaven

Valtimo scripting engine can be used to gain access to sensitive data or resources

Valtimo scripting engine can be used to gain access to sensitive data or resources

com.ritense.valtimo:core: before 12.16.0.RELEASE

1 year ago
CRITICALMaven

Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF

Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF

org.apache.tika:tika-parser-pdf-module: 1.13 → 3.2.2

1 year ago
HIGHMaven

Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability

Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability

org.eclipse.jetty.http2:http2-common: 9.3.0 → 9.4.58

1 year ago
HIGHMaven

Spring Framework MVC Applications Path Traversal Vulnerability

Spring Framework MVC Applications Path Traversal Vulnerability

org.springframework:spring-webmvc: 6.2.0 → 6.2.10

1 year ago
LOWMaven

Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability

Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability

org.bouncycastle:bc-fips: 2.1.0 → 2.1.1

1 year ago
MODERATEMaven

Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation

Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation

org.bouncycastle:bcpkix-jdk15on: 1.44 → 1.79

1 year ago
HIGHMaven

Netty affected by MadeYouReset HTTP/2 DDoS vulnerability

Netty affected by MadeYouReset HTTP/2 DDoS vulnerability

io.netty:netty-codec-http2: 4.2.0.Alpha1 → 4.2.4.Final

1 year ago
MODERATEMaven

Bouncy Castle for Java on All (API modules) allows Excessive Allocation

Bouncy Castle for Java on All (API modules) allows Excessive Allocation

org.bouncycastle:bcprov-jdk14: 1.0 → 1.78

1 year ago
MODERATEMaven

Apache CXF: Untrusted JMS configuration can lead to RCE

Apache CXF: Untrusted JMS configuration can lead to RCE

org.apache.cxf:cxf-rt-transports-jms: before 3.6.8

1 year ago
MODERATEMaven

XWiki allows Reflected XSS in two templates

XWiki allows Reflected XSS in two templates

org.xwiki.platform:xwiki-platform-web-templates: 4.2-milestone-3 → 16.4.8

1 year ago
HIGHMaven

Jakarta Mail vulnerable to SMTP Injection

Jakarta Mail vulnerable to SMTP Injection

org.eclipse.angus:smtp: before 2.0.4

1 year ago
MEDIUMMaven

Reactor Netty HTTP is vulnerable to credential leaks during chained redirects

Reactor Netty HTTP is vulnerable to credential leaks during chained redirects

io.projectreactor.netty:reactor-netty-http: 1.3.0-M1 → 1.3.0-M5

1 year ago
MEDIUMMaven

Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged

Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged

org.apache.cxf:cxf-core: before 3.5.11

1 year ago
CRITICALMaven

XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax

XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax

org.xwiki.rendering:xwiki-rendering-syntax-xhtml: 5.4.5 → 14.10

1 year ago
CRITICALMaven

XWiki Rendering is vulnerable to RCE attacks when processing nested macros

XWiki Rendering is vulnerable to RCE attacks when processing nested macros

org.xwiki.rendering:xwiki-rendering-transformation-macro: 4.2-milestone-1 → 13.10.11

1 year ago
MEDIUMMaven

Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

com.nimbusds:nimbus-jose-jwt: 9.38-rc1 → 10.0.2

1 year ago
MEDIUMMaven

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

org.apache.commons:commons-lang3: 3.0 → 3.18.0

1 year ago
HIGHMaven

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.9

1 year ago
CRITICALMaven

Conductor vulnerable to OS command injection through unrestricted access to Java classes

Conductor vulnerable to OS command injection through unrestricted access to Java classes

org.conductoross:conductor-core: before 3.21.13

1 year ago
HIGHMaven

jackson-core can throw a StackoverflowError when processing deeply nested data

jackson-core can throw a StackoverflowError when processing deeply nested data

com.fasterxml.jackson.core:jackson-core: before 2.15.0

1 year ago
HIGHMaven

Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information

Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information

org.infinispan:infinispan-cli-client: all versions

1 year ago
HIGHMaven

Quarkus potentially leaks data when duplicating a duplicated context

Quarkus potentially leaks data when duplicating a duplicated context

io.quarkus:quarkus-vertx: before 3.15.6

1 year ago
HIGHMaven

sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+

sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+

io.sentry:sentry-android: before 8.14.0

1 year ago
MODERATEMaven

Apache Tomcat - Security constraint bypass for pre/post-resources

Apache Tomcat - Security constraint bypass for pre/post-resources

org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.8

1 year ago
HIGHMaven

Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers

Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers

commons-fileupload:commons-fileupload: 1.0 → 1.6.0

1 year ago
HIGHMaven

Apache Tomcat - DoS in multipart upload

Apache Tomcat - DoS in multipart upload

org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.8

1 year ago
HIGHMaven

Spring Framework vulnerable to a reflected file download (RFD)

Spring Framework vulnerable to a reflected file download (RFD)

org.springframework:spring-web: 6.2.0 → 6.2.8

1 year ago
MEDIUMMaven

Solon Vulnerable to Directory Traversal

Solon Vulnerable to Directory Traversal

org.noear:solon-faas-luffy: 3.1.2 → 3.2.0

1 year ago
HIGHMaven

pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration

pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration

org.postgresql:postgresql: 42.7.4 → 42.7.7

1 year ago
HIGHMaven

Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability

Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability

org.apache.kafka:kafka-clients: 3.1.0 → 3.9.1

1 year ago
MEDIUMMaven

Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation

Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation

com.fasterxml.jackson.core:jackson-core: 2.0.0 → 2.13.0

1 year ago
HIGHMaven

Para Inserts Sensitive Information into Log File for Facebook authentication

Para Inserts Sensitive Information into Log File for Facebook authentication

com.erudika:para-server: before 1.50.8

1 year ago
MEDIUMMaven

WSO2 products vulnerable to Cross-site Scripting

WSO2 products vulnerable to Cross-site Scripting

org.wso2.carbon.identity.framework:org.wso2.carbon.identity.user.store.configuration.ui: before 7.5.12

1 year ago
MEDIUMMaven

WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint

WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint

org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util: 6.0.0 → 7.0.111

1 year ago
HIGHMaven

Para Server Logs Sensitive Information

Para Server Logs Sensitive Information

com.erudika:para-server: before 1.50.8

1 year ago
HIGHMaven

Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies

Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies

org.springframework.cloud:spring-cloud-gateway-server: 4.2.0 → 4.2.3

1 year ago
LOWMaven

Apache Tomcat - CGI security constraint bypass

Apache Tomcat - CGI security constraint bypass

org.apache.tomcat:tomcat-catalina: 9.0.0.M1 → 9.0.105

1 year ago
HIGHMaven

Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users

Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users

com.ritense.valtimo:objecten-api: ≥ 11.0.0.RELEASE

1 year ago
CRITICALMaven

Apache Commons Improper Access Control vulnerability

Apache Commons Improper Access Control vulnerability

commons-beanutils:commons-beanutils: 1.0 → 1.11.0

1 year ago
MODERATEMaven

Eclipse JGit XML External Entity (XXE) Vulnerability

Eclipse JGit XML External Entity (XXE) Vulnerability

org.eclipse.jgit:org.eclipse.jgit: 7.2.0.202503040940-r → 7.2.1.202505142326-r

1 year ago
MEDIUMMaven

Spring Framework DataBinder Case Sensitive Match Exception

Spring Framework DataBinder Case Sensitive Match Exception

org.springframework:spring-context: 6.2.0 → 6.2.7

1 year ago
LOWMaven

Apache Commons Configuration Uncontrolled Resource Consumption

Apache Commons Configuration Uncontrolled Resource Consumption

commons-configuration:commons-configuration: all versions

1 year ago
HIGHMaven

Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit

Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit

org.eclipse.jetty.http2:jetty-http2-common: 12.0.0 → 12.0.17

1 year ago
MEDIUMMaven

**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request

**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request

org.eclipse.jetty:jetty-server: 9.4.0 → 9.4.57.v20241219

1 year ago
HIGHMaven

Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser

Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser

org.graylog2:graylog2-server: before 6.2.0

1 year ago
MODERATEMaven

JRuby-OpenSSL has hostname verification disabled by default

JRuby-OpenSSL has hostname verification disabled by default

rubygems:jruby-openssl: 0.12.1 → 0.15.4

1 year ago
HIGHMaven

Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation

Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation

org.apache.activemq:activemq-openwire-legacy: before 5.16.8

1 year ago
HIGHMaven

Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata

Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata

org.apache.parquet:parquet-avro: before 1.15.2

1 year ago
MEDIUMMaven

HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store

HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store

org.jboss.hal:hal-console: before 3.7.11.Final

1 year ago
HIGHMaven

Keycloak hostname verification

Keycloak hostname verification

org.keycloak:keycloak-services: before 26.2.2

1 year ago
MEDIUMMaven

Keycloak vulnerable to two factor authentication bypass

Keycloak vulnerable to two factor authentication bypass

org.keycloak:keycloak-services: before 26.2.2

1 year ago
MEDIUMMaven

Solr script service doesn't take dropped programming right into account

Solr script service doesn't take dropped programming right into account

org.xwiki.platform:xwiki-platform-search-solr-api: 4.5.1 → 15.10.13

1 year ago
MEDIUMMaven

Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed

Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed

org.springframework.boot:spring-boot: all versions

1 year ago
LOWMaven

Apache Tomcat Rewrite rule bypass

Apache Tomcat Rewrite rule bypass

org.apache.tomcat:tomcat-catalina: 9.0.76 → 9.0.104

1 year ago
MODERATEMaven

Apache Tomcat Denial of Service via invalid HTTP priority header

Apache Tomcat Denial of Service via invalid HTTP priority header

org.apache.tomcat:tomcat-coyote: 9.0.76 → 9.0.104

1 year ago
HIGHMaven

Apache HttpClient disables domain checks

Apache HttpClient disables domain checks

org.apache.httpcomponents.client5:httpclient5: 5.4-alpha1 → 5.4.3

1 year ago
MEDIUMMaven

Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing

Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing

org.apache.poi:poi-ooxml: before 5.4.0

1 year ago
HIGHMaven

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

org.elasticsearch:elasticsearch: 7.17.0 → 8.15.1

1 year ago
MEDIUMMaven

Jenkins Missing Permission Check

Jenkins Missing Permission Check

org.jenkins-ci.main:jenkins-core: 2.500 → 2.504

1 year ago
MEDIUMMaven

Jenkins Missing Permission Check

Jenkins Missing Permission Check

org.jenkins-ci.main:jenkins-core: 2.500 → 2.504

1 year ago
CRITICALMaven

Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution

Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution

org.apache.parquet:parquet-avro: before 1.15.1

1 year ago
MEDIUMMaven

Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type

Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type

org.apache.activemq:artemis-server: 2.0.0 → 2.40.0

1 year ago
MEDIUMMaven

WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack

WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack

org.wildfly.security:wildfly-elytron: 1.17.0.Final → 2.2.9.Final

1 year ago
MEDIUMMaven

Spring Security Vulnerable to Authorization Bypass via Security Annotations

Spring Security Vulnerable to Authorization Bypass via Security Annotations

org.springframework.security:spring-security-core: 6.4.0 → 6.4.4

1 year ago
HIGHMaven

Spring Security Does Not Enforce Password Length

Spring Security Does Not Enforce Password Length

org.springframework.security:spring-security-crypto: 6.3.0 → 6.3.8

1 year ago
MODERATEMaven

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)

