Vulnerabilities

Last updated 3 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
org.apache.logging.log4j:log4j-core Incomplete fix for Apache Log4j vulnerability Critical 9.0 4 years ago 6 hours ago
org.apache.logging.log4j:log4j-layout-template-json Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout Medium Risk 6.0 5 months ago 22 days ago
org.apache.logging.log4j:log4j-1.2-api Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters Medium Risk 6.0 5 months ago 22 days ago
org.apache.logging.log4j:log4j-api Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization Medium Risk 6.0 2 months ago 22 days ago
org.apache.logging.log4j:log4j-core Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration Medium Risk 6.0 5 months ago 22 days ago
org.apache.logging.log4j:log4j-core Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters Medium Risk 6.0 5 months ago 22 days ago
org.apache.logging.log4j:log4j-core Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility Medium Risk 6.0 5 months ago 22 days ago
org.apache.logging.log4j:log4j-core Apache Log4j does not verify the TLS hostname in its Socket Appender Medium Risk 6.0 9 months ago 22 days ago
org.apache.logging.log4j:log4j-core Improper Input Validation and Injection in Apache Log4j2 Medium Risk 6.6 4 years ago 3 months ago
org.apache.logging.log4j:log4j Improper validation of certificate with host mismatch in Apache Log4j SMTP appender Low Risk 3.7 6 years ago 3 months ago
org.apache.logging.log4j:log4j-core Improper validation of certificate with host mismatch in Apache Log4j SMTP appender Low Risk 3.7 6 years ago 3 months ago
log4j:log4j Deserialization of Untrusted Data in Log4j Critical 9.8 6 years ago 3 months ago
org.apache.logging.log4j:log4j-core Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion High Risk 8.6 4 years ago 3 months ago
log4j:log4j SQL Injection in Log4j 1.2.x Critical 9.8 4 years ago 3 months ago
org.apache.logging.log4j:log4j-core Remote code injection in Log4j Critical 10.0 4 years ago 11 months ago
uk.co.nichesolutions.logging.log4j:log4j-core Remote code injection in Log4j Critical 10.0 4 years ago 11 months ago
log4j:log4j Apache Log4j 1.x (EOL) allows Denial of Service (DoS) High Risk 7.5 3 years ago 1 year ago
org.apache.logging.log4j:log4j-core Apache Log4j 1.x (EOL) allows Denial of Service (DoS) High Risk 7.5 3 years ago 1 year ago
log4j:log4j Deserialization of Untrusted Data in Log4j 1.x High Risk 8.8 4 years ago 1 year ago
org.apache.logging.log4j:log4j Deserialization of Untrusted Data in Log4j Critical 9.8 6 years ago 2 years ago
org.apache.logging.log4j:log4j-core Deserialization of Untrusted Data in Log4j Critical 9.8 6 years ago 2 years ago
log4j:log4j Deserialization of Untrusted Data in Apache Log4j Critical 9.8 4 years ago 2 years ago
log4j:log4j JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data High Risk 7.5 4 years ago 2 years ago