CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2023-6394 CRITICAL

Quarkus: graphql operations over websockets bypass

CVSS 9.1 EPSS 0.81% Dec 9, 2023
CVE-2023-6393 MEDIUM

Quarkus: potential invalid reuse of context when @cacheresult on a uni is used

CVSS 5.3 EPSS 0.64% Dec 6, 2023
CVE-2023-44487 KEV MEDIUM

HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

CVSS 6.9 EPSS 100.00% Oct 10, 2023
GoMavenSwiftURL
CVE-2023-4853 HIGH

Quarkus: http security policy bypass

CVSS 8.1 EPSS 1.45% Sep 20, 2023
CVE-2023-1108 HIGH

Undertow: infinite loop in sslconduit during close

CVSS 7.5 EPSS 1.77% Sep 14, 2023
CVE-2023-2974 HIGH

Quarkus-core: tls protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported tls protocol

CVSS 8.1 EPSS 0.88% Jul 4, 2023
CVE-2023-1664 MEDIUM

keycloak: Untrusted Certificate Validation

CVSS 6.5 EPSS 0.43% May 26, 2023
CVE-2023-0044 MEDIUM

quarkus-vertx-http: a cross-site attack may be initiated which might lead to the Information Disclosure

CVSS 6.1 EPSS 0.55% Feb 23, 2023
CVE-2022-4492 CRITICAL

undertow: Server identity in https connection is not checked by the undertow client

CVSS 9.8 EPSS 0.60% Feb 23, 2023
CVE-2022-4116 CRITICAL

quarkus_dev_ui: Dev UI Config Editor is vulnerable to drive-by localhost attacks leading to RCE

CVSS 9.8 EPSS 32.52% Nov 22, 2022
CVE-2022-1259 HIGH

undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)

CVSS 7.5 EPSS 1.31% Aug 31, 2022
CVE-2021-3669 MEDIUM

kernel: reading /proc/sysvipc/shm does not scale with large shared memory segment counts

CVSS 5.5 EPSS 0.29% Aug 26, 2022
CVE-2021-3914 MEDIUM

smallrye-health-ui: persistent cross-site scripting in endpoint

CVSS 6.5 EPSS 0.51% Aug 25, 2022
CVE-2021-4178 MEDIUM

kubernetes-client: Insecure deserialization in unmarshalYaml method

CVSS 6.7 EPSS 0.33% Aug 24, 2022
CVE-2022-1011 HIGH

kernel: FUSE allows UAF reads of write() buffers, allowing theft of (partial) /etc/shadow hashes

CVSS 7.8 EPSS 1.17% Mar 18, 2022
CVE-2021-3744 MEDIUM

kernel: crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd()

CVSS 5.5 EPSS 0.53% Mar 4, 2022
CVE-2021-3609 HIGH

kernel: race condition in net/can/bcm.c leads to local privilege escalation

CVSS 7.0 EPSS 0.43% Mar 3, 2022
CVE-2021-3642 MEDIUM

wildfly-elytron: possible timing attack in ScramServer

CVSS 5.3 EPSS 0.85% Aug 5, 2021
CVE-2021-3536 MEDIUM

wildfly: XSS via admin console when creating roles in domain mode

CVSS 4.8 EPSS 0.53% May 20, 2021
CVE-2021-20218 HIGH

fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise

CVSS 7.4 EPSS 1.31% Mar 16, 2021
CVE-2019-14900 MEDIUM

hibernate: SQL injection issue in Hibernate ORM

CVSS 6.5 EPSS 2.13% Jul 6, 2020

Showing 1 to 21 CVEs · page 1