Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - | cpe:/a:redhat:jboss_enterprise_application_platform:7 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - | cpe:/a:redhat:jboss_enterprise_application_platform:8 |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15555 | 8.8 HIGH | Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization |
| CVE-2026-15560 | 8.1 HIGH | Openjdk-orb: unauthed class loading via iiop in eap |
| CVE-2026-15556 | 8.1 HIGH | Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions |
| CVE-2026-72693 | 7.8 HIGH | Kbd: local privilege escalation in openvt via incorrect process owner verification allowin |
| CVE-2026-71217 | 7.5 HIGH | Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote de |
| CVE-2026-15567 | 7.5 HIGH | Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop lis |
| CVE-2026-15565 | 7.5 HIGH | Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serveren |
| CVE-2026-15562 | 7.5 HIGH | Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authenticat |
| CVE-2026-15561 | 7.5 HIGH | Undertow-core: oom via missing limits in chunked trailer in eap's undertow |
| CVE-2026-50237 | 7.4 HIGH | Openshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin- |
| CVE-2026-15554 | 7.4 HIGH | Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery |
| CVE-2026-15563 | 7.4 HIGH | Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or do |
| CVE-2026-50236 | 7.4 HIGH | Openshift/console: authenticated ssrf with full response reflection and path neutralizatio |
| CVE-2026-72694 | 7.1 HIGH | Mrtg: mrtg daemon symlink-following chown allows local privilege escalation via pid file p |
| CVE-2026-19391 | 6.5 MEDIUM | Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwords |
| CVE-2026-24330 | 6.5 MEDIUM | Wildfly-core: wildfly: arbitrary file read via malicious archive deployment |
| CVE-2026-71218 | 5.3 MEDIUM | Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated |
| CVE-2026-24329 | 4.9 MEDIUM | Wildfly-core: wildfly core: denial of service via malformed payload injection by an authen |
| CVE-2026-19519 | 4.3 MEDIUM | Claircore: claircore: denial of service via unchecked type assertion in rpm header parser |
No comments yet