H2database / H2
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-45868 | The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to speci… | HIGH | 8.4 | Nov 23, 2022 |
| CVE-2022-23221 | h2: Loading of custom classes from remote servers through JNDI | CRITICAL | 9.8 | Jan 19, 2022 |
| CVE-2021-42392 | h2: Remote Code Execution in Console | CRITICAL | 9.8 | Jan 7, 2022 |
| CVE-2021-23463 | XML External Entity (XXE) Injection | CRITICAL | 9.1 | Dec 10, 2021 |
| CVE-2018-14335 | h2: Information Exposure due to insecure handling of permissions in the backup | MEDIUM | 6.5 | Jul 24, 2018 |
| CVE-2018-10054 | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the… | HIGH | 8.8 | Apr 11, 2018 |
Showing 1 to 6 of 6 CVEs