Vulnerabilities

Summary — last 7 days

New vulnerabilities2,535▼ 358 vs. last week
Critical / high1,338▲ 66 vs. last week
New active exploitation (KEV)6▼ 6 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.8)3.2%—Apache Java Chassis1/25/20216/17/2026
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5