Security Deep Dive
CloudStack
Security posture and CVE patch evidence from tracked releases.
9 actively-exploited dependency CVEs affects 4.22.1.0.
KEV-listed CVEs are confirmed exploited in the wild — patch urgently.
Versions by Severity
CVEs are attributed to tracked releases published before the patch release.
| Version | Published | C | H | M | L | KEV | Notes |
|---|---|---|---|---|---|---|---|
| 4.22.1.0 | 2026-05-26 | — | — | — | — | — |
Latest
|
| 4.22.0.1 | 2026-05-08 | — | — | — | — | — |
Patches
CVE-2017-12615
Patches
CVE-2017-12617
Patches
CVE-2020-1938
Patches
CVE-2021-39144
Patches
CVE-2021-44228
Patches
CVE-2021-45046
Patches
CVE-2022-22965
Patches
CVE-2023-44487
Patches
CVE-2025-24813
|
| 4.20.3.0 | 2026-04-17 | 5 | 4 | — | — | KEV 9 |
—
|
| 4.22.0.0 | 2025-11-11 | 5 | 4 | — | — | KEV 9 |
—
|
| 4.20.2.0 | 2025-10-27 | 5 | 4 | — | — | KEV 9 |
—
|
| 4.21.0.0 | 2025-08-29 | 5 | 4 | — | — | KEV 9 |
—
|
| 4.20.1.0 | 2025-06-10 | 5 | 4 | — | — | KEV 9 |
—
|
| 4.19.3.0 | 2025-06-10 | 5 | 4 | — | — | KEV 9 |
—
|
Trust Signals — 2 of 9 Present
Evidence already collected from releases and repository metadata.
Security Score
A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.
epss
0.00 / 0.5
Max EPSS 0.945
freshness
1.00 / 1.0
4d stale
scorecard
2.80 / 4.0
Score 7.0/10
cve health
0.00 / 2.5
No open CVEs
patch speed
0.50 / 0.5
⚠ Estimated — no CVE patch history
kev exposure
-1.50 / 1.5
KEV exposure detected
supply chain risk
-1.50 / 10.0
Risk 100.0/100
Score breakdown
schema v2Vulnerability posture
vulnerability posture
0.0
25%
Release responsiveness
release responsiveness
10.0
5%
Dependency exposure
dependency exposure
0.0
10%
Provenance trust
provenance trust
7.0
40%
Maintainer health
maintainer health
10.0
10%
Operational risk
operational risk
0.0
10%
How is this calculated?
The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.
Supply Chain Risk
Risk 100.0/100Scorecard
Scorecard 7.0/10OpenSSF Scorecard evaluates supply-chain security practices automatically. Score ≥ 6 is passing; ≥ 8 is excellent.
| Check | Score | Reason |
|---|---|---|
| Maintained | 10 | 30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10 |
| Code-Review | 8 | Found 24/30 approved changesets -- score normalized to 8 |
| Dangerous-Workflow | 10 | no dangerous workflow patterns detected |
| Token-Permissions | 8 | detected GitHub workflow tokens with excessive permissions |
| CII-Best-Practices | 2 | badge detected: InProgress |
| License | 10 | license file detected |
| Signed-Releases | -1 | no releases found |
| Security-Policy | 10 | security policy file detected |
| Binary-Artifacts | 8 | binaries present in source code |
| Branch-Protection | 0 | branch protection not enabled on development/release branches |
| Packaging | 10 | packaging workflow detected |
| Fuzzing | 0 | project is not fuzzed |
| Pinned-Dependencies | 2 | dependency not pinned by hash detected -- score normalized to 2 |
| SAST | 10 | SAST tool detected |
CVE Patch History
Tracks CVEs that were addressed in tagged releases. Shorter gap between disclosure and patch = faster response. EPSS = predicted probability of exploitation in next 30 days (FIRST.org); colored at ≥90%ile and ≥50%ile.
CVEs Patched by Year
| CVE | Severity | EPSS | Disclosed | Fixed in | Days to fix | vs Ecosystem Median | KEV |
|---|---|---|---|---|---|---|---|
| CVE-2017-12615 | HIGH | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2017-12617 | HIGH | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2020-1938 | CRITICAL | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2021-39144 | HIGH | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2021-44228 | CRITICAL | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2021-45046 | CRITICAL | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2022-22965 | CRITICAL | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2023-44487 | HIGH | 99%ile | — | 4.22.0.1 | — | — | KEV |
| CVE-2025-24813 | CRITICAL | 99%ile | — | 4.22.0.1 | — | — | KEV |
KEV = CISA Known Exploited Vulnerabilities catalog — actively exploited in the wild.
