Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 128 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-2240 Smallrye-fault-tolerance: smallrye fault tolerance -- High 7.5 2025-03-12 14:55:16 Deep Dive
CVE-2025-23368 Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli -- High 8.1 2025-03-04 15:14:48 Deep Dive
CVE-2024-11831 Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript -- Medium 5.4 2025-02-10 15:27:47 Deep Dive
CVE-2025-23367 Org.wildfly.core:wildfly-server: wildfly improper rbac permission -- Medium 6.5 2025-01-30 14:30:04 Deep Dive
CVE-2025-23366 Org.jboss.hal:hal-console: wildfly hal console cross-site scripting -- Medium 6.5 2025-01-14 17:41:43 Deep Dive
CVE-2024-11736 Org.keycloak:keycloak-quarkus-server: unrestricted admin use of system and environment variables -- Medium 4.9 2025-01-14 08:36:09 Deep Dive
CVE-2024-11734 Org.keycloak:keycloak-quarkus-server: denial of service in keycloak server via security headers -- Medium 6.5 2025-01-14 08:35:42 Deep Dive
CVE-2024-8447 Narayana: deadlock via multiple join requests sent to lra coordinator -- Medium 5.9 2025-01-02 20:19:30 Deep Dive
CVE-2024-10973 Keycloak: cli option for encrypted jgroups ignored -- Medium 5.7 2024-12-17 22:59:39 Deep Dive
CVE-2024-12397 Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling -- High 7.4 2024-12-12 09:05:28 Deep Dive
CVE-2024-12369 Elytron-oidc-client: oidc authorization code injection -- Medium 4.2 2024-12-09 20:53:09 Deep Dive
CVE-2024-10492 Keycloak-quarkus-server: keycloak path trasversal -- 低危 -2024-11-25 07:37:31 Deep Dive
CVE-2024-10270 Org.keycloak:keycloak-services: keycloak denial of service -- Medium 6.5 2024-11-25 07:37:05 Deep Dive
CVE-2024-10451 Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process Red HatRed Hat build of Keycloak 24 Medium 5.9 2024-11-25 07:37:05 Deep Dive
CVE-2024-9666 Org.keycloak/keycloak-quarkus-server: keycloak proxy header handling denial-of-service (dos) vulnerability -- Medium 4.7 2024-11-25 07:29:52 Deep Dive
CVE-2023-4639 Undertow: cookie smuggling/spoofing Red HatMigration Toolkit for Runtimes 1 on RHEL 8 High 7.4 2024-11-17 10:21:45 Deep Dive
CVE-2023-1973 Undertow: unrestricted request storage leads to memory exhaustion Red HatRed Hat JBoss Enterprise Application Platform 7 High 7.5 2024-11-07 10:01:58 Deep Dive
CVE-2023-1932 Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss Red HatA-MQ Clients 2 Medium 6.1 2024-11-07 10:00:52 Deep Dive
CVE-2024-10234 Wildfly: wildfly vulnerable to cross-site scripting (xss) -- Medium 6.1 2024-10-22 13:17:58 Deep Dive
CVE-2024-3656 Keycloak: unguarded admin rest api endpoints allows low privilege users to use administrative functionalities -- High 8.1 2024-10-09 18:59:11 Deep Dive