com.liferay.portal:release.dxp.bom: ≥ 2024.Q2.0

1 year ago
MEDIUMMaven

Wire has Uncontrolled Recursion on Nested Groups

Wire has Uncontrolled Recursion on Nested Groups

com.squareup.wire:wire-runtime: before 5.2.0

1 year ago
MEDIUMMaven

Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check

Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check

net.i2p.crypto:eddsa: all versions

1 year ago
MEDIUMMaven

Snowflake JDBC Driver client-side encryption key in DEBUG logs

Snowflake JDBC Driver client-side encryption key in DEBUG logs

net.snowflake:snowflake-jdbc: 3.0.13 → 3.23.1

1 year ago
HIGHMaven

SmallRye Fault Tolerance out-of-memory (OOM) issue

SmallRye Fault Tolerance out-of-memory (OOM) issue

io.smallrye:smallrye-fault-tolerance-core: 6.3.0 → 6.4.2

1 year ago
MEDIUMMaven

Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

org.keycloak:keycloak-ldap-federation: 26.1.0 → 26.1.3

1 year ago
CRITICALMaven

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.3

1 year ago
CRITICALMaven

com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations

com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations

com.xwiki.confluencepro:application-confluence-migrator-pro-ui: 1.0 → 1.2.0

1 year ago
MEDIUMMaven

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

org.jenkins-ci.main:jenkins-core: before 2.492.2

1 year ago
MEDIUMMaven

Jenkins Open Redirect vulnerability

Jenkins Open Redirect vulnerability

org.jenkins-ci.main:jenkins-core: before 2.492.2

1 year ago
MEDIUMMaven

Jenkins cross-site request forgery (CSRF) vulnerability

Jenkins cross-site request forgery (CSRF) vulnerability

org.jenkins-ci.main:jenkins-core: 2.493 → 2.500

1 year ago
MEDIUMMaven

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

org.jenkins-ci.main:jenkins-core: 2.493 → 2.500

1 year ago
HIGHMaven

Emissary May Use a Broken or Risky Cryptographic Algorithm

Emissary May Use a Broken or Risky Cryptographic Algorithm

gov.nsa.emissary:emissary: before 8.24.0

1 year ago
HIGHMaven

Pebble has Arbitrary Local File Inclusion (LFI) Vulnerability via `include` macro

Pebble has Arbitrary Local File Inclusion (LFI) Vulnerability via `include` macro

io.pebbletemplates:pebble: all versions

1 year ago
HIGHMaven

io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout

io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout

io.quarkus:quarkus-resteasy: 3.16.0.CR1 → 3.19.1

1 year ago
MEDIUMMaven

Keycloak allows cross-site scripting (XSS)

Keycloak allows cross-site scripting (XSS)

org.keycloak:keycloak-core: all versions

1 year ago
CRITICALMaven

Apache Ignite: Possible RCE when deserializing incoming messages by the server node

Apache Ignite: Possible RCE when deserializing incoming messages by the server node

org.apache.ignite:ignite-core: 2.6.0 → 2.17.0

1 year ago
HIGHMaven

Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance

Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance

io.quarkus:quarkus-rest: 3.16.0.CR1 → 3.18.2

1 year ago
HIGHMaven

Denial of Service attack on windows app using Netty

Denial of Service attack on windows app using Netty

io.netty:netty-common: before 4.1.118.Final

1 year ago
HIGHMaven

SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

io.netty:netty-handler: 4.1.91.Final → 4.1.118.Final

1 year ago
HIGHMaven

Netplex Json-smart Uncontrolled Recursion vulnerability

Netplex Json-smart Uncontrolled Recursion vulnerability

net.minidev:json-smart: 2.5.0 → 2.5.2

1 year ago
MEDIUMMaven

Snowflake JDBC uses insecure temporary credential cache file permissions

Snowflake JDBC uses insecure temporary credential cache file permissions

net.snowflake:snowflake-jdbc: 3.6.8 → 3.22.0

1 year ago
CRITICALMaven

Deep Java Library path traversal issue

Deep Java Library path traversal issue

ai.djl:api: before 0.31.1

1 year ago
CRITICALMaven

Snowflake JDBC allows an untrusted search path on Windows

Snowflake JDBC allows an untrusted search path on Windows

net.snowflake:snowflake-jdbc: 3.2.3 → 3.22.0

1 year ago
HIGHMaven

Infinispan vulnerable to Insertion of Sensitive Information into Log File

Infinispan vulnerable to Insertion of Sensitive Information into Log File

org.infinispan:infinispan-parent: all versions

1 year ago
MODERATEMaven

Apache Solr Relative Path Traversal vulnerability

Apache Solr Relative Path Traversal vulnerability

org.apache.solr:solr-core: 6.6 → 9.8.0

1 year ago
HIGHMaven

Apache Solr vulnerable to Execution with Unnecessary Privileges

Apache Solr vulnerable to Execution with Unnecessary Privileges

org.apache.solr:solr-core: before 9.8.0

1 year ago
HIGHMaven

Apache CXF: Denial of Service vulnerability with temporary files

Apache CXF: Denial of Service vulnerability with temporary files

org.apache.cxf:cxf-core: before 3.5.10

1 year ago
HIGHMaven

HAL Console has a Cross Site Scripting (XSS) vulnerability of user input

HAL Console has a Cross Site Scripting (XSS) vulnerability of user input

org.jboss.hal:hal-console: before 3.7.7.Final

1 year ago
HIGHMaven

Denial of Service in Keycloak Server via Security Headers

Denial of Service in Keycloak Server via Security Headers

org.keycloak:keycloak-quarkus-server: before 26.0.8

1 year ago
HIGHMaven

Keycloak allows unrestricted admin use of system and environment variables

Keycloak allows unrestricted admin use of system and environment variables

org.keycloak:keycloak-quarkus-server: before 26.0.8

1 year ago
CRITICALMaven

Apache MINA Deserialization RCE Vulnerability

Apache MINA Deserialization RCE Vulnerability

org.apache.mina:mina-core: 2.2.0 → 2.2.4

1 year ago
MODERATEMaven

Cross Site Scripting (XSS) vulnerability while uploading content to a new deployment

Cross Site Scripting (XSS) vulnerability while uploading content to a new deployment

