Vulnerabilities

Summary — last 7 days

New vulnerabilities2,757▲ 47 vs. last week
Critical / high1,482▲ 372 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (4.3)0.39%—Cdata API Server9/2/20256/17/2026
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the usage of MySQL…
DeferredCritical (9.8)8.1%—Cdata API ServerAIEclipse JettyAI4/5/20246/17/2026
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
ModifiedMedium (5)2.4%—Spumko Project Hapi Server Framework5/16/20146/17/2026
The hapi server framework 2.0.x and 2.1.x before 2.2.0 for Node.js allows remote attackers to cause a denial of service (file descriptor consumption and process crash) via unspecified vectors.