Skip to content
Noroxi

h2database records

6 published records for vendor h2database.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 16.7%
Pre-auth RCE
2
With a fix record
83.3%
Median publish → KEV
No record has entered KEV

All records

6 records
  • CVE-2021-42392
    64This week

    The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database.

    CriticalCVSS 9.8Proof of conceptEPSS 83%

    h2database · h2Jan 10, 2022

  • H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING

    CriticalCVSS 9.8Proof of conceptEPSS 65%

    h2database · h2Jan 19, 2022

  • H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary J

    HighCVSS 8.8WeaponizedEPSS 34%

    cognitect · datomicApr 11, 2018

  • XML External Entity (XXE) Injection

    CriticalCVSS 9.1No exploitEPSS 3%

    h2database · h2Dec 10, 2021

  • The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allow

    HighCVSS 7.8No exploitEPSS 0%

    h2database · h2Nov 23, 2022

  • An issue was discovered in H2 1.4.197.

    MediumCVSS 6.5Proof of conceptEPSS 13%

    h2database · h2Jul 24, 2018