debezium kayıtları
debezium üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-385 Covert Timing Channel1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2025-70974İstismar yok | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Javaalibaba · fastjson · CWE-829 | Kritik10,0 | — | %0,8 | 9 Oca 2026 |
37İzleyin | CVE-2025-14813İstismar yok | GOSTCTR implementation unable to process more than 255 blocks correctlylegion of the bouncy castle inc. · bc-java · CWE-327 | Kritik9,3 | — | %0,3 | 15 Nis 2026 |
36İzleyin | CVE-2026-27830İstismar yok | c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString propertyswaldman · c3p0 · CWE-94 | Yüksek8,9 | — | %2,2 | 25 Şub 2026 |
35İzleyin | CVE-2026-5598İstismar yok | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | Yüksek8,9 | — | %1,0 | 15 Nis 2026 |
30İzleyin | CVE-2026-40984İstismar yok | Micrometer HTTP server instrumentations DoS vulnerabilityspring · micrometer · CWE-400 | Yüksek7,5 | — | %1,1 | 9 Haz 2026 |
30İzleyin | CVE-2026-40983İstismar yok | Micrometer gRPC server instrumentation DoS vulnerabilityspring · micrometer · CWE-400 | Yüksek7,5 | — | %0,8 | 9 Haz 2026 |
25İzleyin | CVE-2026-5588İstismar yok | PKIX draft CompositeVerifier accepts empty signature sequence as valid.legion of the bouncy castle inc. · bc-java · CWE-327 | Orta6,3 | — | %0,7 | 15 Nis 2026 |
22İzleyin | CVE-2026-0636İstismar yok | LDAP Injection Vulnerability in LDAPStoreHelper.javalegion of the bouncy castle inc. · bc-java · CWE-90 | Orta5,5 | — | %0,5 | 15 Nis 2026 |
- CVE-2025-7097440Planlayın
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java
KritikCVSS 10,0İstismar yokEPSS %1alibaba · fastjson9 Oca 2026
- CVE-2025-1481337İzleyin
GOSTCTR implementation unable to process more than 255 blocks correctly
KritikCVSS 9,3İstismar yokEPSS %0legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-2783036İzleyin
c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
YüksekCVSS 8,9İstismar yokEPSS %2swaldman · c3p025 Şub 2026
- CVE-2026-559835İzleyin
Non-constant time comparisons risk private key leakage in FrodoKEM.
YüksekCVSS 8,9İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-4098430İzleyin
Micrometer HTTP server instrumentations DoS vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1spring · micrometer9 Haz 2026
- CVE-2026-4098330İzleyin
Micrometer gRPC server instrumentation DoS vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1spring · micrometer9 Haz 2026
- CVE-2026-558825İzleyin
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
OrtaCVSS 6,3İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2026-063622İzleyin
LDAP Injection Vulnerability in LDAPStoreHelper.java
OrtaCVSS 5,5İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026