Dependency Vulnerabilities
Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.
Critical
67
High
226
Medium
207
Low
0
Unknown
0
9 dependency vulnerabilities are in KEV.
CISA confirmed these vulnerabilities are actively exploited. Treat as critical priority.
| CVE | Severity | KEV | Dependency | Affected version | Cleared in release |
|---|---|---|---|---|---|
| CVE-2013-4366 | critical | — | org.apache.httpcomponents:httpclient | — | 4.22.0.1 |
| CVE-2013-7285 | critical | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2015-3253 | critical | — | org.codehaus.groovy:groovy-all | — | 4.22.0.1 |
| CVE-2015-7501 | critical | — | org.apache.commons:commons-collections4 | — | 4.22.0.1 |
| CVE-2016-1000027 | critical | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2016-3720 | critical | — | com.fasterxml.jackson.dataformat:jackson-dataformat-xml | — | 4.22.0.1 |
| CVE-2016-4800 | critical | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2016-6814 | critical | — | org.codehaus.groovy:groovy-all | — | 4.22.0.1 |
| CVE-2017-15095 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2017-17485 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2017-5645 | critical | — | org.apache.logging.log4j:log4j-core | — | 4.22.0.1 |
| CVE-2017-5648 | critical | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2017-5651 | critical | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2017-7525 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2017-7657 | critical | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2017-7658 | critical | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2018-1000613 | critical | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2018-11307 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-1285 | critical | — | log4net | 2.0.0 | 4.22.0.1 |
| CVE-2018-14718 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-14719 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-14720 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-14721 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-19360 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-19361 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-19362 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-20060 | critical | — | urllib3 | — | 4.22.0.1 |
| CVE-2018-7489 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-7750 | critical | — | paramiko | 1.13.0 | 4.22.0.1 |
| CVE-2018-8014 | critical | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-10173 | critical | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2019-14379 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-14540 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-16335 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-16942 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-16943 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-17267 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-17531 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-17638 | critical | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2019-20330 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-1938 | critical | KEV | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.1.0 |
| CVE-2020-26238 | critical | — | com.cronutils:cron-utils | — | 4.22.0.1 |
| CVE-2020-8840 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-9546 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-9547 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-9548 | critical | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2021-3918 | critical | — | json-schema | 0.2.3 | 4.22.0.1 |
| CVE-2021-41269 | critical | — | com.cronutils:cron-utils | — | 4.22.0.1 |
| CVE-2021-44228 | critical | KEV | org.apache.logging.log4j:log4j-core | — | 4.22.1.0 |
| CVE-2021-44906 | critical | — | minimist | 1.2.5 | 4.22.0.1 |
| CVE-2021-45046 | critical | KEV | org.apache.logging.log4j:log4j-core | — | 4.22.1.0 |
| CVE-2022-22965 | critical | KEV | org.springframework:spring-beans | — | 4.22.1.0 |
| CVE-2022-29078 | critical | — | ejs | 2.7.4 | 4.22.0.1 |
| CVE-2022-37601 | critical | — | loader-utils | 2.0.2 | 4.22.0.1 |
| CVE-2023-45133 | critical | — | @babel/traverse | 7.18.6 | 4.22.0.1 |
| CVE-2023-45133 | critical | — | babel-traverse | 6.26.0 | 4.22.0.1 |
| CVE-2025-12383 | critical | — | org.glassfish.jersey.core:jersey-client | — | 4.22.0.1 |
| CVE-2025-24813 | critical | KEV | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.1.0 |
| CVE-2025-6545 | critical | — | pbkdf2 | 3.1.2 | 4.22.0.1 |
| CVE-2025-6547 | critical | — | pbkdf2 | 3.1.2 | 4.22.0.1 |
| CVE-2025-7783 | critical | — | form-data | 2.3.3 | 4.22.0.1 |
| CVE-2025-9287 | critical | — | cipher-base | 1.0.4 | 4.22.0.1 |
| CVE-2025-9288 | critical | — | sha.js | 2.4.11 | 4.22.0.1 |
| CVE-2026-25896 | critical | — | fast-xml-parser | 4.3.0 | 4.22.0.1 |
