CVE-2025-8415
- EPSS 0.04%
- Veröffentlicht 20.08.2025 16:14:33
- Zuletzt bearbeitet 03.09.2025 04:16:06
A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacke...
CVE-2024-11831
- EPSS 0.6%
- Veröffentlicht 10.02.2025 16:15:37
- Zuletzt bearbeitet 04.06.2025 23:15:20
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. T...
CVE-2024-12397
- EPSS 0.38%
- Veröffentlicht 12.12.2024 09:15:05
- Zuletzt bearbeitet 10.06.2025 11:15:21
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary a...
CVE-2024-12401
- EPSS 0.41%
- Veröffentlicht 12.12.2024 09:15:05
- Zuletzt bearbeitet 12.12.2024 09:15:05
A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in a Secret resource, to use large amounts of CPU in the cert-manager controller pod to effectively create a ...
CVE-2023-1932
- EPSS 0.23%
- Veröffentlicht 07.11.2024 10:15:04
- Zuletzt bearbeitet 24.06.2025 13:07:42
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an inva...
CVE-2024-1300
- EPSS 0.1%
- Veröffentlicht 02.04.2024 08:15:53
- Zuletzt bearbeitet 25.11.2024 03:15:10
A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is err...
CVE-2024-1023
- EPSS 0.23%
- Veröffentlicht 27.03.2024 08:15:38
- Zuletzt bearbeitet 25.11.2024 03:15:09
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can ...
CVE-2023-44487
- EPSS 94.44%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.