Vulnerabilities

Summary — last 7 days

New vulnerabilities3,069▲ 549 vs. last week
Critical / high1,455▲ 270 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)383▲ 176 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)1.4%—Stleary Json-java10/12/20236/17/2026
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
AnalyzedHigh (7.5)0.97%—Stleary Json-javaHutool12/13/20226/17/2026
A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
ModifiedHigh (7.5)1.2%—HutoolStleary Json-java12/13/20226/17/2026
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.