| CVE-2026-29145 | critical | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-33557 | critical | — | org.apache.kafka:kafka-clients | — | 4.22.0.1 |
| GHSA-vjh7-7g9h-fjfh | critical | — | elliptic | 6.5.4 | 4.22.0.1 |
| CVE-2006-0847 | high | — | cherrypy | — | 4.22.0.1 |
| CVE-2008-0252 | high | — | cherrypy | — | 4.22.0.1 |
| CVE-2010-2076 | high | — | org.apache.cxf:cxf-rt-frontend-jaxrs | — | 4.22.0.1 |
| CVE-2012-0881 | high | — | xerces:xercesImpl | — | 4.22.0.1 |
| CVE-2012-6153 | high | — | org.apache.httpcomponents:httpclient | — | 4.22.0.1 |
| CVE-2013-4002 | high | — | xerces:xercesImpl | — | 4.22.0.1 |
| CVE-2014-9970 | high | — | org.jasypt:jasypt | — | 4.22.0.1 |
| CVE-2015-2080 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2015-6420 | high | — | org.apache.commons:commons-collections4 | — | 4.22.0.1 |
| CVE-2016-1000338 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000340 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000342 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000343 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000344 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000352 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-3674 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2016-7051 | high | — | com.fasterxml.jackson.dataformat:jackson-dataformat-xml | — | 4.22.0.1 |
| CVE-2017-12615 | high | KEV | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.1.0 |
| CVE-2017-12617 | high | KEV | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.1.0 |
| CVE-2017-7656 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2017-7957 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2017-9735 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2018-1000180 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2018-1000805 | high | — | paramiko | 1.13.0 | 4.22.0.1 |
| CVE-2018-12022 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-12023 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-12538 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2018-12545 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2018-1336 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2018-18074 | high | — | requests | 2.2.1 | 4.22.0.1 |
| CVE-2018-5968 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2018-8034 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-0199 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-0232 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-10072 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-11324 | high | — | urllib3 | — | 4.22.0.1 |
| CVE-2019-12086 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-12402 | high | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2019-12418 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-14439 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-14892 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-14893 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-17563 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2020-10650 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-10672 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-10673 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-10968 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-10969 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-11111 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-11112 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-11113 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-11619 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-11620 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-14060 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-14061 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-14062 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-14195 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-24616 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-24750 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-25649 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-26217 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2020-27216 | high | — | org.eclipse.jetty:jetty-webapp | — | 4.22.0.1 |
| CVE-2020-28052 | high | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2020-28491 | high | — | com.fasterxml.jackson.dataformat:jackson-dataformat-cbor | — | 4.22.0.1 |
| CVE-2020-28499 | high | — | merge | 1.2.1 | 4.22.0.1 |
