VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 16 hours ago
Reset
More filters (1)
Columns
Record: disputed
Overview 4 matches, all in RASP scope, all disputed · 1 protected · 0 KEV · 0 public PoC · 1 CISA SSVC · 0 EPSS ≥ 0.5
4matches, all in RASP scope, all disputed 1protected25.0% 0KEV0.0% 0public PoC0.0% 1CISA SSVC25.0% 0EPSS ≥ 0.50.0%
Critical 0 0.0% High 4 100.0% Medium 0 0.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 1 25.0% Rule in development 0 0.0% Mitigation candidate 1 25.0% No exploit published 2 50.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 1 25.0% not blocked 3 75.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 0 0.0% Proof of concept only 1 25.0% Forecast only 0 0.0% No public exploit 3 75.0%
split by peak 1 / year
Unknown: 0None: 0Low: 0Medium: 0High: 4Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 2Mitigation candidate: 1Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 3blocked by ARMR today: 1 No public exploit: 3Forecast only: 0Proof of concept only: 1Working exploit published: 0Exploited in the wild: 0 2014: 1 CVE 2015: 0 CVEs 2016: 0 CVEs 2017: 0 CVEs 2018: 1 CVE 2019: 0 CVEs 2020: 1 CVE 2021: 0 CVEs 2022: 1 CVE
201420152016201720182019202020212022
4 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2022-45868 High 2022-11-23 Mitigation candidate Proof of concept only The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states "This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that." Nonetheless, the issue was fixed in 2.2.220.
CVE-2020-16164 High 2020-07-30 No exploit published No public exploit An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate Revocation List files from the RPKI relying party's view. NOTE: some third parties may regard this as a preferred behavior, not a vulnerability
CVE-2018-10054 High 2018-04-11 No exploit published No public exploit H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
CVE-2013-2185 High 2014-01-19 Protected by RASP No public exploit The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue