| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-4963 | Folio Spring Module Core Schema Name HibernateSchemaService.java dropSchema sql injection | Folio | Spring Module Core | Medium | 5.5 | 2024-03-20 18:31:05 | Deep Dive |
| CVE-2024-22258 | CVE-2024-22258: PKCE Downgrade in Spring Authorization Server | Spring | Spring | Medium | 6.1 | 2024-03-20 03:58:13 | Deep Dive |
| CVE-2024-22257 | VMware Spring Security 安全漏洞 | N/A | Spring Security | High | 8.2 | 2024-03-18 14:18:53 | Deep Dive |
| CVE-2024-22259 | CVE-2024-22259: Spring Framework URL Parsing with Host Validation (2nd report) | Spring | Spring Framework | High | 8.1 | 2024-03-16 04:40:09 | Deep Dive |
| CVE-2024-22243 | CVE-2024-22243: Spring Framework URL Parsing with Host Validation | Spring | Spring Framework | High | 8.1 | 2024-02-23 05:03:54 | Deep Dive |
| CVE-2024-22234 | CVE-2024-22234: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated | Spring | Spring Security | High | 7.4 | 2024-02-20 07:02:51 | Deep Dive |
| CVE-2024-1635 | Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol | - | - | High | 7.5 | 2024-02-19 21:23:14 | Deep Dive |
| CVE-2023-34042 | VMware Spring Security 安全漏洞 | N/A | Spring Security | Medium | 4.1 | 2024-02-05 22:00:01 | Deep Dive |
| CVE-2024-22236 | Spring Cloud 安全漏洞 | Spring | Spring Cloud Contract | Low | 3.3 | 2024-01-31 06:54:51 | Deep Dive |
| CVE-2024-22233 | CVE-2024-22233: Spring Framework server Web DoS Vulnerability | Spring | Spring Framework | High | 7.5 | 2024-01-22 12:16:15 | Deep Dive |
| CVE-2023-5236 | Infinispan: circular reference on marshalling leads to dos | Red Hat | Red Hat Data Grid 8.4.4 | Medium | 4.4 | 2023-12-18 13:43:08 | Deep Dive |
| CVE-2023-5379 | Undertow: ajp request closes connection exceeding maxrequestsize | Red Hat | Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | High | 7.5 | 2023-12-12 21:54:53 | Deep Dive |
| CVE-2023-34055 | Spring Boot server Web Observations DoS Vulnerability | Spring | Spring Boot | Medium | 5.3 | 2023-11-28 08:27:25 | Deep Dive |
| CVE-2023-34054 | Reactor Netty HTTP Server Metrics DoS Vulnerability | Spring | Reactor Netty | Medium | 5.3 | 2023-11-28 08:16:14 | Deep Dive |
| CVE-2023-34053 | Spring Framework server Web Observations DoS Vulnerability | Spring | Spring Framework | Medium | 5.3 | 2023-11-28 08:10:37 | Deep Dive |
| CVE-2023-34050 | Spring AMQP Deserialization Vulnerability | Spring | Spring AMQP | Medium | 5.0 | 2023-10-19 07:11:35 | Deep Dive |
| CVE-2023-45669 | Improper signature counter value handling in webauthn4j-spring-security | webauthn4j | webauthn4j-spring-security | Medium | 4.8 | 2023-10-16 18:20:50 | Deep Dive |
| CVE-2023-3223 | Undertow: outofmemoryerror due to @multipartconfig handling | Red Hat | Red Hat Fuse 7.12.1 | High | 7.5 | 2023-09-27 13:54:45 | Deep Dive |
| CVE-2022-4245 | Codehaus-plexus: xml external entity (xxe) injection | Red Hat | RHINT Camel-K-1.10.1 | Medium | 4.3 | 2023-09-25 19:20:57 | Deep Dive |
| CVE-2022-4244 | Codehaus-plexus: directory traversal | Red Hat | RHINT Camel-K-1.10.1 | High | 7.5 | 2023-09-25 19:20:05 | Deep Dive |