Where
-Infinity
0

maven/io.quarkus:quarkus-vertx-httpAuthentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Risk 43
Severity
7.5
First published (updated )

Quarkus QuarkusGHSL-2026-099: Authorization Bypass in Quarkus - CVE-2026-39852

Risk 57
Severity
8.8
First published (updated )

Quarkus Quarkus RESTQuarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write

Risk 43
Severity
7.5
First published (updated )

Quarkus QuarkusDescription: Security checks for standard security annotations on the RESTEasy Reactive inherited en…

Risk 5
Severity
1
First published (updated )

maven/io.quarkus:quarkus-smallrye-graphql-clientQuarkus: graphql operations over websockets bypass

Risk 48
Severity
9.1
EPSS
0.07%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.quarkus:quarkus-keycloak-authorizationQuarkus: http security policy bypass

Risk 79
Severity
8.1
First published (updated )

redhat/quarkus-vertx-httpXSS, CSRF

Risk 39
Severity
6.1
First published (updated )

Quarkus QuarkusQuarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET o…

Risk 72
Severity
7.5
First published (updated )

Quarkus QuarkusCode Injection

Risk 89
Severity
9.8
First published (updated )

redhat/candlepinIn FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur …

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/eap7-jackson-databindIn FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a ch…

Risk 46
Severity
7.5
First published (updated )

PostgreSQL PostgreSQL JDBC driverUnchecked Class Instantiation when providing Plugin Classes

Risk 88
Severity
9.8
First published (updated )

IBM Data Virtualization on Cloud Pak for DataAn unspecified vulnerability in Oracle MySQL Connectors related to the Connector/J component could …

Risk 63
Severity
6.6
First published (updated )

redhat/rh-sso7-keycloakHTTP fails to validate against control chars in header names which may lead to HTTP request smuggling

Risk 39
Severity
6.5
First published (updated )

Quarkus QuarkusMySQL Connector/J has no security check when external general entities are included in XML sources, …

Risk 57
Severity
7.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Oracle Financial Services Enterprise Case ManagementTiming Attack Vulnerability for Apache Kafka Connect and Clients

Risk 37
Severity
5.9
First published (updated )

Oracle Banking Digital ExperienceLast updated 24 July 2024

Risk 45
Severity
7.5
First published (updated )

Oracle Banking Digital ExperienceLast updated 24 July 2024

Risk 45
Severity
7.5
First published (updated )

redhat/eap7-apache-cxfCrafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptions

Risk 45
Severity
7.5
First published (updated )

redhat/eap7-wildfly-elytronA flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled…

Risk 33
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Cloud Pak for Business Automationblock repositories using http by default

Risk 69
Severity
9.1
First published (updated )

redhat/eap7-apache-commons-ioInput Validation

Risk 45
Severity
7.5
First published (updated )

redhat/eap7-elytron-webPossible request smuggling in HTTP/2 due missing validation of content-length

Risk 37
Severity
5.9
First published (updated )

redhat/eap7-nettyPossible request smuggling in HTTP/2 due missing validation

Risk 39
Severity
6.5
First published (updated )

redhat/eap7-resteasyLast updated 24 July 2024

Risk 28
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fasterxml jackson-dataformats-binaryDenial of Service (DoS)

Risk 45
Severity
7.5
First published (updated )

maven/org.mongodb:mongodb-driver-legacyMongoDB Java driver client-side field level encryption not verifying KMS host name

Risk 55
Severity
6.8
First published (updated )

redhat/eap7-artemis-wildfly-integrationLocal Information Disclosure Vulnerability in Netty on Unix-Like systems due temporary files

Risk 37
Severity
6.2
First published (updated )

Oracle Primavera UnifierInput Validation

Risk 28
Severity
5.3
First published (updated )

redhat/eap7-hibernateSQL Injection

Risk 59
Severity
7.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203