org.jboss.hal:hal-console: before 3.7.7.Final

1 year ago
HIGHMaven

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.2

1 year ago
MODERATEMaven

QOS.CH logback-core Expression Language Injection vulnerability

QOS.CH logback-core Expression Language Injection vulnerability

ch.qos.logback:logback-core: 1.4.0 → 1.5.13

1 year ago
LOWMaven

QOS.CH logback-core Server-Side Request Forgery vulnerability

QOS.CH logback-core Server-Side Request Forgery vulnerability

ch.qos.logback:logback-core: 1.4.0 → 1.5.13

1 year ago
MEDIUMMaven

Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm

Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm

org.apache.kafka:kafka_2.13: 0.10.2.0 → 3.7.2

1 year ago
MODERATEMaven

Elasticsearch Incorrect Authorization vulnerability

Elasticsearch Incorrect Authorization vulnerability

org.elasticsearch:elasticsearch: 8.16.0 → 8.16.2

1 year ago
CRITICALMaven

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.2

1 year ago
MEDIUMMaven

Welcome and About GeoServer pages communicate version and revision information

Welcome and About GeoServer pages communicate version and revision information

org.geoserver.web:gs-web-app: 2.0.0 → 2.25.1

1 year ago
HIGHMaven

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

io.quarkus.http:quarkus-http-core: before 5.3.4

1 year ago
MEDIUMMaven

Spring LDAP data exposure vulnerability

Spring LDAP data exposure vulnerability

org.springframework.ldap:spring-ldap-core: 3.0.0 → 3.2.8

1 year ago
MEDIUMMaven

Spring Framework has Authorization Bypass for Case Sensitive Comparisons

Spring Framework has Authorization Bypass for Case Sensitive Comparisons

org.springframework.security:spring-security-core: before 5.7.14

1 year ago
CRITICALMaven

AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s

AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s

org.asynchttpclient:async-http-client: 2.1.0 → 2.12.4

1 year ago
HIGHMaven

Keycloak proxy header handling Denial-of-Service (DoS) vulnerability

Keycloak proxy header handling Denial-of-Service (DoS) vulnerability

org.keycloak:keycloak-quarkus-server: all versions

1 year ago
HIGHMaven

Keycloak Build Process Exposes Sensitive Data

Keycloak Build Process Exposes Sensitive Data

org.keycloak:keycloak-quarkus-server: before 24.0.9

1 year ago
MEDIUMMaven

Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path

Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path

org.keycloak:keycloak-quarkus-server: before 26.0.6

1 year ago
HIGHMaven

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

org.keycloak:keycloak-core: before 26.0.6

1 year ago
HIGHMaven

org.keycloak:keycloak-services has Inefficient Regular Expression Complexity

org.keycloak:keycloak-services has Inefficient Regular Expression Complexity

org.keycloak:keycloak-services: before 24.0.9

1 year ago
HIGHMaven

Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider

Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider

org.apache.kafka:kafka-clients: 2.3.0 → 3.7.1

1 year ago
MEDIUMMaven

Missing permission check in Jenkins Script Security Plugin

Missing permission check in Jenkins Script Security Plugin

org.jenkins-ci.plugins:script-security: before 1368.vb

1 year ago
HIGHMaven

Denial of Service attack on windows app using netty

Denial of Service attack on windows app using netty

io.netty:netty-common: before 4.1.115.Final

1 year ago
HIGHMaven

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

com.thoughtworks.xstream:xstream: before 1.4.21

1 year ago
HIGHMaven

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M21

1 year ago
HIGHMaven

Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server

Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server

org.apache.zookeeper:zookeeper: 3.9.0 → 3.9.3

1 year ago
HIGHMaven

Snowflake JDBC Security Advisory

Snowflake JDBC Security Advisory

net.snowflake:snowflake-jdbc: 3.2.6 → 3.20.0

1 year ago
MEDIUMMaven

Apache NiFi Cross-site Scripting vulnerability

Apache NiFi Cross-site Scripting vulnerability

org.apache.nifi:nifi-web-ui: 1.10.0 → 1.28.0

1 year ago
HIGHMaven

Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications

Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications

org.springframework.security:spring-security-web: 5.0.0 → 5.7.13

1 year ago
MEDIUMMaven

Spring Framework DataBinder Case Sensitive Match Exception

Spring Framework DataBinder Case Sensitive Match Exception

org.springframework:spring-context: 6.1.0 → 6.1.14

1 year ago
MEDIUMMaven

Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect

Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect

org.keycloak:keycloak-services: before 22.0.13

1 year ago
HIGHMaven

Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak

Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak

org.keycloak:keycloak-saml-core: before 22.0.13

1 year ago
MEDIUMMaven

Eclipse Jetty has a denial of service vulnerability on DosFilter

Eclipse Jetty has a denial of service vulnerability on DosFilter

org.eclipse.jetty.ee10:jetty-ee10-servlets: 12.0.0 → 12.0.3

1 year ago
MEDIUMMaven

Eclipse Jetty URI parsing of invalid authority

Eclipse Jetty URI parsing of invalid authority

org.eclipse.jetty:jetty-http: 7.0.0 → 12.0.12

1 year ago
CRITICALMaven

Keycloak has session fixation in Elytron SAML adapters

Keycloak has session fixation in Elytron SAML adapters

org.keycloak:keycloak-services: before 22.0.12

1 year ago
MEDIUMMaven

Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity

Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity

org.keycloak:keycloak-core: before 24.0.7

1 year ago
HIGHMaven

Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks

Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks

org.eclipse.jetty:jetty-server: 12.0.0 → 12.0.9

1 year ago
MEDIUMMaven

HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4

HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4

org.jboss.resteasy:resteasy-netty4-cdi: all versions

1 year ago
MEDIUMMaven

JSON-lib mishandles an unbalanced comment string

JSON-lib mishandles an unbalanced comment string

org.kordamp.json:json-lib-core: before 3.1.0

1 year ago
CRITICALMaven

Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)

Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)

org.apache.avro:avro: before 1.11.4

1 year ago
HIGHMaven

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

commons-io:commons-io: 2.0 → 2.14.0

1 year ago
MEDIUMMaven

Jenkins exposes multi-line secrets through error messages

Jenkins exposes multi-line secrets through error messages

org.jenkins-ci.main:jenkins-core: before 2.462.3

1 year ago
MEDIUMMaven

Jenkins item creation restriction bypass vulnerability

Jenkins item creation restriction bypass vulnerability

org.jenkins-ci.main:jenkins-core: before 2.462.3

1 year ago
MEDIUMMaven

Apache Hadoop: Temporary File Local Information Disclosure

Apache Hadoop: Temporary File Local Information Disclosure

org.apache.hadoop:hadoop-common: before 3.4.0

1 year ago
MEDIUMMaven

Spring Framework DoS via conditional HTTP request

Spring Framework DoS via conditional HTTP request

org.springframework:spring-web: before 5.3.38

1 year ago
CRITICALMaven

SOFA Hessian Remote Command Execution (RCE) Vulnerability

SOFA Hessian Remote Command Execution (RCE) Vulnerability

com.alipay.sofa:hessian: before 3.5.5

1 year ago
HIGHMaven

protobuf-java has potential Denial of Service issue

protobuf-java has potential Denial of Service issue

com.google.protobuf:protobuf-java: before 3.25.5

1 year ago
MEDIUMMaven

druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability

druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability

org.apache.druid.extensions:druid-pac4j: 0.18.0 → 30.0.1

1 year ago
MEDIUMMaven

Keycloak Services has a potential bypass of brute force protection

Keycloak Services has a potential bypass of brute force protection

org.keycloak:keycloak-services: before 22.0.12

1 year ago
MEDIUMMaven

OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerability

OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerability

org.opendaylight.aaa:aaa-artifacts: all versions

1 year ago
HIGHMaven

Path traversal vulnerability in functional web frameworks

Path traversal vulnerability in functional web frameworks

org.springframework:spring-webmvc: 6.1.0 → 6.1.13

2 years ago
HIGHMaven

Keycloak Denial of Service vulnerability

Keycloak Denial of Service vulnerability

org.keycloak:keycloak-core: before 24.0.0

2 years ago
MEDIUMMaven

Keycloak Open Redirect vulnerability

Keycloak Open Redirect vulnerability

org.keycloak:keycloak-core: before 24.0.7

2 years ago
MEDIUMMaven

Spring Framework vulnerable to Denial of Service

Spring Framework vulnerable to Denial of Service

org.springframework:spring-expression: before 5.3.39

2 years ago
HIGHMaven

Apache MINA SSHD: integrity check bypass

Apache MINA SSHD: integrity check bypass

org.apache.sshd:sshd-common: before 2.12.0

2 years ago
HIGHMaven

CometVisu Backend for openHAB affected by SSRF/XSS

CometVisu Backend for openHAB affected by SSRF/XSS

org.openhab.ui.bundles:org.openhab.ui.cometvisu: 3.4.0.M4 → 4.2.1

2 years ago
MEDIUMMaven

Jenkins does not perform a permission check in an HTTP endpoint

Jenkins does not perform a permission check in an HTTP endpoint

org.jenkins-ci.main:jenkins-core: before 2.452.4

2 years ago
CRITICALMaven

Jenkins Remoting library arbitrary file read vulnerability

Jenkins Remoting library arbitrary file read vulnerability

org.jenkins-ci.main:remoting: before 3206.3208

2 years ago
CRITICALMaven

Path traversal in Reposilite javadoc file expansion (arbitrary file creation/overwrite) (`GHSL-2024-073`)

Path traversal in Reposilite javadoc file expansion (arbitrary file creation/overwrite) (`GHSL-2024-073`)

com.reposilite:reposilite-backend: 3.3.0 → 3.5.12

2 years ago
CRITICALMaven

Reposilite artifacts vulnerable to Stored Cross-site Scripting

Reposilite artifacts vulnerable to Stored Cross-site Scripting

com.reposilite:reposilite-backend: 3.3.0 → 3.5.12

2 years ago
HIGHMaven

Elasticsearch stores private key on disk unencrypted

Elasticsearch stores private key on disk unencrypted

org.elasticsearch:elasticsearch: 8.0.0-alpha1 → 8.13.0

2 years ago
HIGHMaven

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

com.graphql-java:graphql-java: before 19.11

2 years ago
CRITICALMaven

OpenAM FreeMarker template injection

OpenAM FreeMarker template injection

org.openidentityplatform.openam:openam-oauth2: before 15.0.4

2 years ago
HIGHMaven

DNSJava DNSSEC Bypass

DNSJava DNSSEC Bypass

dnsjava:dnsjava: before 3.6.0

2 years ago
HIGHMaven

DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resources

DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resources

dnsjava:dnsjava: 3.5.0 → 3.6.0

2 years ago
HIGHMaven

DNSJava vulnerable to KeyTrap - Denial-of-Service Algorithmic Complexity Attacks

DNSJava vulnerable to KeyTrap - Denial-of-Service Algorithmic Complexity Attacks

dnsjava:dnsjava: 3.5.0 → 3.6.0

2 years ago
CRITICALMaven

Absent Input Validation in BinaryHttpParser

Absent Input Validation in BinaryHttpParser

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.13.Final

2 years ago
MEDIUMMaven

The OpenSearch reporting plugin improperly controls tenancy access to reporting resources

The OpenSearch reporting plugin improperly controls tenancy access to reporting resources

org.opensearch.plugin:opensearch-reports-scheduler: before 2.14.0.0

2 years ago
MEDIUMMaven

OpenSearch Observability does not properly restrict access to private tenant resources

OpenSearch Observability does not properly restrict access to private tenant resources

org.opensearch.plugin:opensearch-observability: before 2.14.0.0

2 years ago
MEDIUMMaven

Apache NiFi vulnerable to Cross-site Scripting

Apache NiFi vulnerable to Cross-site Scripting

org.apache.nifi:nifi-web-ui: 1.10.0 → 1.27.0

2 years ago
HIGHMaven

Apache Tomcat - Denial of Service

Apache Tomcat - Denial of Service

org.apache.tomcat.embed:tomcat-embed-core: 11.0.0-M1 → 11.0.0-M21

2 years ago
HIGHMaven

GeoServer's Server Status shows sensitive environmental variables and Java properties

GeoServer's Server Status shows sensitive environmental variables and Java properties

org.geoserver.web:gs-web-app: 2.10.0 → 2.24.4

2 years ago
MEDIUMMaven

Exposure of secrets through system log in Jenkins Structs Plugin

Exposure of secrets through system log in Jenkins Structs Plugin

org.jenkins-ci.plugins:structs: before 338.v848422169819

2 years ago
MEDIUMMaven

DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document

DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document

org.dspace:dspace-server-webapp: 7.0 → 7.6.2

2 years ago
HIGHMaven

Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java

Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java

org.cyclonedx:cyclonedx-core-java: 2.1.0 → 9.0.4

2 years ago
CRITICALMaven

XWiki programming rights may be inherited by inclusion

XWiki programming rights may be inherited by inclusion

org.xwiki.platform:xwiki-platform-rendering-macro-include: before 15.0-rc-1

2 years ago
MEDIUMMaven

Keycloak leaks configured LDAP bind credentials through the Keycloak admin console

Keycloak leaks configured LDAP bind credentials through the Keycloak admin console

org.keycloak:keycloak-ldap-federation: 25.0.0 → 25.0.1

2 years ago
MEDIUMMaven

ClassGraph XML External Entity Reference

ClassGraph XML External Entity Reference

io.github.classgraph:classgraph: before 4.8.112

2 years ago
CRITICALMaven

XWiki Platform allows remote code execution from user account

XWiki Platform allows remote code execution from user account

org.xwiki.platform:xwiki-platform-oldcore: 13.4.7 → 14.10.21

2 years ago
CRITICALMaven

DeepJavaLibrary API absolute path traversal

DeepJavaLibrary API absolute path traversal

ai.djl:api: 0.1.0 → 0.28.0

2 years ago
MEDIUMMaven

CrateDB has a Client initialized Session-Renegotiation DoS

CrateDB has a Client initialized Session-Renegotiation DoS

io.crate:crate: before 5.7.2

2 years ago
HIGHMaven

Elasticsearch StackOverflow vulnerability

Elasticsearch StackOverflow vulnerability

org.elasticsearch:elasticsearch: 8.13.1 → 8.14.0

2 years ago
HIGHMaven

Keycloak's admin API allows low privilege users to use administrative functions

Keycloak's admin API allows low privilege users to use administrative functions

org.keycloak:keycloak-services: before 24.0.5

2 years ago
HIGHMaven

Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)

Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)

org.keycloak:keycloak-services: before 24.0.5

2 years ago
HIGHMaven

BoringSSLAEADContext in Netty Repeats Nonces

BoringSSLAEADContext in Netty Repeats Nonces

io.netty.incubator:netty-incubator-codec-ohttp: 0.0.3.Final → 0.0.11.Final

2 years ago
MEDIUMMaven

iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash

iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash

org.iq80.snappy:snappy: before 0.5

2 years ago
HIGHMaven

Decompressors can crash the JVM and leak memory content in Aircompressor

Decompressors can crash the JVM and leak memory content in Aircompressor

io.airlift:aircompressor: before 0.27

2 years ago
HIGHMaven

OpenAPI Generator Online - Arbitrary File Read/Delete

OpenAPI Generator Online - Arbitrary File Read/Delete

org.openapitools:openapi-generator-online: before 7.6.0

2 years ago
CRITICALMaven

Amazon JDBC Driver for Redshift SQL Injection via line comment generation

Amazon JDBC Driver for Redshift SQL Injection via line comment generation

com.amazon.redshift:redshift-jdbc42: before 2.1.0.28

2 years ago
MEDIUMMaven

Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.

Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.

org.bouncycastle:bcprov-jdk18on: before 1.78

2 years ago
HIGHMaven

Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")

Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")

org.bouncycastle:bctls-fips: before 1.0.19

2 years ago
MEDIUMMaven

Bouncy Castle crafted signature and public key can be used to trigger an infinite loop

Bouncy Castle crafted signature and public key can be used to trigger an infinite loop

org.bouncycastle:bcprov-jdk18on: 1.73 → 1.78

2 years ago
HIGHMaven

Neo4j Cypher component mishandles IMMUTABLE privileges

Neo4j Cypher component mishandles IMMUTABLE privileges

org.neo4j:neo4j-cypher: 5.0.0 → 5.19.0

2 years ago
HIGHMaven

Bouncy Castle Java Cryptography API vulnerable to DNS poisoning

Bouncy Castle Java Cryptography API vulnerable to DNS poisoning

org.bouncycastle:bcprov-jdk18on: 1.61 → 1.78

2 years ago
CRITICALMaven

Jenkins Script Security Plugin sandbox bypass vulnerability

Jenkins Script Security Plugin sandbox bypass vulnerability

org.jenkins-ci.plugins:script-security: before 1336.vf33a

2 years ago
CRITICALMaven

Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies

Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies

org.jenkins-ci.plugins:script-security: before 1336.vf33a

2 years ago
CRITICALMaven

OpenMetadata vulnerable to a SpEL Injection in `PUT /api/v1/events/subscriptions` (`GHSL-2023-251`)

OpenMetadata vulnerable to a SpEL Injection in `PUT /api/v1/events/subscriptions` (`GHSL-2023-251`)

org.open-metadata:openmetadata-service: before 1.2.4

2 years ago
CRITICALMaven

OpenMetadata vulnerable to a SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` (`GHSL-2023-236`)

OpenMetadata vulnerable to a SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` (`GHSL-2023-236`)

org.open-metadata:openmetadata-service: before 1.2.4

2 years ago
HIGHMaven

OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)

OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)

org.open-metadata:openmetadata-service: before 1.3.1

2 years ago
CRITICALMaven

Ant Media Server vulnerable to a local privilege escalation

Ant Media Server vulnerable to a local privilege escalation

io.antmedia:ant-media-server: 2.6.0 → 2.9.0

2 years ago
MEDIUMMaven

Keycloak Authorization Bypass vulnerability

Keycloak Authorization Bypass vulnerability

org.keycloak:keycloak-services: before 22.0.10

2 years ago
HIGHMaven

Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow

Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow

org.keycloak:keycloak-services: before 22.0.10

2 years ago
HIGHMaven

Keycloak path traversal vulnerability in redirection validation

Keycloak path traversal vulnerability in redirection validation

org.keycloak:keycloak-services: before 22.0.10

2 years ago
HIGHMaven

Keycloak vulnerable to session hijacking via re-authentication

Keycloak vulnerable to session hijacking via re-authentication

org.keycloak:keycloak-services: before 22.0.10

2 years ago
MEDIUMMaven

Keycloak path traversal vulnerability in the redirect validation

Keycloak path traversal vulnerability in the redirect validation

org.keycloak:keycloak-services: before 22.0.10

2 years ago
HIGHMaven

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

org.keycloak:keycloak-services: before 22.0.10

2 years ago
MEDIUMMaven

Keycloak vulnerable to impersonation via logout token exchange

Keycloak vulnerable to impersonation via logout token exchange

org.keycloak:keycloak-services: before 22.0.10

2 years ago
MEDIUMMaven

Keycloak secondary factor bypass in step-up authentication

Keycloak secondary factor bypass in step-up authentication

org.keycloak:keycloak-services: before 22.0.10

2 years ago
HIGHMaven

Spring Framework URL Parsing with Host Validation

Spring Framework URL Parsing with Host Validation

org.springframework:spring-web: before 5.3.34

2 years ago
HIGHMaven

Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode

Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode

org.apache.kafka:kafka-metadata: 3.5.0 → 3.6.2

2 years ago
CRITICALMaven

XWiki Platform: Remote code execution through space title and Solr space facet

XWiki Platform: Remote code execution through space title and Solr space facet

org.xwiki.platform:xwiki-platform-search-solr-ui: 7.2-rc-1 → 14.10.20

2 years ago
MEDIUMMaven

WildFly Elytron: OIDC app attempting to access the second tenant, the user should be prompted to log

WildFly Elytron: OIDC app attempting to access the second tenant, the user should be prompted to log

org.wildfly.security:wildfly-elytron-http-oidc: before 2.2.5.Final

2 years ago
CRITICALMaven

XWiki Platform remote code execution from account via custom skins support

XWiki Platform remote code execution from account via custom skins support

org.xwiki.platform:xwiki-platform-oldcore: 6.4-milestone-1 → 14.10.19

2 years ago
MEDIUMMaven

XWiki Platform CSRF in the job scheduler

XWiki Platform CSRF in the job scheduler

org.xwiki.platform:xwiki-platform-scheduler-ui: 3.1 → 14.10.19

2 years ago
CRITICALMaven

XWiki Platform: Privilege escalation (PR) from user registration through PDFClass

XWiki Platform: Privilege escalation (PR) from user registration through PDFClass

org.xwiki.platform:xwiki-platform-oldcore: 3.0.1 → 14.10.20

2 years ago
CRITICALMaven

XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution

XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution

org.xwiki.commons:xwiki-commons-velocity: 3.0.1 → 14.10.19

2 years ago
CRITICALMaven

XWiki Platform CSRF remote code execution through the realtime HTML Converter API

XWiki Platform CSRF remote code execution through the realtime HTML Converter API

org.xwiki.platform:xwiki-platform-realtime-ui: 13.9-rc-1 → 14.10.19

2 years ago
CRITICALMaven

XWiki Platform CSRF remote code execution through scheduler job's document reference

XWiki Platform CSRF remote code execution through scheduler job's document reference

org.xwiki.platform:xwiki-platform-scheduler-ui: 3.1 → 14.10.19

2 years ago
CRITICALMaven

XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet

XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet

org.xwiki.platform:xwiki-platform-search-ui: 5.2-milestone-2 → 14.10.20

2 years ago
CRITICALMaven

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

org.xwiki.platform:xwiki-platform-localization-source-wiki: 4.3-milestone-2 → 14.10.20

2 years ago
CRITICALMaven

XWiki Platform remote code execution from account through UIExtension parameters

XWiki Platform remote code execution from account through UIExtension parameters

org.xwiki.platform:xwiki-platform-uiextension-api: before 14.10.19

2 years ago
CRITICALMaven

XWiki Platform: Remote code execution as guest via DatabaseSearch

XWiki Platform: Remote code execution as guest via DatabaseSearch

org.xwiki.platform:xwiki-platform-search-ui: 2.4-milestone-1 → 14.10.20

2 years ago
HIGHMaven

XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted

XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted

org.xwiki.platform:xwiki-platform-oldcore: 5.0-rc-1 → 14.10.19

2 years ago
MEDIUMMaven

WildFly Elytron: SSRF security issue

WildFly Elytron: SSRF security issue

org.wildfly.security:wildfly-elytron-realm-token: all versions

2 years ago
CRITICALMaven

quarkus-core leaks local environment variables from Quarkus namespace during application's build

quarkus-core leaks local environment variables from Quarkus namespace during application's build

io.quarkus:quarkus-core: 3.9.0.CR1 → 3.9.2

2 years ago
HIGHMaven

Elasticsearch Uncontrolled Resource Consumption vulnerability

Elasticsearch Uncontrolled Resource Consumption vulnerability

org.elasticsearch:elasticsearch: 7.0.0 → 7.17.19

2 years ago
HIGHMaven

Elasticsearch Incorrect Authorization vulnerability

Elasticsearch Incorrect Authorization vulnerability

org.elasticsearch:elasticsearch: 8.10.0 → 8.13.0

2 years ago
MEDIUMMaven

Netty's HttpPostRequestDecoder can OOM

Netty's HttpPostRequestDecoder can OOM

io.netty:netty-codec-http: before 4.1.108.Final

2 years ago
HIGHMaven

XNIO denial of service vulnerability

XNIO denial of service vulnerability

org.jboss.xnio:xnio-api: before 3.8.14.Final

2 years ago
MEDIUMMaven

Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree

Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree

org.apache.commons:commons-configuration2: 2.0 → 2.10.1

2 years ago
MEDIUMMaven

Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

org.apache.commons:commons-configuration2: 2.0 → 2.10.1

2 years ago
MEDIUMMaven

GeoServer's Simple SVG Renderer vulnerable to Stored Cross-Site Scripting (XSS)

GeoServer's Simple SVG Renderer vulnerable to Stored Cross-Site Scripting (XSS)

org.geoserver:gs-wms: before 2.23.4

2 years ago
MEDIUMMaven

GeoServer's MapML HTML Page vulnerable to Stored Cross-Site Scripting (XSS)

GeoServer's MapML HTML Page vulnerable to Stored Cross-Site Scripting (XSS)

org.geoserver.extension:gs-mapml: before 2.23.4

2 years ago
MEDIUMMaven

GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS)

GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS)

org.geoserver:gs-gwc: 2.24.0 → 2.24.1

2 years ago
HIGHMaven

GeoServer Arbitrary file renaming vulnerability in REST Coverage/Data Store API

GeoServer Arbitrary file renaming vulnerability in REST Coverage/Data Store API

org.geoserver:gs-restconfig: before 2.23.5

2 years ago
MEDIUMMaven

GeoServer's Style Publisher vulnerable to Stored Cross-Site Scripting (XSS)

GeoServer's Style Publisher vulnerable to Stored Cross-Site Scripting (XSS)

org.geoserver:gs-main: before 2.23.3

2 years ago
MEDIUMMaven

GeoServer's GWC Seed Form vulnerable to Stored Cross-Site Scripting (XSS)

GeoServer's GWC Seed Form vulnerable to Stored Cross-Site Scripting (XSS)

org.geoserver:gs-gwc-rest: before 2.23.2

2 years ago
MEDIUMMaven

GeoServer's WMS OpenLayers Format vulnerable to Stored Cross-Site Scripting (XSS)

GeoServer's WMS OpenLayers Format vulnerable to Stored Cross-Site Scripting (XSS)

org.geoserver:gs-wms: before 2.23.3

2 years ago
HIGHMaven

Erroneous authentication pass in Spring Security

Erroneous authentication pass in Spring Security

org.springframework.security:spring-security-core: before 5.7.12

2 years ago
HIGHMaven

Spring Framework URL Parsing with Host Validation Vulnerability

Spring Framework URL Parsing with Host Validation Vulnerability

org.springframework:spring-web: 6.1.0 → 6.1.5

2 years ago
MEDIUMMaven

Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling

Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling

org.apache.zookeeper:zookeeper: 3.8.0 → 3.8.4

2 years ago
HIGHMaven

SSRF vulnerability using the Aegis DataBinding in Apache CXF

SSRF vulnerability using the Aegis DataBinding in Apache CXF

org.apache.cxf:cxf-rt-databinding-aegis: before 3.5.8

2 years ago
HIGHMaven

Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests

Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M17

2 years ago
MEDIUMMaven

In Quarkus, git credentials could be inadvertently published

In Quarkus, git credentials could be inadvertently published

io.quarkus:quarkus-kubernetes-deployment: before 3.7.3

2 years ago
MEDIUMMaven

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat

org.apache.tomcat:tomcat-websocket: 11.0.0-M1 → 11.0.0-M17

2 years ago
HIGHMaven

Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service

Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service

org.clojure:clojure: 1.7.0 → 1.11.2

2 years ago
HIGHMaven

jose4j denial of service via specifically crafted JWE

jose4j denial of service via specifically crafted JWE

org.bitbucket.b_c:jose4j: before 0.9.4

2 years ago
MEDIUMMaven

Apache James MIME4J improper input validation vulnerability

Apache James MIME4J improper input validation vulnerability

org.apache.james:apache-mime4j-core: before 0.8.10

2 years ago
HIGHMaven

Connection leaking on idle timeout when TCP congested

Connection leaking on idle timeout when TCP congested

org.eclipse.jetty.http2:http2-common: 9.3.0 → 9.4.54

2 years ago
HIGHMaven

Spring Web vulnerable to Open Redirect or Server Side Request Forgery

Spring Web vulnerable to Open Redirect or Server Side Request Forgery

org.springframework:spring-web: 6.1.0 → 6.1.4

2 years ago
MEDIUMMaven

Cross-site Scripting Vulnerability in Statement Browser

Cross-site Scripting Vulnerability in Statement Browser

com.yetanalytics:lrs: before 1.2.17

2 years ago
MEDIUMMaven

XWiki extension license information is public, exposing instance id and license holder details

XWiki extension license information is public, exposing instance id and license holder details

com.xwiki.licensing:application-licensing-licensor-ui: 1.0 → 1.24.2

2 years ago
CRITICALMaven

org.postgresql:postgresql vulnerable to SQL Injection via line comment generation

org.postgresql:postgresql vulnerable to SQL Injection via line comment generation

org.postgresql:postgresql: before 42.2.28

2 years ago
HIGHMaven

Liferay Portal defaults to a low work factor for the default password hashing algorithm

Liferay Portal defaults to a low work factor for the default password hashing algorithm

com.liferay.portal:release.dxp.bom: 7.3.0 → 7.3.10.u4

2 years ago
CRITICALMaven

Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)

Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)

com.liferay.portal:release.portal.bom: before 7.4.3.13

2 years ago
HIGHMaven

Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file

Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file

org.apache.commons:commons-compress: 1.3 → 1.26.0

2 years ago
HIGHMaven

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

org.apache.commons:commons-compress: 1.21 → 1.26.0

2 years ago
MEDIUMMaven

Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project

Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project

org.openjfx:javafx-media: before 17.0.10

2 years ago
MEDIUMMaven

Absolute path traversal vulnerability in digdag server

Absolute path traversal vulnerability in digdag server

io.digdag:digdag-server: before 0.10.5.1

2 years ago
MEDIUMMaven

OpenRefine JDBC Attack Vulnerability

OpenRefine JDBC Attack Vulnerability

org.openrefine:database: before 3.7.8

2 years ago
HIGHMaven

Denial of Service in Connect2id Nimbus JOSE+JWT

Denial of Service in Connect2id Nimbus JOSE+JWT

com.nimbusds:nimbus-jose-jwt: before 9.37.2

2 years ago
HIGHMaven

Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds

Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds

org.apache.solr:solr-solrj-streaming: 9.0.0 → 9.4.1

2 years ago
CRITICALMaven

Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets

Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets

org.apache.solr:solr-core: 6.0.0 → 8.11.3

2 years ago
MEDIUMMaven

Micronaut management endpoints vulnerable to drive-by localhost attack

Micronaut management endpoints vulnerable to drive-by localhost attack

io.micronaut:micronaut-http-server: before 3.8.3

2 years ago
HIGHMaven

Graylog session fixation vulnerability through cookie injection

Graylog session fixation vulnerability through cookie injection

org.graylog2:graylog2-server: 4.3.0 → 5.1.11

2 years ago
CRITICALMaven

Graylog vulnerable to instantiation of arbitrary classes triggered by API request

Graylog vulnerable to instantiation of arbitrary classes triggered by API request

org.graylog2:graylog2-server: 2.0.0 → 5.1.11

2 years ago
MEDIUMMaven

Malicious input can provoke XSS when preserving comments

Malicious input can provoke XSS when preserving comments

org.owasp.antisamy:antisamy: before 1.7.5

2 years ago
HIGHMaven

CrateDB database has an arbitrary file read vulnerability

CrateDB database has an arbitrary file read vulnerability

io.crate:crate: before 5.3.9

2 years ago
CRITICALMaven

Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE

Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE

org.jenkins-ci.main:jenkins-core: 1.606 → 2.426.3

2 years ago
MEDIUMMaven

Path traversal vulnerability in Jenkins Matrix Project Plugin

Path traversal vulnerability in Jenkins Matrix Project Plugin

org.jenkins-ci.plugins:matrix-project: before 822.824.v14451b

2 years ago
CRITICALMaven

Cross-site WebSocket hijacking vulnerability in the Jenkins CLI

Cross-site WebSocket hijacking vulnerability in the Jenkins CLI

org.jenkins-ci.main:jenkins-core: 2.217 → 2.426.3

2 years ago
MEDIUMMaven

keycloak-core: open redirect via "form_post.jwt" JARM response mode

keycloak-core: open redirect via "form_post.jwt" JARM response mode

org.keycloak:keycloak-core: before 23.0.4

2 years ago
CRITICALMaven

Remote Command Execution in SOFARPC

Remote Command Execution in SOFARPC

com.alipay.sofa:rpc-sofa-boot-starter: before 5.12.0

2 years ago
HIGHMaven

Spring Framework server Web DoS Vulnerability

Spring Framework server Web DoS Vulnerability

org.springframework:spring-core: 6.1.2 → 6.1.3

2 years ago
CRITICALMaven

XWiki Remote Code Execution Vulnerability via User Registration

XWiki Remote Code Execution Vulnerability via User Registration

org.xwiki.platform:xwiki-platform-administration-ui: 2.2 → 14.10.17

2 years ago
HIGHMaven

XWiki vulnerable to Denial of Service attack through attachments

XWiki vulnerable to Denial of Service attack through attachments

org.xwiki.platform:xwiki-platform-distribution-war: 14.10 → 14.10.18

2 years ago
CRITICALMaven

XWiki has no right protection on rollback action

XWiki has no right protection on rollback action

org.xwiki.platform:xwiki-platform-oldcore: 1.0 → 14.10.17

2 years ago
HIGHMaven

Ion Java StackOverflow vulnerability

Ion Java StackOverflow vulnerability

com.amazon.ion:ion-java: before 1.10.5

2 years ago
HIGHMaven

Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions

Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions

org.infinispan:infinispan-server-rest: 15.0.0.Dev01 → 15.0.0.Dev04

2 years ago
HIGHMaven

Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions

Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions

org.infinispan:infinispan-server-rest: 15.0.0.Dev01 → 15.0.0.Dev04

2 years ago
HIGHMaven

Infinispan circular object references causes out of memory errors

Infinispan circular object references causes out of memory errors

org.infinispan.protostream:protostream: before 4.6.2.Final

2 years ago
MEDIUMMaven

Infinispan caches credentials in clear text

Infinispan caches credentials in clear text

org.infinispan:infinispan-core: 15.0.0.Dev01 → 15.0.0.Dev07

2 years ago
MEDIUMMaven

json-path Out-of-bounds Write vulnerability

json-path Out-of-bounds Write vulnerability

com.jayway.jsonpath:json-path: 2.2.0 → 2.9.0

2 years ago
HIGHMaven

Grails data binding causes JVM crash and/or other denial of service

Grails data binding causes JVM crash and/or other denial of service

org.grails:grails-databinding: 6.0.0 → 6.1.0

2 years ago
MEDIUMMaven

Velocity execution without script right through tree macro

Velocity execution without script right through tree macro

org.xwiki.platform:xwiki-platform-index-tree-macro: 8.3-rc-1 → 14.10.7

2 years ago
CRITICALMaven

Remote code execution/programming rights with configuration section from any user account

Remote code execution/programming rights with configuration section from any user account

org.xwiki.platform:xwiki-platform-administration-ui: 2.3 → 14.10.15

2 years ago
MEDIUMMaven

Solr search discloses email addresses of users

Solr search discloses email addresses of users

org.xwiki.platform:xwiki-platform-search-solr-api: before 14.10.15

2 years ago
CRITICALMaven

Remote code execution from account through SearchAdmin

Remote code execution from account through SearchAdmin

org.xwiki.platform:xwiki-platform-search-ui: 4.5-rc-1 → 14.10.15

2 years ago
HIGHMaven

Solr search discloses password hashes of all users

Solr search discloses password hashes of all users

org.xwiki.platform:xwiki-platform-search-solr-api: 7.2-milestone-2 → 14.10.15

2 years ago
HIGHMaven

Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability

Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability

org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01

2 years ago
MEDIUMMaven

Jenkins Nexus Platform Plugin missing permission check

Jenkins Nexus Platform Plugin missing permission check

org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01

2 years ago
HIGHMaven

Jenkins Nexus Platform Plugin missing permission check

Jenkins Nexus Platform Plugin missing permission check

org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01

2 years ago
MEDIUMMaven

Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability

Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability

org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01

2 years ago
HIGHMaven

Data leak of password hash through change requests

Data leak of password hash through change requests

org.xwiki.contrib.changerequest:application-changerequest-default: 0.1 → 1.10

2 years ago
HIGHMaven

Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data

Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data

ch.qos.logback:logback-core: 1.4.13 → 1.4.14

2 years ago
CRITICALMaven

HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL

HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL

org.htmlunit:htmlunit: before 3.9.0

2 years ago
CRITICALMaven

Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download

Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download

io.github.microcks:microcks: before 1.17.1

2 years ago
HIGHMaven

logback serialization vulnerability

logback serialization vulnerability

ch.qos.logback:logback-classic: 1.3.0 → 1.3.12

2 years ago
HIGHMaven

Reactor Netty HTTP Server denial of service vulnerability

Reactor Netty HTTP Server denial of service vulnerability

io.projectreactor.netty:reactor-netty-core: 1.1.0 → 1.1.13

2 years ago
HIGHMaven

Apache Tomcat Improper Input Validation vulnerability

Apache Tomcat Improper Input Validation vulnerability

org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.0-M11

2 years ago
HIGHMaven

Bouncy Castle Denial of Service (DoS)

