This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit multiple vulnerabilities to achieve remote code execution (e.g., CVE-2024-2961) or bypass authentication (e.g., CVE-2017-7658) to access sensitive Hive data. With 396 critical or high-severity exposures and a maximum severity of 10.0, the attack surface is unacceptably large. No workaround fully mitigates the most severe issues.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2017-7658 | CRITICAL10 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.2.25.v20180606, 9.3.24.v20180605, 9.4.11.v20180605 | 21.0% High Exploitation Risk | Directly ExposedContext importance: HIGH |
| CVE-2017-7658 | CRITICAL10 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.2.25.v20180606, 9.3.24.v20180605, 9.4.11.v20180605 | 21.0% High Exploitation Risk | Directly ExposedContext importance: HIGH |
| CVE-2019-20445 | CRITICAL10 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 13.5% High Exploitation Risk | Directly Exposed |
| CVE-2019-20445 | CRITICAL10 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 13.5% High Exploitation Risk | Directly Exposed |
| CVE-2019-20445 | CRITICAL10 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 13.5% High Exploitation Risk | Directly Exposed |
| CVE-2019-20445 | CRITICAL10 | io.netty:netty-handler 4.0.52.Final fixed in 4.1.45 | 13.5% High Exploitation Risk | Directly Exposed |
| CVE-2019-20445 | CRITICAL10 | io.netty:netty-handler 4.1.17.Final fixed in 4.1.45 | 13.5% High Exploitation Risk | Directly Exposed |
| CVE-2024-2961 | CRITICAL10 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u9 | 88.3% Actively Exploited | Directly Exposed |
| CVE-2024-2961 | CRITICAL10 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u9 | 88.3% Actively Exploited | Directly Exposed |
| CVE-2022-23307 | CRITICAL10 | log4j:log4j 1.2.17 No fix yet | 52.5% Actively Exploited | Directly Exposed |
| CVE-2022-23302 | CRITICAL10 | log4j:log4j 1.2.17 No fix yet | 61.8% Actively Exploited | Directly Exposed |
| CVE-2020-13936 | CRITICAL10 | org.apache.velocity:velocity 1.7 No fix yet | 22.7% High Exploitation Risk | Directly Exposed |
| CVE-2023-4911 | CRITICAL10 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u7 | 78.6% Actively Exploited | Directly Exposed |
| CVE-2023-4911 | CRITICAL10 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u7 | 78.6% Actively Exploited | Directly Exposed |
| CVE-2019-1010022 | CRITICAL9.8 | libc-bin 2.31-13+deb11u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010022 | CRITICAL9.8 | libc6 2.31-13+deb11u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45853 | CRITICAL9.8 | zlib1g 1:1.2.11.dfsg-2+deb11u1 No fix yet | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2017-15095 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.8.11, 2.9.4, 2.6.7.3, 2.7.9.2 | 8.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-11307 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-14719 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 9.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14379 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16335 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16942 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16943 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17267 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10, 2.8.11.5 | 4.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17531 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20330 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.2 | 8.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14892 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.6.7.3, 2.8.11.5, 2.9.10 | 5.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-15095 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.8.11, 2.9.4, 2.6.7.3, 2.7.9.2 | 8.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-11307 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-14719 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 9.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14379 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16335 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16942 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16943 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17267 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10, 2.8.11.5 | 4.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17531 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20330 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.2 | 8.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14892 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.6.7.3, 2.8.11.5, 2.9.10 | 5.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-15095 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.8.11, 2.9.4, 2.6.7.3, 2.7.9.2 | 8.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-11307 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-14719 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 9.