| CVE-2020-35490 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-35491 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-35728 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36179 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36180 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36181 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36182 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36183 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36184 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36185 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36186 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36187 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36188 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36189 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-36518 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2020-7212 | high | — | urllib3 | — | 4.22.0.1 |
| CVE-2020-7660 | high | — | serialize-javascript | 1.9.1 | 4.22.0.1 |
| CVE-2021-20190 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2021-21341 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-22118 | high | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2021-25122 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2021-25329 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2021-28165 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2021-29505 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-33503 | high | — | urllib3 | — | 4.22.0.1 |
| CVE-2021-35515 | high | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2021-35516 | high | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2021-35517 | high | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2021-36090 | high | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2021-3803 | high | — | nth-check | 1.0.2 | 4.22.0.1 |
| CVE-2021-39139 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39141 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39144 | high | KEV | com.thoughtworks.xstream:xstream | — | 4.22.1.0 |
| CVE-2021-39145 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39146 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39147 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39148 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39149 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39150 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39151 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39152 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39153 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-39154 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-43859 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-45105 | high | — | org.apache.logging.log4j:log4j-core | — | 4.22.0.1 |
| CVE-2021-46877 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2022-2191 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2022-22968 | high | — | org.springframework:spring-context | — | 4.22.0.1 |
| CVE-2022-22970 | high | — | org.springframework:spring-beans | — | 4.22.0.1 |
| CVE-2022-23457 | high | — | org.owasp.esapi:esapi | 2.1.0.1 | 4.22.0.1 |
| CVE-2022-24434 | high | — | dicer | 0.3.0 | 4.22.0.1 |
| CVE-2022-24771 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2022-24772 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2022-24999 | high | — | qs | 6.5.2 | 4.22.0.1 |
| CVE-2022-25647 | high | — | com.google.code.gson:gson | — | 4.22.0.1 |
| CVE-2022-25858 | high | — | terser | 4.8.0 | 4.22.0.1 |
| CVE-2022-25881 | high | — | http-cache-semantics | 4.1.0 | 4.22.0.1 |
| CVE-2022-25883 | high | — | semver | 7.0.0 | 4.22.0.1 |
| CVE-2022-25900 | high | — | git-clone | 0.1.0 | 4.22.0.1 |
| CVE-2022-31129 | high | — | moment | 2.29.3 | 4.22.0.1 |
| CVE-2022-31159 | high | — | com.amazonaws:aws-java-sdk-s3 | — | 4.22.0.1 |
| CVE-2022-3517 | high | — | minimatch | 3.0.4 | 4.22.0.1 |
| CVE-2022-37599 | high | — | loader-utils | 2.0.2 | 4.22.0.1 |
| CVE-2022-37603 | high | — | loader-utils | 2.0.2 | 4.22.0.1 |
| CVE-2022-37620 | high | — | html-minifier | 3.5.21 | 4.22.0.1 |
| CVE-2022-38900 | high | — | decode-uri-component | 0.2.0 | 4.22.0.1 |
| CVE-2022-40151 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2022-4065 | high | — | org.testng:testng | 7.1.0 | 4.22.0.1 |
| CVE-2022-40897 | high | — | setuptools | 40.3.0 | 4.22.0.1 |
| CVE-2022-41404 | high | — | org.ini4j:ini4j | — | 4.22.0.1 |
| CVE-2022-41966 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2022-42003 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2022-42004 | high | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2022-42252 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2022-45143 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2022-45688 | high | — | org.json:json | — | 4.22.0.1 |
| CVE-2022-46175 | high | — | json5 | 0.5.1 | 4.22.0.1 |
| CVE-2023-22102 | high | — | com.mysql:mysql-connector-j | — | 4.22.0.1 |
| CVE-2023-24998 | high | — | commons-fileupload:commons-fileupload | 1.4 | 4.22.0.1 |
| CVE-2023-24998 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2023-26464 | high | — | org.apache.logging.log4j:log4j-core | — | 4.22.0.1 |
| CVE-2023-28709 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2023-34981 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2023-43804 | high | — | urllib3 | — | 4.22.0.1 |
| CVE-2023-46234 | high | — | browserify-sign | 4.2.1 | 4.22.0.1 |
| CVE-2023-46589 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2023-5072 | high | — | org.json:json | — | 4.22.0.1 |
| CVE-2024-13009 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2024-21272 | high | — | mysql-connector-python | 8.0.30 | 4.22.0.1 |
| CVE-2024-21536 | high | — | http-proxy-middleware | 0.19.1 | 4.22.0.1 |
| CVE-2024-21538 | high | — | cross-spawn | 6.0.5 | 4.22.0.1 |
| CVE-2024-21907 | high | — | Newtonsoft.Json | 4.5.11 | 4.22.0.1 |
| CVE-2024-22243 | high | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2024-22259 | high | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2024-22262 | high | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2024-29180 | high | — | webpack-dev-middleware | 3.7.3 | 4.22.0.1 |
| CVE-2024-29415 | high | — | ip | 1.1.8 | 4.22.0.1 |
| CVE-2024-34750 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2024-37890 | high | — | ws | 5.2.3 | 4.22.0.1 |
| CVE-2024-4068 | high | — | braces | 2.3.2 | 4.22.0.1 |
| CVE-2024-45296 | high | — | path-to-regexp | 0.1.7 | 4.22.0.1 |
| CVE-2024-45590 | high | — | body-parser | 1.20.0 | 4.22.0.1 |
| CVE-2024-47072 | high | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2024-47554 | high | — | commons-io:commons-io | — | 4.22.0.1 |
| CVE-2024-50379 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2024-52798 | high | — | path-to-regexp | 0.1.7 | 4.22.0.1 |
| CVE-2024-56337 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2024-6345 | high | — | setuptools | 40.3.0 | 4.22.0.1 |
| CVE-2025-12816 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2025-25975 | high | — | parse-git-config | 2.0.3 | 4.22.0.1 |
| CVE-2025-27152 | high | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2025-27597 | high | — | vue-i18n | 9.2.2 | 4.22.0.1 |
| CVE-2025-47273 | high | — | setuptools | 40.3.0 | 4.22.0.1 |
| CVE-2025-48976 | high | — | commons-fileupload:commons-fileupload | 1.4 | 4.22.0.1 |
| CVE-2025-48988 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-48989 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-52520 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-52999 | high | — | com.fasterxml.jackson.core:jackson-core | 2.13.3 | 4.22.0.1 |
| CVE-2025-53506 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-55752 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-59952 | high | — | io.minio:minio | 8.5.2 | 4.22.0.1 |
| CVE-2025-66031 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2025-66418 | high | — | urllib3 | — | 4.22.0.1 |
| CVE-2025-66471 | high | — | urllib3 | — | 4.22.0.1 |
| CVE-2026-1605 | high | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2026-21441 | high | — | urllib3 | — | 4.22.0.1 |
| CVE-2026-23745 | high | — | tar | 6.1.11 | 4.22.0.1 |
| CVE-2026-23950 | high | — | tar | 6.1.11 | 4.22.0.1 |
| CVE-2026-24400 | high | — | org.assertj:assertj-core | — | 4.22.0.1 |
| CVE-2026-24734 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-24842 | high | — | tar | 6.1.11 | 4.22.0.1 |
| CVE-2026-25639 | high | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-26278 | high | — | fast-xml-parser | 4.3.0 | 4.22.0.1 |
| CVE-2026-26960 | high | — | tar | 6.1.11 | 4.22.0.1 |
| CVE-2026-26996 | high | — | minimatch | 3.0.4 | 4.22.0.1 |
| CVE-2026-27903 | high | — | minimatch | 3.0.4 | 4.22.0.1 |
| CVE-2026-27904 | high | — | minimatch | 3.0.4 | 4.22.0.1 |
| CVE-2026-29063 | high | — | immutable | 4.1.0 | 4.22.0.1 |
| CVE-2026-29129 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-29786 | high | — | tar | 6.1.11 | 4.22.0.1 |
| CVE-2026-31802 | high | — | tar | 6.1.11 | 4.22.0.1 |
| CVE-2026-32141 | high | — | flatted | 2.0.2 | 4.22.0.1 |
| CVE-2026-33036 | high | — | fast-xml-parser | 4.3.0 | 4.22.0.1 |
| CVE-2026-33228 | high | — | flatted | 2.0.2 | 4.22.0.1 |
| CVE-2026-33671 | high | — | picomatch | 2.3.1 | 4.22.0.1 |
| CVE-2026-33891 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2026-33894 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2026-33895 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2026-33896 | high | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2026-34483 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-34487 | high | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-35554 | high | — | org.apache.kafka:kafka-clients | — | 4.22.0.1 |
| CVE-2026-42033 | high | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-42035 | high | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-42043 | high | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-44728 | high | — | @babel/plugin-transform-modules-systemjs | 7.18.6 | 4.22.0.1 |
| CVE-2026-4800 | high | — | lodash-es | 4.17.21 | 4.22.0.1 |
| CVE-2026-4800 | high | — | lodash | 4.17.21 | 4.22.0.1 |
| CVE-2026-4867 | high | — | path-to-regexp | 0.1.7 | 4.22.0.1 |
| GHSA-5c6j-r48x-rmvq | high | — | serialize-javascript | 4.0.0 | 4.22.0.1 |
| GHSA-7c2q-5qmr-v76q | high | — | org.owasp.esapi:esapi | 2.1.0.1 | 4.22.0.1 |
| CVE-2006-6969 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2008-1947 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2009-2625 | medium | — | xerces:xercesImpl | — | 4.22.0.1 |
| CVE-2010-3300 | medium | — | org.owasp.esapi:esapi | — | 4.22.0.1 |
| CVE-2011-1411 | medium | — | org.opensaml:opensaml | — | 4.22.0.1 |
| CVE-2011-1498 | medium | — | org.apache.httpcomponents:httpclient | — | 4.22.0.1 |
| CVE-2011-4461 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2012-2098 | medium | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2012-4418 | medium | — | org.apache.axis2:axis2 | 1.6.4 | 4.22.0.1 |
| CVE-2012-5785 | medium | — | org.apache.axis2:axis2 | 1.6.4 | 4.22.0.1 |
| CVE-2013-0239 | medium | — | org.apache.cxf:cxf-rt-frontend-jaxrs | — | 4.22.0.1 |
| CVE-2013-1624 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2013-2160 | medium | — | org.apache.cxf:cxf-rt-frontend-jaxrs | — | 4.22.0.1 |
| CVE-2013-5960 | medium | — | org.owasp.esapi:esapi | — | 4.22.0.1 |
| CVE-2013-6429 | medium | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2013-6430 | medium | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2013-6440 | medium | — | org.opensaml:opensaml | — | 4.22.0.1 |
| CVE-2014-0095 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2014-1829 | medium | — | requests | 2.2.1 | 4.22.0.1 |
| CVE-2014-1830 | medium | — | requests | 2.2.1 | 4.22.0.1 |
| CVE-2014-3577 | medium | — | org.apache.httpcomponents:httpclient | — | 4.22.0.1 |
| CVE-2014-3584 | medium | — | org.apache.cxf:cxf-rt-frontend-jaxrs | — | 4.22.0.1 |
| CVE-2014-3603 | medium | — | org.opensaml:opensaml | — | 4.22.0.1 |
| CVE-2015-1796 | medium | — | org.opensaml:opensaml | — | 4.22.0.1 |
| CVE-2015-2296 | medium | — | requests | 2.2.1 | 4.22.0.1 |
| CVE-2015-3192 | medium | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2015-5262 | medium | — | org.apache.httpcomponents:httpclient | — | 4.22.0.1 |
| CVE-2015-7940 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000339 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000341 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-1000345 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2016-5004 | medium | — | org.apache.xmlrpc:xmlrpc-common | — | 4.22.0.1 |
| CVE-2016-5725 | medium | — | com.jcraft:jsch | — | 4.22.0.1 |
| CVE-2016-9015 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2017-12610 | medium | — | org.apache.kafka:kafka-clients | — | 4.22.0.1 |
| CVE-2017-13098 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2018-1000873 | medium | — | com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | — | 4.22.0.1 |
| CVE-2018-1002205 | medium | — | DotNetZip | 1.9.1.8 | 4.22.0.1 |
| CVE-2018-10237 | medium | — | com.google.guava:guava | — | 4.22.0.1 |
| CVE-2018-11039 | medium | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2018-11087 | medium | — | com.rabbitmq:amqp-client | — | 4.22.0.1 |
| CVE-2018-11771 | medium | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2018-11784 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2018-12536 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2018-1304 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2018-1305 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2018-1324 | medium | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2018-25091 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2018-5382 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2018-8037 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-0221 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-10241 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2019-10246 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2019-10247 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2019-10782 | medium | — | com.puppycrawl.tools:checkstyle | 8.18 | 4.22.0.1 |
| CVE-2019-11236 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2019-12384 | medium | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-12814 | medium | — | com.fasterxml.jackson.core:jackson-databind | — | 4.22.0.1 |
| CVE-2019-16769 | medium | — | serialize-javascript | 1.9.1 | 4.22.0.1 |
| CVE-2019-17569 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2019-17632 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2020-13956 | medium | — | org.apache.httpcomponents:httpclient | — | 4.22.0.1 |
| CVE-2020-14338 | medium | — | xerces:xercesImpl | — | 4.22.0.1 |
| CVE-2020-15250 | medium | — | junit:junit | — | 4.22.0.1 |
| CVE-2020-15366 | medium | — | ajv | 6.6.2 | 4.22.0.1 |
| CVE-2020-15522 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2020-17521 | medium | — | org.codehaus.groovy:groovy-all | — | 4.22.0.1 |
| CVE-2020-1935 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2020-26137 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2020-26258 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2020-26259 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2020-26939 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2020-27218 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2020-27223 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2020-7608 | medium | — | yargs-parser | 10.1.0 | 4.22.0.1 |
| CVE-2020-7789 | medium | — | node-notifier | 5.4.5 | 4.22.0.1 |
| CVE-2020-8929 | medium | — | com.google.crypto.tink:tink | — | 4.22.0.1 |
| CVE-2021-21342 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21343 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21344 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21345 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21346 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21347 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21348 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21349 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21350 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-21351 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-23382 | medium | — | postcss | 6.0.23 | 4.22.0.1 |
| CVE-2021-24122 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2021-28164 | medium | — | org.eclipse.jetty:jetty-webapp | — | 4.22.0.1 |
| CVE-2021-28169 | medium | — | org.eclipse.jetty:jetty-servlets | — | 4.22.0.1 |
| CVE-2021-28363 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2021-29425 | medium | — | commons-io:commons-io | — | 4.22.0.1 |
| CVE-2021-34429 | medium | — | org.eclipse.jetty:jetty-webapp | — | 4.22.0.1 |
| CVE-2021-37533 | medium | — | commons-net:commons-net | 3.7.2 | 4.22.0.1 |
| CVE-2021-38153 | medium | — | org.apache.kafka:kafka-clients | 2.7.0 | 4.22.0.1 |
| CVE-2021-39140 | medium | — | com.thoughtworks.xstream:xstream | — | 4.22.0.1 |
| CVE-2021-44832 | medium | — | org.apache.logging.log4j:log4j-core | — | 4.22.0.1 |
| CVE-2022-0122 | medium | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2022-23437 | medium | — | xerces:xercesImpl | — | 4.22.0.1 |
| CVE-2022-24773 | medium | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2022-24891 | medium | — | org.owasp.esapi:esapi | 2.1.0.1 | 4.22.0.1 |
| CVE-2022-33987 | medium | — | got | 8.3.2 | 4.22.0.1 |
| CVE-2023-0842 | medium | — | xml2js | 0.4.23 | 4.22.0.1 |
| CVE-2023-26048 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2023-26115 | medium | — | word-wrap | 1.2.3 | 4.22.0.1 |
| CVE-2023-26136 | medium | — | tough-cookie | 3.0.1 | 4.22.0.1 |
| CVE-2023-26159 | medium | — | follow-redirects | 1.15.1 | 4.22.0.1 |
| CVE-2023-28155 | medium | — | request | 2.88.2 | 4.22.0.1 |
| CVE-2023-29483 | medium | — | dnspython | — | 4.22.0.1 |
| CVE-2023-2976 | medium | — | com.google.guava:guava | — | 4.22.0.1 |
| CVE-2023-33201 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2023-33202 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2023-41080 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2023-42503 | medium | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2023-42795 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2023-44270 | medium | — | postcss | 8.4.14 | 4.22.0.1 |
| CVE-2023-44487 | medium | KEV | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.1.0 |
| CVE-2023-45648 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2023-45803 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2023-45857 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2023-46120 | medium | — | com.rabbitmq:amqp-client | — | 4.22.0.1 |
| CVE-2024-21733 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2024-24549 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2024-25710 | medium | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2024-26308 | medium | — | org.apache.commons:commons-compress | — | 4.22.0.1 |
| CVE-2024-28849 | medium | — | follow-redirects | 1.15.1 | 4.22.0.1 |
| CVE-2024-28863 | medium | — | tar | 6.1.11 | 4.22.0.1 |
| CVE-2024-29041 | medium | — | express | 4.18.1 | 4.22.0.1 |
| CVE-2024-29857 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2024-30171 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2024-31141 | medium | — | org.apache.kafka:kafka-clients | 2.7.0 | 4.22.0.1 |
| CVE-2024-33883 | medium | — | ejs | 2.7.4 | 4.22.0.1 |
| CVE-2024-34447 | medium | — | org.bouncycastle:bcprov-jdk15on | — | 4.22.0.1 |
| CVE-2024-35195 | medium | — | requests | 2.2.1 | 4.22.0.1 |
| CVE-2024-37891 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2024-38809 | medium | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2024-38820 | medium | — | org.springframework:spring-context | — | 4.22.0.1 |
| CVE-2024-38820 | medium | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2024-4067 | medium | — | micromatch | 3.1.10 | 4.22.0.1 |
| CVE-2024-47081 | medium | — | requests | 2.2.1 | 4.22.0.1 |
| CVE-2024-52317 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2024-53382 | medium | — | prismjs | 1.28.0 | 4.22.0.1 |
| CVE-2024-55565 | medium | — | nanoid | 2.1.11 | 4.22.0.1 |
| CVE-2024-8184 | medium | — | org.eclipse.jetty:jetty-server | — | 4.22.0.1 |
| CVE-2024-9823 | medium | — | org.eclipse.jetty:jetty-servlets | — | 4.22.0.1 |
| CVE-2025-13465 | medium | — | lodash-es | 4.17.21 | 4.22.0.1 |
| CVE-2025-13465 | medium | — | lodash | 4.17.21 | 4.22.0.1 |
| CVE-2025-15284 | medium | — | qs | 6.5.3 | 4.22.0.1 |
| CVE-2025-15599 | medium | — | dompurify | 3.2.6 | 4.22.0.1 |
| CVE-2025-27789 | medium | — | @babel/helpers | 7.18.6 | 4.22.0.1 |
| CVE-2025-27789 | medium | — | @babel/runtime | 7.24.4 | 4.22.0.1 |
| CVE-2025-27817 | medium | — | org.apache.kafka:kafka-clients | — | 4.22.0.1 |
| CVE-2025-30359 | medium | — | webpack-dev-server | 3.11.3 | 4.22.0.1 |
| CVE-2025-30360 | medium | — | webpack-dev-server | 3.11.3 | 4.22.0.1 |
| CVE-2025-31650 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-32996 | medium | — | http-proxy-middleware | 1.3.1 | 4.22.0.1 |
| CVE-2025-32997 | medium | — | http-proxy-middleware | 1.3.1 | 4.22.0.1 |
| CVE-2025-41234 | medium | — | org.springframework:spring-web | — | 4.22.0.1 |
| CVE-2025-48924 | medium | — | commons-lang:commons-lang | — | 4.22.0.1 |
| CVE-2025-48924 | medium | — | org.apache.commons:commons-lang3 | — | 4.22.0.1 |
| CVE-2025-49124 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-49125 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-49128 | medium | — | com.fasterxml.jackson.core:jackson-core | — | 4.22.0.1 |
| CVE-2025-50181 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2025-50182 | medium | — | urllib3 | — | 4.22.0.1 |
| CVE-2025-53892 | medium | — | vue-i18n | 9.2.2 | 4.22.0.1 |
| CVE-2025-53892 | medium | — | @intlify/core-base | 9.2.2 | 4.22.0.1 |
| CVE-2025-62718 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2025-64718 | medium | — | js-yaml | 3.14.1 | 4.22.0.1 |
| CVE-2025-66030 | medium | — | node-forge | 0.10.0 | 4.22.0.1 |
| CVE-2025-66614 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2025-68161 | medium | — | org.apache.logging.log4j:log4j-core | 2.19.0 | 4.22.0.1 |
| CVE-2025-69873 | medium | — | ajv | 6.6.2 | 4.22.0.1 |
| CVE-2025-8916 | medium | — | org.bouncycastle:bcpkix-jdk15on | — | 4.22.0.1 |
| CVE-2026-0540 | medium | — | dompurify | 3.2.6 | 4.22.0.1 |
| CVE-2026-25645 | medium | — | requests | 2.2.1 | 4.22.0.1 |
| CVE-2026-25854 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-2739 | medium | — | bn.js | 5.2.1 | 4.22.0.1 |
| CVE-2026-2950 | medium | — | lodash | 4.17.21 | 4.22.0.1 |
| CVE-2026-2950 | medium | — | lodash-es | 4.17.21 | 4.22.0.1 |
| CVE-2026-32990 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-33349 | medium | — | fast-xml-parser | 4.3.0 | 4.22.0.1 |
| CVE-2026-33558 | medium | — | org.apache.kafka:kafka-clients | 2.7.0 | 4.22.0.1 |
| CVE-2026-33672 | medium | — | picomatch | 2.3.1 | 4.22.0.1 |
| CVE-2026-33750 | medium | — | brace-expansion | 1.1.11 | 4.22.0.1 |
| CVE-2026-34043 | medium | — | serialize-javascript | 4.0.0 | 4.22.0.1 |
| CVE-2026-34477 | medium | — | org.apache.logging.log4j:log4j-core | 2.19.0 | 4.22.0.1 |
| CVE-2026-34478 | medium | — | org.apache.logging.log4j:log4j-core | — | 4.22.0.1 |
| CVE-2026-34480 | medium | — | org.apache.logging.log4j:log4j-core | 2.19.0 | 4.22.0.1 |
| CVE-2026-34500 | medium | — | org.apache.tomcat.embed:tomcat-embed-core | — | 4.22.0.1 |
| CVE-2026-40021 | medium | — | log4net | 2.0.0 | 4.22.0.1 |
| CVE-2026-40175 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-41238 | medium | — | dompurify | 3.2.6 | 4.22.0.1 |
| CVE-2026-41239 | medium | — | dompurify | 3.2.6 | 4.22.0.1 |
| CVE-2026-41240 | medium | — | dompurify | 3.2.6 | 4.22.0.1 |
| CVE-2026-41305 | medium | — | postcss | 8.4.14 | 4.22.0.1 |
| CVE-2026-41650 | medium | — | fast-xml-parser | 4.3.0 | 4.22.0.1 |
| CVE-2026-42034 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-42036 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-42038 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-42039 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-42041 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-42042 | medium | — | axios | 0.21.4 | 4.22.0.1 |
| CVE-2026-5588 | medium | — | org.bouncycastle:bcpkix-jdk15on | — | 4.22.0.1 |
| GHSA-39q2-94rc-95cp | medium | — | dompurify | 3.2.6 | 4.22.0.1 |
| GHSA-72hv-8253-57qq | medium | — | com.fasterxml.jackson.core:jackson-core | 2.13.3 | 4.22.0.1 |
Showing 500 of 500