Bouncy Castle Denial of Service (DoS)

org.bouncycastle:bcprov-ext-jdk16: before 1.73

2 years ago
HIGHMaven

Whole content of all documents of all wikis exposed to anybody with view right on Solr suggest service

Whole content of all documents of all wikis exposed to anybody with view right on Solr suggest service

org.xwiki.platform:xwiki-platform-search-solr-query: 6.3-milestone-2 → 14.10.15

2 years ago
CRITICALMaven

Apache Derby: LDAP injection vulnerability in authenticator

Apache Derby: LDAP injection vulnerability in authenticator

org.apache.derby:derby: ≥ 10.1.1.0

2 years ago
CRITICALMaven

Cookies are sent to external images in rendered diff (and server side request forgery)

Cookies are sent to external images in rendered diff (and server side request forgery)

org.xwiki.platform:xwiki-platform-diff-xml: 11.10.1 → 14.10.15

2 years ago
CRITICALMaven

Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries

Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries

org.xwiki.contrib:xwiki-application-admintools: before 4.5.1

2 years ago
HIGHMaven

Authenticated Rundeck users can view or delete jobs they do not have authorization for.

Authenticated Rundeck users can view or delete jobs they do not have authorization for.

org.rundeck:rundeck: 4.12.0 → 4.17.3

2 years ago
HIGHMaven

Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain

Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain

io.quarkus:quarkus-project: ≥ 3.0.0.CR1

2 years ago
HIGHMaven

In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack

In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack

io.projectreactor.netty:reactor-netty-http: 1.1.0 → 1.1.13

2 years ago
HIGHMaven

Java: DoS Vulnerability in JSON-JAVA

Java: DoS Vulnerability in JSON-JAVA

org.json:json: before 20231013

2 years ago
CRITICALMaven

XWiki Platform vulnerable to remote code execution through the section parameter in Administration as guest

XWiki Platform vulnerable to remote code execution through the section parameter in Administration as guest

org.xwiki.platform:xwiki-platform-administration-ui: before 14.10.14

2 years ago
CRITICALMaven

XWiki Platform privilege escalation from script right to programming right through title displayer

XWiki Platform privilege escalation from script right to programming right through title displayer

org.xwiki.platform:xwiki-platform-display-api: 3.2-milestone-3 → 14.10.7

2 years ago
HIGHMaven

Elasticsearch vulnerable to Uncontrolled Resource Consumption

Elasticsearch vulnerable to Uncontrolled Resource Consumption

org.elasticsearch:elasticsearch: before 7.17.13

2 years ago
HIGHMaven

jose4j uses weak cryptographic algorithm

jose4j uses weak cryptographic algorithm

org.bitbucket.b_c:jose4j: before 0.9.3

2 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter

org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter

org.xwiki.platform:xwiki-platform-office-importer: 3.5-milestone-1 → 14.10.8

2 years ago
CRITICALMaven

XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro

XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro

org.xwiki.rendering:xwiki-rendering-macro-footnotes: before 14.10.6

2 years ago
HIGHMaven

org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move

org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move

org.xwiki.platform:xwiki-platform-attachment-api: 14.0-rc-1 → 14.4.8

2 years ago
CRITICALMaven

XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled

XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled

org.xwiki.platform:xwiki-platform-web-templates: 12.0-rc-1 → 14.10.12

2 years ago
CRITICALMaven

Privilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheet

Privilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheet

org.xwiki.platform:xwiki-platform-menu: 5.1-rc-1 → 14.10.8

2 years ago
HIGHMaven

WPS Server Side Request Forgery vulnerability

WPS Server Side Request Forgery vulnerability

org.geoserver.extension:gs-wps-core: before 2.22.5

2 years ago
HIGHMaven

RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS Attack

RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS Attack

com.rabbitmq:amqp-client: before 5.18.0

2 years ago
HIGHMaven

Apache Santuario - XML Security for Java are vulnerable to private key disclosure

Apache Santuario - XML Security for Java are vulnerable to private key disclosure

org.apache.santuario:xmlsec: 2.3.0 → 2.3.4

2 years ago
CRITICALMaven

MySQL Connectors takeover vulnerability

MySQL Connectors takeover vulnerability

com.mysql:mysql-connector-j: before 8.2.0

2 years ago
MEDIUMMaven

OpenSearch Issue with tenant read-only permissions

OpenSearch Issue with tenant read-only permissions

org.opensearch.plugin:opensearch-security: 2.0.0.0 → 2.11.0.0

2 years ago
MEDIUMMaven

WebAuthn4J Spring Security Improper signature counter value handling

WebAuthn4J Spring Security Improper signature counter value handling

com.webauthn4j:webauthn4j-spring-security-core: before 0.9.1.RELEASE

2 years ago
HIGHMaven

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper

org.apache.zookeeper:zookeeper: before 3.7.2

2 years ago
HIGHMaven

Denial of service vulnerability on creating a Launch with too many recursively nested elements in reportportal

Denial of service vulnerability on creating a Launch with too many recursively nested elements in reportportal

com.epam.reportportal:service-api: before 5.10.0

2 years ago
HIGHMaven

io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack

io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack

io.netty:netty-codec-http2: before 4.1.100.Final

2 years ago
HIGHMaven

HTTP/2 HPACK integer overflow and buffer allocation

HTTP/2 HPACK integer overflow and buffer allocation

org.eclipse.jetty.http2:http2-hpack: 10.0.0 → 10.0.16

2 years ago
MEDIUMMaven

mXSS in AntiSamy

mXSS in AntiSamy

org.owasp.antisamy:antisamy: before 1.7.4

2 years ago
MEDIUMMaven

io.micronaut.security:micronaut-security-oauth2 has invalid IdTokenClaimsValidator logic on aud

io.micronaut.security:micronaut-security-oauth2 has invalid IdTokenClaimsValidator logic on aud

io.micronaut.security:micronaut-security-oauth2: 3.11.0 → 3.11.1

2 years ago
HIGHMaven

Apache Avro Java SDK vulnerable to Improper Input Validation

Apache Avro Java SDK vulnerable to Improper Input Validation

org.apache.avro:avro: before 1.11.3

2 years ago
HIGHMaven

snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact

snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact

org.xerial.snappy:snappy-java: before 1.1.10.4

2 years ago
CRITICALMaven

Arbitrary File Overwrite in Eclipse JGit

Arbitrary File Overwrite in Eclipse JGit

org.eclipse.jgit:org.eclipse.jgit: 6.0.0.202111291000-r → 6.6.1.202309021850-r

2 years ago
MEDIUMMaven

Jetty's OpenId Revoked authentication allows one request

Jetty's OpenId Revoked authentication allows one request

org.eclipse.jetty:jetty-openid: 9.4.21 → 9.4.52.v20230823

3 years ago
MEDIUMMaven

Jetty accepts "+" prefixed value in Content-Length

Jetty accepts "+" prefixed value in Content-Length

org.eclipse.jetty:jetty-http: 9.0.0 → 9.4.52

3 years ago
MEDIUMMaven

Jetty vulnerable to errant command quoting in CGI Servlet

Jetty vulnerable to errant command quoting in CGI Servlet

org.eclipse.jetty:jetty-servlets: 9.0.0 → 9.4.52

3 years ago
HIGHMaven

Apache Commons Compress denial of service vulnerability

Apache Commons Compress denial of service vulnerability

org.apache.commons:commons-compress: 1.22 → 1.24.0

3 years ago
HIGHMaven

OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack

OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack

org.openrefine:database: before 3.7.5

3 years ago
CRITICALMaven

OpenRefine Remote Code execution in project import with mysql jdbc url attack

OpenRefine Remote Code execution in project import with mysql jdbc url attack

org.openrefine:database: before 3.7.5

3 years ago
MEDIUMMaven

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

org.wiremock:wiremock-standalone: before 3.0.3

3 years ago
MEDIUMMaven

Velocity execution without script right through VelocityCode and VelocityWiki property

Velocity execution without script right through VelocityCode and VelocityWiki property

org.xwiki.platform:xwiki-platform-oldcore: 7.2 → 14.10.10

3 years ago
HIGHMaven

DDFFileParser is vulnerable to XXE Attacks

DDFFileParser is vulnerable to XXE Attacks

org.eclipse.leshan:leshan-core: before 1.5.0

3 years ago
MEDIUMMaven

Apache Tomcat Open Redirect vulnerability

Apache Tomcat Open Redirect vulnerability

org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.0-M11

3 years ago
CRITICALMaven

XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action

XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action

org.xwiki.platform:xwiki-platform-oldcore: 3.2-milestone-3 → 14.10.9

3 years ago
HIGHMaven

XWiki Platform privilege escalation (PR) from account through AWM content fields

XWiki Platform privilege escalation (PR) from account through AWM content fields

org.xwiki.platform:xwiki-platform-appwithinminutes-ui: 4.3-milestone-2 → 14.10.5

3 years ago
HIGHMaven

Apache Ivy External Entity Reference vulnerability

Apache Ivy External Entity Reference vulnerability

org.apache.ivy:ivy: before 2.5.2

3 years ago
HIGHMaven

XWiki Platform privilege escalation (PR)/RCE from account through Invitation subject/message

