CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Quarkus: graphql operations over websockets bypass
Quarkus: potential invalid reuse of context when @cacheresult on a uni is used
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
Quarkus: http security policy bypass
Undertow: infinite loop in sslconduit during close
Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol
keycloak: Untrusted Certificate Validation
quarkus-vertx-http: a cross-site attack may be initiated which might lead to the Information Disclosure
undertow: Server identity in https connection is not checked by the undertow client
quarkus_dev_ui: Dev UI Config Editor is vulnerable to drive-by localhost attacks leading to RCE
undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)
kernel: reading /proc/sysvipc/shm does not scale with large shared memory segment counts
smallrye-health-ui: persistent cross-site scripting in endpoint
kubernetes-client: Insecure deserialization in unmarshalYaml method
kernel: FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes
kernel: crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd()
kernel: race condition in net/can/bcm.c leads to local privilege escalation
wildfly-elytron: possible timing attack in ScramServer
wildfly: XSS via admin console when creating roles in domain mode
fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise
hibernate: SQL injection issue in Hibernate ORM
Showing 1 to 21 CVEs · page 1