Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
607952
AlmaLinux
4582
Alpaquita
8725
Alpine
4045
Android
3262
BellSoft Hardened Containers
416
Bitnami
6834
Chainguard
5514
CleanStart
713
CRAN
14
crates.io
2195
Debian
54017
Echo
3139
GHC
3
GIT
81456
GitHub Actions
49
Go
6479
Hackage
30
Hex
57
Julia
410
Linux
15361
Mageia
5861
Maven
6292
MinimOS
21893
npm
216959
NuGet
1624
opam
11
openEuler
6292
openSUSE
12388
OSS-Fuzz
3817
Packagist
5998
Pub
11
PyPI
18548
Red Hat
19106
Rocky Linux
2889
Root
11696
RubyGems
1924
SUSE
20136
SwiftURL
50
Ubuntu
51656
VSCode
18
Wolfi
3482
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-w35j-pv5h-q9q9
Maven/org.apache.logging.log4j:log4j-layout-template-json
Apache Log4j's JsonTemplateLayout produces invalid JSON output when log events contain non-finite floating-point values
23 hours ago
Fix available
Severity - 6.3 (Medium)
GHSA-3pxv-7cmr-fjr4
Maven/org.apache.logging.log4j:log4j-core
Apache Log4j Core's XmlLayout fails to sanitize characters
23 hours ago
Fix available
Severity - 6.9 (Medium)
GHSA-5568-6qcg-g7fx
Maven/org.apache.activemq:activemq-all
Maven/org.apache.activemq:activemq-broker
Maven/org.apache.activemq:activemq-client
Maven/org.apache.activemq:apache-activemq
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
yesterday
Fix available
Severity - 7.5 (High)
GHSA-hwqh-2684-54fc
Maven/org.springframework.cloud:spring-cloud-gateway
Spring Cloud Gateway's SSL bundle configuration silently bypassed
yesterday
Fix available
Severity - 7.5 (High)
GHSA-24j9-x2wg-9qv6
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
yesterday
Fix available
Severity - 6.5 (Medium)
GHSA-69r9-qgr7-g2wj
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
yesterday
Fix available
Severity - 7.5 (High)
GHSA-rv64-5gf8-9qq8
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
yesterday
Fix available
Severity - 7.5 (High)
GHSA-x4m4-345f-5h5g
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
yesterday
Fix available
Severity - 7.5 (High)
GHSA-563x-q5rq-57qp
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
yesterday
Fix available
Severity - 7.5 (High)
GHSA-69cc-cv78-qc8g
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat: Configured cipher preference order not preserved
yesterday
Fix available
Severity - 7.5 (High)
GHSA-8mc5-53m5-3qj2
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat has an Improper Input Validation vulnerability
yesterday
Fix available
Severity - 6.9 (Medium)
GHSA-95jq-rwvf-vjx4
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
yesterday
Fix available
Severity - 9.1 (Critical)
GHSA-9m3c-qcxr-9x87
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat has an Open Redirect vulnerability
yesterday
Fix available
Severity - 6.9 (Medium)
GHSA-h468-7pvh-8vr8
Maven/org.apache.tomcat.embed:tomcat-embed-core
Maven/org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat-catalina
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
yesterday
Fix available
Severity - 8.7 (High)
GHSA-gcvm-c75m-h4p4
Maven/org.apache.openmeetings:openmeetings-parent
Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
yesterday
Fix available
Severity - 8.7 (High)
GHSA-xvqc-pp94-fmpx
Maven/org.apache.activemq:activemq-all
Maven/org.apache.activemq:activemq-mqtt
Maven/org.apache.activemq:apache-activemq
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound
yesterday
Fix available
Severity - 5.4 (Medium)
Load more...
Maven - OSV