XWiki Platform privilege escalation (PR)/RCE from account through Invitation subject/message

org.xwiki.platform:xwiki-platform-invitation-ui: 2.5-m-1 → 14.4.8

3 years ago
MEDIUMMaven

Jenkins Delphix Plugin vulnerable to exposure of system-scoped credentials

Jenkins Delphix Plugin vulnerable to exposure of system-scoped credentials

org.jenkins-ci.plugins:delphix: before 3.0.3

3 years ago
MEDIUMMaven

Jenkins Delphix Plugin missing permission check

Jenkins Delphix Plugin missing permission check

org.jenkins-ci.plugins:delphix: before 3.0.3

3 years ago
CRITICALMaven

Deserialization vulnerability in Helix workflow and REST

Deserialization vulnerability in Helix workflow and REST

org.apache.helix:helix-core: before 1.3.0

3 years ago
HIGHMaven

Incorrect control flow in Jenkins Gradle Plugin breaks credentials masking in the build log

Incorrect control flow in Jenkins Gradle Plugin breaks credentials masking in the build log

org.jenkins-ci.plugins:gradle: before 2.8.1

3 years ago
CRITICALMaven

Arbitrary File Creation in AbstractUnArchiver

Arbitrary File Creation in AbstractUnArchiver

org.codehaus.plexus:plexus-archiver: before 4.8.0

3 years ago
HIGHMaven

Paths contain matrix variables bypass decorators

Paths contain matrix variables bypass decorators

com.linecorp.armeria:armeria: before 1.24.3

3 years ago
HIGHMaven

OpenAM vulnerable to user impersonation using SAMLv1.x SSO process

OpenAM vulnerable to user impersonation using SAMLv1.x SSO process

org.openidentityplatform.openam:openam-federation-library: before 14.7.3

3 years ago
MEDIUMMaven

OpenRefine vulnerable to zip slip in project import

OpenRefine vulnerable to zip slip in project import

org.openrefine:main: before 3.7.4

3 years ago
HIGHMaven

Okio Signed to Unsigned Conversion Error vulnerability

Okio Signed to Unsigned Conversion Error vulnerability

com.squareup.okio:okio: 2.0.0-RC1 → 3.4.0

3 years ago
MEDIUMMaven

Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations

Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations

org.eclipse.jetty:jetty-xml: 10.0.0-alpha0 → 10.0.16

3 years ago
CRITICALMaven

XWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST API

XWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST API

org.xwiki.platform:xwiki-platform-rest-server: 1.8 → 14.10.8

3 years ago
MEDIUMMaven

Apache MINA SSHD information disclosure vulnerability

Apache MINA SSHD information disclosure vulnerability

org.apache.sshd:sshd-common: 2.1.0 → 2.9.3

3 years ago
MEDIUMMaven

Graylog user session is still usable after logout

Graylog user session is still usable after logout

org.graylog2:graylog2-server: 1.0 → 5.0.9

3 years ago
CRITICALMaven

Apache Cassandra: Privilege escalation when enabling FQL/Audit logs

Apache Cassandra: Privilege escalation when enabling FQL/Audit logs

org.apache.cassandra:cassandra-all: 4.1.0 → 4.1.2

3 years ago
CRITICALMaven

Apache InLong has Weak Password Requirements in Apache InLong

Apache InLong has Weak Password Requirements in Apache InLong

org.apache.inlong:manager-pojo: 1.1.0 → 1.47.0

3 years ago
MEDIUMMaven

gRPC connection termination issue

gRPC connection termination issue

io.grpc:grpc-protobuf: 1.53.0 → 1.53.1

3 years ago
MEDIUMMaven

Graylog server has partial path traversal vulnerability in Support Bundle feature

Graylog server has partial path traversal vulnerability in Support Bundle feature

org.graylog2:graylog2-server: 5.1.0 → 5.1.3

3 years ago
HIGHMaven

gRPC Reachable Assertion issue

gRPC Reachable Assertion issue

io.grpc:grpc-protobuf: 1.51.0 → 1.53.0

3 years ago
MEDIUMMaven

Bouncy Castle For Java LDAP injection vulnerability

Bouncy Castle For Java LDAP injection vulnerability

org.bouncycastle:bcprov-jdk18on: before 1.74

3 years ago
HIGHMaven

Connection confusion in gRPC

Connection confusion in gRPC

io.grpc:grpc-protobuf: 1.53.0 → 1.53.1

3 years ago
CRITICALMaven

org.xwiki.commons:xwiki-commons-xml's HTML sanitizer allows form elements in restricted

org.xwiki.commons:xwiki-commons-xml's HTML sanitizer allows form elements in restricted

org.xwiki.commons:xwiki-commons-xml: 14.6-rc-1 → 14.10.6

3 years ago
CRITICALMaven

XWiki Platform vulnerable to persistent Cross-site Scripting through CKEditor Configuration pages

XWiki Platform vulnerable to persistent Cross-site Scripting through CKEditor Configuration pages

org.xwiki.platform:xwiki-platform-ckeditor-ui: 14.6-rc-1 → 14.10.6

3 years ago
CRITICALMaven

Remote Code Execution for 2.4.1 and earlier

Remote Code Execution for 2.4.1 and earlier

net.opentsdb:opentsdb: before 2.4.2

3 years ago
CRITICALMaven

XWiki Platform vulnerable to reflected cross-site scripting via delattachment action

XWiki Platform vulnerable to reflected cross-site scripting via delattachment action

org.xwiki.platform:xwiki-platform-oldcore: 3.2-milestone-3 → 14.10.6

3 years ago
CRITICALMaven

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template

org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 9.4-rc-1 → 14.10.5

3 years ago
HIGHMaven

FastAsyncWorldEdit vulnerable to Uncontrolled Resource Consumption

FastAsyncWorldEdit vulnerable to Uncontrolled Resource Consumption

com.fastasyncworldedit:FastAsyncWorldEdit-Core: before 2.6.3

3 years ago
CRITICALMaven

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template

org.xwiki.platform:xwiki-platform-web-templates: 3.4-milestone-1 → 14.10.5

3 years ago
CRITICALMaven

XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template

XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template

org.xwiki.platform:xwiki-platform-web-templates: 2.5-milestone-2 → 14.10.5

3 years ago
CRITICALMaven

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template

org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 6.0-rc-1 → 14.10.6

3 years ago
CRITICALMaven

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page

org.xwiki.platform:xwiki-platform-appwithinminutes-ui: 6.2-milestone-1 → 14.10.5

3 years ago
CRITICALMaven

XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResults

XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResults

org.xwiki.platform:xwiki-platform-like-ui: 12.9-rc-1 → 14.4.8

3 years ago
MEDIUMMaven

XWiki Platform's tags on non-viewable pages can be revealed to users

XWiki Platform's tags on non-viewable pages can be revealed to users

org.xwiki.platform:xwiki-platform-tag-api: 5.0-milestone-1 → 14.4.8

3 years ago
CRITICALMaven

XWiki Platform vulnerable to cross-site scripting via xcontinue parameter in previewactions template

XWiki Platform vulnerable to cross-site scripting via xcontinue parameter in previewactions template

org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 6.1-rc-1 → 14.10.5

3 years ago
HIGHMaven

XWiki Platform may retrieve email addresses of all users

XWiki Platform may retrieve email addresses of all users

org.xwiki.platform:xwiki-platform-livetable-ui: 3.5-milestone-1 → 14.4.8

3 years ago
CRITICALMaven

XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parameters

XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parameters

org.xwiki.platform:xwiki-platform-appwithinminutes-ui: 5.4.4 → 14.4.8

3 years ago
HIGHMaven

XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application

XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application

org.xwiki.platform:xwiki-platform-invitation-ui: 2.4-m-2 → 14.4.8

3 years ago
HIGHMaven

netty-handler SniHandler 16MB allocation

netty-handler SniHandler 16MB allocation

io.netty:netty-handler: before 4.1.94.Final

3 years ago
HIGHMaven

snappy-java's Integer Overflow vulnerability in shuffle leads to DoS

snappy-java's Integer Overflow vulnerability in shuffle leads to DoS

org.xerial.snappy:snappy-java: before 1.1.10.1

3 years ago
HIGHMaven

snappy-java's unchecked chunk length leads to DoS

snappy-java's unchecked chunk length leads to DoS

org.xerial.snappy:snappy-java: before 1.1.10.1

3 years ago
HIGHMaven

snappy-java's Integer Overflow vulnerability in compress leads to DoS

snappy-java's Integer Overflow vulnerability in compress leads to DoS

org.xerial.snappy:snappy-java: before 1.1.10.1

3 years ago
HIGHMaven

Guava vulnerable to insecure use of temporary directory

Guava vulnerable to insecure use of temporary directory

com.google.guava:guava: 1.0 → 32.0.0-android

3 years ago
HIGHMaven

hjson stack exhaustion vulnerability

hjson stack exhaustion vulnerability

org.hjson:hjson: before 3.0.1

3 years ago
CRITICALMaven

GeoServer RCE due to improper control of generation of code in jai-ext`Jiffle` map algebra language

GeoServer RCE due to improper control of generation of code in jai-ext`Jiffle` map algebra language

org.geoserver:gs-wms: before 2.18.6

3 years ago
HIGHMaven

DataEase API interface has IDOR vulnerability

DataEase API interface has IDOR vulnerability

io.dataease:dataease-plugin-common: before 1.18.7

3 years ago
CRITICALMaven

Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled

Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled

org.xerial:sqlite-jdbc: 3.6.14.1 → 3.41.2.2

3 years ago
MEDIUMMaven

org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability

org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability

org.xwiki.platform:xwiki-platform-oldcore: before 14.10.4

3 years ago
CRITICALMaven

Privilege escalation (PR)/RCE from account through class sheet

Privilege escalation (PR)/RCE from account through class sheet

org.xwiki.platform:xwiki-platform-test-ui: 3.3-milestone-3 → 14.10.4

3 years ago
CRITICALMaven

Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml

Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml

org.xwiki.commons:xwiki-commons-xml: 14.6-rc-1 → 14.10.4

3 years ago
MODERATEMaven

Chosen Ciphertext Attack in Jose4j

Chosen Ciphertext Attack in Jose4j

org.bitbucket.b_c:jose4j: before 0.9.3

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection

org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection

org.xwiki.platform:xwiki-platform-attachment-ui: 3.0-rc-1 → 13.10.11

3 years ago
MEDIUMMaven

XWiki App Within Minutes app grants space admin rights that allows cross-site scripting

XWiki App Within Minutes app grants space admin rights that allows cross-site scripting

org.xwiki.platform:xwiki-platform-appwithinminutes: 4.0-milestone-2 → 4.2-milestone-1

3 years ago
CRITICALMaven

XWiki Platform vulnerable to code injection in display method used in user profiles

