CVE-2020-25633
- EPSS 0.28%
- Veröffentlicht 18.09.2020 19:15:16
- Zuletzt bearbeitet 21.11.2024 05:18:17
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highe...
CVE-2019-14900
- EPSS 1.22%
- Veröffentlicht 06.07.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:38
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. Th...
CVE-2020-13692
- EPSS 2.47%
- Veröffentlicht 04.06.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:44
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
CVE-2020-1714
- EPSS 2.15%
- Veröffentlicht 13.05.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:13
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privi...
CVE-2020-10693
- EPSS 0.03%
- Veröffentlicht 06.05.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:52
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping...
CVE-2020-1728
- EPSS 0.13%
- Veröffentlicht 06.04.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:15
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might ...
CVE-2017-18640
- EPSS 2.17%
- Veröffentlicht 12.12.2019 03:15:10
- Zuletzt bearbeitet 21.11.2024 03:20:32
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.