Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 128 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2024-9622 Resteasy-netty4-cdi: resteasy-netty4: resteasy-reactor-netty: http request smuggling leading to client timeouts in resteasy-netty4 -- Medium 5.3 2024-10-08 16:26:13 Deep Dive
CVE-2024-8883 Keycloak: vulnerable redirect uri validation results in open redirec -- Medium 6.1 2024-09-19 15:48:28 Deep Dive
CVE-2024-8698 Keycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloak -- High 7.7 2024-09-19 15:48:18 Deep Dive
CVE-2024-7341 Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters -- High 7.1 2024-09-09 18:51:14 Deep Dive
CVE-2024-4629 Keycloak: potential bypass of brute force protection -- Medium 6.5 2024-09-03 19:42:01 Deep Dive
CVE-2024-7885 Undertow: improper state management in proxy protocol parsing causes information leakage -- High 7.5 2024-08-21 14:13:37 Deep Dive
CVE-2024-3653 Undertow: learningpushhandler can lead to remote memory dos attacks -- Medium 5.3 2024-07-08 21:21:21 Deep Dive
CVE-2024-5971 Undertow: response write hangs in case of java 17 tlsv1.3 newsessionticket -- High 7.5 2024-07-08 20:51:29 Deep Dive
CVE-2024-6162 Undertow: url-encoded request path information can be broken on ajp-listener -- High 7.5 2024-06-20 14:33:10 Deep Dive
CVE-2024-4029 Wildfly: no timeout for eap management interface may lead to denial of service (dos) -- Medium 4.1 2024-05-02 14:55:27 Deep Dive
CVE-2024-1102 Jberet: jberet-core logging database credentials -- Medium 6.5 2024-04-25 16:24:30 Deep Dive
CVE-2023-6717 Keycloak: xss via assertion consumer service url in saml post-binding flow -- Medium 6.0 2024-04-25 16:02:03 Deep Dive
CVE-2023-5675 Quarkus: authorization flaw in quarkus resteasy reactive and classic when "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.default-roles-allowed" properties are used. -- Medium 6.5 2024-04-25 15:44:56 Deep Dive
CVE-2024-1249 Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginiframe leads to ddos -- High 7.4 2024-04-17 13:22:48 Deep Dive
CVE-2024-1132 Keycloak: path transversal in redirection validation -- High 8.1 2024-04-17 13:21:19 Deep Dive
CVE-2023-6236 Eap: oidc app attempting to access the second tenant, the user should be prompted to log Red HatRed Hat JBoss Enterprise Application Platform 8 High 7.3 2024-04-10 01:04:54 Deep Dive
CVE-2024-1233 Eap: wildfly-elytron has a ssrf security issue -- High 7.3 2024-04-09 07:01:48 Deep Dive
CVE-2024-1300 Io.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni support -- Medium 5.4 2024-04-02 07:33:05 Deep Dive
CVE-2024-3094 Xz: malicious code in distributed source -- Critical 10.0 2024-03-29 16:51:13 Deep Dive
CVE-2024-1023 Io.vertx/vertx-core: memory leak due to the use of netty fastthreadlocal data structures in vertx -- Medium 6.5 2024-03-27 07:51:16 Deep Dive