XWiki Platform vulnerable to code injection in display method used in user profiles

org.xwiki.platform:xwiki-platform-oldcore: 3.3-milestone-1 → 13.10.11

3 years ago
CRITICALMaven

XWiki Platform vulnerable to code injection from view right on XWiki.ClassSheet

XWiki Platform vulnerable to code injection from view right on XWiki.ClassSheet

org.xwiki.platform:xwiki-platform-xclass-ui: 7.0-rc-1 → 14.4.8

3 years ago
CRITICALMaven

Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml

Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml

org.xwiki.commons:xwiki-commons-xml: 4.2-milestone-1 → 14.10

3 years ago
HIGHMaven

XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector

XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector

org.xwiki.platform:xwiki-platform-attachment-ui: 2.0-rc-2 → 13.10.11

3 years ago
CRITICALMaven

XWiki Platform vulnerable to code injection from account/view through VFS Tree macro

XWiki Platform vulnerable to code injection from account/view through VFS Tree macro

org.xwiki.platform:xwiki-platform-vfs-ui: 7.4-milestone-2 → 13.10.11

3 years ago
HIGHMaven

Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewer

Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewer

org.xwiki.platform:xwiki-platform-office-viewer: 2.5-milestone-2 → 13.10.11

3 years ago
CRITICALMaven

XWiki Platform vulnerable to privilege escalation from view right using Invitation.InvitationCommon

XWiki Platform vulnerable to privilege escalation from view right using Invitation.InvitationCommon

org.xwiki.platform:xwiki-platform-invitation-ui: 2.5-m-1 → 13.10.11

3 years ago
MEDIUMMaven

OutOfMemoryError for large multipart without filename in Eclipse Jetty

OutOfMemoryError for large multipart without filename in Eclipse Jetty

org.eclipse.jetty:jetty-server: before 9.4.51.v20230217

3 years ago
CRITICALMaven

Code injection via unescaped translations in xwiki-platform

Code injection via unescaped translations in xwiki-platform

org.xwiki.platform:xwiki-platform-administration-ui: 4.3-milestone-2 → 14.10.2

3 years ago
MEDIUMMaven

Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies

Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies

org.eclipse.jetty:jetty-server: before 9.4.51.v20230217

3 years ago
HIGHMaven

Snowflake JDBC vulnerable to command injection via SSO URL authentication

Snowflake JDBC vulnerable to command injection via SSO URL authentication

net.snowflake:snowflake-jdbc: before 3.13.29

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors

org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors

org.xwiki.platform:xwiki-platform-oldcore: 14.5 → 14.10

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macro

org.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macro

org.xwiki.platform:xwiki-platform-rendering-xwiki: before 14.8-rc-1

3 years ago
HIGHMaven

org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation

org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation

org.xwiki.platform:xwiki-platform-flamingo-theme-ui: 12.6.6 → 13.10.11

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki: 5.3-milestone-2 → 13.10.11

3 years ago
HIGHMaven

Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro

Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro

org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 1.9-milestone-2 → 13.10.10

3 years ago
HIGHMaven

org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents

org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents

org.xwiki.platform:xwiki-platform-oldcore: 1.2-milestone-1 → 13.10.11

3 years ago
CRITICALMaven

org.xwiki.commons:xwiki-commons-xml Cross-site Scripting vulnerability

org.xwiki.commons:xwiki-commons-xml Cross-site Scripting vulnerability

org.xwiki.commons:xwiki-commons-xml: 4.2-milestone-1 → 14.6-rc-1

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-logging-ui: 4.2-milestone-3 → 13.10.11

3 years ago
MEDIUMMaven

Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm

Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm

org.xwiki.platform:xwiki-platform-web-templates: 13.9-rc-1 → 13.10.8

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-panels-ui: 1.1-M2 → 13.10.11

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-notifications-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-notifications-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-notifications-ui: 13.2-rc-1 → 13.10.11

3 years ago
HIGHMaven

xwiki-platform-administration-ui vulnerable to privilege escalation

xwiki-platform-administration-ui vulnerable to privilege escalation

org.xwiki.platform:xwiki-platform-administration-ui: 1.5M2 → 13.10.11

3 years ago
MEDIUMMaven

Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter

Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter

io.goobi.viewer:viewer-core: before 23.03

3 years ago
MEDIUMMaven

Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments

Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments

io.goobi.viewer:viewer-core: before 23.03

3 years ago
MEDIUMMaven

Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames

Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames

io.goobi.viewer:viewer-core: before 23.03

3 years ago
CRITICALMaven

Apache James server's JMX management service vulnerable to privilege escalation by local user

Apache James server's JMX management service vulnerable to privilege escalation by local user

org.apache.james:javax-mail-extension: before 3.7.4

3 years ago
MEDIUMMaven

Apiman vulnerable to permissions bypass due to missing check on API key URL

Apiman vulnerable to permissions bypass due to missing check on API key URL

io.apiman:apiman-manager-api-rest-impl: before 3.1.0.Final

3 years ago
HIGHMaven

json-smart Uncontrolled Recursion vulnerability

json-smart Uncontrolled Recursion vulnerability

net.minidev:json-smart: before 2.4.9

3 years agoEPSS 1%
HIGHMaven

Jettison vulnerable to infinite recursion

Jettison vulnerable to infinite recursion

org.codehaus.jettison:jettison: before 1.5.4

3 years ago
HIGHMaven

jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode

jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode

com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.12.6

3 years ago
MEDIUMMaven

Incorrect Permission Preservation in Jenkins Core

Incorrect Permission Preservation in Jenkins Core

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
MEDIUMMaven

Incorrect Authorization in Jenkins Core

Incorrect Authorization in Jenkins Core

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
MEDIUMMaven

Information disclosure through error stack traces related to agents

Information disclosure through error stack traces related to agents

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
CRITICALMaven

Cross-site Scripting vulnerability in Jenkins

Cross-site Scripting vulnerability in Jenkins

org.jenkins-ci.main:jenkins-core: 2.376 → 2.394

3 years ago
CRITICALMaven

Incorrect Authorization in Jenkins Core

Incorrect Authorization in Jenkins Core

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-panels-ui vulnerable to Eval Injection

org.xwiki.platform:xwiki-platform-panels-ui vulnerable to Eval Injection

org.xwiki.platform:xwiki-platform-panels-ui: 6.3-milestone-2 → 13.10.11

3 years ago
HIGHMaven

XWiki Platform packages Expose Sensitive Information to an Unauthorized Actor

XWiki Platform packages Expose Sensitive Information to an Unauthorized Actor

org.xwiki.platform:xwiki-platform-livetable-ui: 3.2-m3 → 13.4.4

3 years ago
HIGHMaven

xwiki vulnerable to Improper Handling of Exceptional Conditions

xwiki vulnerable to Improper Handling of Exceptional Conditions

org.xwiki.platform:xwiki-platform-rendering-parser: 6.0 → 13.10.10

3 years ago
HIGHMaven

Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm

Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm

org.xwiki.platform:xwiki-platform-web: 1.3-rc-1 → 13.10.11

3 years ago
CRITICALMaven

XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile

XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile

org.xwiki.platform:xwiki-platform-icon-ui: 6.2-milestone-1 → 13.10.10

3 years ago
CRITICALMaven

org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability

org.xwiki.platform:xwiki-platform-flamingo-theme-ui: 6.2.4 → 13.10.10

3 years ago
MEDIUMMaven

xwiki contains Incorrect Authorization

xwiki contains Incorrect Authorization

org.xwiki.platform:xwiki-platform-rendering-macro-context: 3.0-milestone-1 → 13.10.10

3 years ago
HIGHMaven

XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data

XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data

org.xwiki.platform:xwiki-platform-livedata-macro: 12.10 → 13.10.10

3 years ago
CRITICALMaven

XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author

XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author

org.xwiki.platform:xwiki-platform-oldcore: 13.10 → 13.10.11

3 years ago
HIGHMaven

Keycloak vulnerable to user impersonation via stolen UUID code

Keycloak vulnerable to user impersonation via stolen UUID code

org.keycloak:keycloak-services: before 21.0.1

3 years ago
CRITICALMaven

GeoServer OGC Filter SQL Injection Vulnerabilities

GeoServer OGC Filter SQL Injection Vulnerabilities

org.geoserver.community:gs-jdbcconfig: before 2.21.4

3 years ago
HIGHMaven

Apache Commons FileUpload denial of service vulnerability

Apache Commons FileUpload denial of service vulnerability

commons-fileupload:commons-fileupload: before 1.5

3 years ago
HIGHMaven

XML External Entity (XXE) vulnerability in apoc.import.graphml

XML External Entity (XXE) vulnerability in apoc.import.graphml

org.neo4j.procedure:apoc-core: 5.0.0 → 5.5.0

3 years ago
MEDIUMMaven

StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route

StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route

io.vertx:vertx-web: 4.0.0 → 4.3.8

3 years ago
HIGHMaven

Field-level security issue with .keyword fields in OpenSearch

Field-level security issue with .keyword fields in OpenSearch

org.opensearch.plugin:opensearch-security: before 1.3.8

3 years ago
HIGHMaven

Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator

Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator

org.wildfly.security:wildfly-elytron: before 1.15.15.Final

3 years ago
CRITICALMaven

XWiki CKEditor.HTMLConverter vulnerable to Remote Code Execution via Cross-Site Request Forgery

XWiki CKEditor.HTMLConverter vulnerable to Remote Code Execution via Cross-Site Request Forgery

org.xwiki.contrib:application-ckeditor-ui: before 1.64.3

3 years ago
HIGHMaven

Apache James server allows an attacker with local access to access private user data in transit

Apache James server allows an attacker with local access to access private user data in transit

org.apache.james:james-server: all versions

3 years ago
HIGHMaven

json stack overflow vulnerability

json stack overflow vulnerability

cn.hutool:hutool-json: before 5.8.25

3 years ago
HIGHMaven

Jettison Out-of-bounds Write vulnerability

Jettison Out-of-bounds Write vulnerability

org.codehaus.jettison:jettison: before 1.5.2

3 years ago
HIGHMaven

Jettison Out-of-bounds Write vulnerability

Jettison Out-of-bounds Write vulnerability

org.codehaus.jettison:jettison: before 1.5.2

3 years ago
MEDIUMMaven

HAProxyMessageDecoder Stack Exhaustion DoS

HAProxyMessageDecoder Stack Exhaustion DoS

io.netty:netty-codec-haproxy: before 4.1.86.Final

3 years ago
HIGHMaven

SnakeYaml Constructor Deserialization Remote Code Execution

SnakeYaml Constructor Deserialization Remote Code Execution

org.yaml:snakeyaml: before 2.0

3 years ago
HIGHMaven

Protobuf Java vulnerable to Uncontrolled Resource Consumption

Protobuf Java vulnerable to Uncontrolled Resource Consumption

com.google.protobuf:protobuf-java: 3.0.0 → 3.16.3

3 years ago
HIGHMaven

Protobuf Java vulnerable to Uncontrolled Resource Consumption

Protobuf Java vulnerable to Uncontrolled Resource Consumption

com.google.protobuf:protobuf-java: 3.0.0 → 3.16.3

3 years ago

Tooling for Maven

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm