CVE Browser
CVE-2022-45868 HIGH
The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to speci…
CVSS 8.4 EPSS 0.31% Nov 23, 2022
CVE-2022-23221 CRITICAL
h2: Loading of custom classes from remote servers through JNDI
CVSS 9.8 EPSS 64.77% Jan 19, 2022
CVE-2021-42392 CRITICAL
h2: Remote Code Execution in Console
CVSS 9.8 EPSS 83.18% Jan 7, 2022
CVE-2021-23463 CRITICAL
XML External Entity (XXE) Injection
CVSS 9.1 EPSS 2.79% Dec 10, 2021
CVE-2018-14335 MEDIUM
h2: Information Exposure due to insecure handling of permissions in the backup
CVSS 6.5 EPSS 13.22% Jul 24, 2018
CVE-2018-10054 HIGH
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the…
CVSS 8.8 EPSS 33.74% Apr 11, 2018
Showing 1 to 6 CVEs · page 1