Middleware common libraries and tools
This hub aggregates every CVE we track for Middleware common libraries and tools, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
3
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4CRITICAL3MEDIUM2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 9 most recently published vulnerabilities affecting Middleware common libraries and tools.
- CVE-2022-23307A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.8.8
- CVE-2022-23305SQL injection in JDBC Appender in Apache Log4j V19.8
- CVE-2022-23302Deserialization of untrusted data in JMSSink in Apache Log4j 1.x8.8
- CVE-2021-42575The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.9.8
- CVE-2021-42340DoS via memory leak with WebSocket connections7.5
- CVE-2021-37714Crafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptions7.5
- CVE-2021-35043OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement ...6.1
- CVE-2021-30129DoS/OOM leak vulnerability in Apache Mina SSHD Server6.5
- CVE-2021-23926XMLBeans XML Entity Expansion9.1
Product normalization is registry-driven with AI assist and human review. How it works