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-14720 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 7.5% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14379 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16335 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16942 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16943 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17267 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10, 2.8.11.5 | 4.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17531 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20330 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.2 | 8.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14892 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.6.7.3, 2.8.11.5, 2.9.10 | 5.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-11307 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-14719 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 9.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-14720 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 7.5% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14379 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16335 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16942 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16943 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17267 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10, 2.8.11.5 | 4.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17531 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.1, 2.8.11.5, 2.6.7.3 | 5.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20330 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.2 | 8.6% Low-Moderate Risk | Directly Exposed |
| CVE-2020-9546 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 4.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14892 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.6.7.3, 2.8.11.5, 2.9.10 | 5.4% Low-Moderate Risk | Directly Exposed |
| CVE-2019-14893 | CRITICAL9.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10 | 4.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-39135 | CRITICAL9.8 | org.apache.calcite:calcite-core 1.16.0 fixed in 1.32.0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-46337 | CRITICAL9.8 | org.apache.derby:derby 10.14.1.0 fixed in 10.14.3, 10.15.2.1, 10.16.1.2, 10.17.1.0 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37404 | CRITICAL9.8 | org.apache.hadoop:hadoop-common 3.1.0 fixed in 3.3.2, 3.2.3, 2.10.2 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2022-25168 | CRITICAL9.8 | org.apache.hadoop:hadoop-common 3.1.0 fixed in 2.10.2, 3.2.4, 3.3.3 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-17190 | CRITICAL9.8 | org.apache.spark:spark-core_2.11 2.3.0 No fix yet | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10202 | CRITICAL9.8 | org.codehaus.jackson:jackson-mapper-asl 1.9.13 No fix yet | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-41853 | CRITICAL9.8 | org.hsqldb:hsqldb 2.3.4 fixed in 2.7.1 | 3.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-1597 | CRITICAL9.8 | org.postgresql:postgresql 9.4.1208.jre7 fixed in 42.2.28, 42.3.9, 42.4.4, 42.5.5, 42.6.1, 42.7.2 | 4.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-21724 | CRITICAL9.8 | org.postgresql:postgresql 9.4.1208.jre7 fixed in 42.2.25, 42.3.2 | 3.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-50387 | CRITICAL9.75 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u6 | 100.0% Actively Exploited | Directly Exposed |
| CVE-2023-50868 | CRITICAL9.75 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u6 | 82.8% Actively Exploited | Directly Exposed |
| CVE-2023-50387 | CRITICAL9.75 | libudev1 247.3-7 fixed in 247.3-7+deb11u6 | 100.0% Actively Exploited | Directly Exposed |
| CVE-2023-50868 | CRITICAL9.75 | libudev1 247.3-7 fixed in 247.3-7+deb11u6 | 82.8% Actively Exploited | Directly Exposed |
| CVE-2014-0114 | CRITICAL9.75 | commons-beanutils:commons-beanutils 1.9.3 fixed in 1.9.4 | 95.8% Actively Exploited | Directly Exposed |
| CVE-2021-4104 | CRITICAL9.75 | log4j:log4j 1.2.17 No fix yet | 81.1% Actively Exploited | Directly Exposed |
| CVE-2017-5637 | CRITICAL9.75 | org.apache.zookeeper:zookeeper 3.4.6 fixed in 3.4.10, 3.5.3 | 73.7% Actively Exploited | Directly Exposed |
| CVE-2017-5637 | CRITICAL9.75 | org.apache.zookeeper:zookeeper 3.4.9 fixed in 3.4.10, 3.5.3 | 73.7% Actively Exploited | Directly Exposed |
| CVE-2021-28165 | CRITICAL9.75 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.4.39, 10.0.2, 11.0.2 | 53.9% Actively Exploited | Directly Exposed |
| CVE-2021-28165 | CRITICAL9.75 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.4.39, 10.0.2, 11.0.2 | 53.9% Actively Exploited | Directly Exposed |
| CVE-2023-0286 | CRITICAL9.62 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 62.0% Actively Exploited | Directly Exposed |
| CVE-2020-35728 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8 | 12.5% High Exploitation Risk | Directly Exposed |
| CVE-2020-36179 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8, 2.6.7.5 | 20.9% High Exploitation Risk | Directly Exposed |
| CVE-2020-36184 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8 | 10.4% High Exploitation Risk | Directly Exposed |
| CVE-2020-36188 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8, 2.6.7.5 | 10.9% High Exploitation Risk | Directly Exposed |
| CVE-2020-35728 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8 | 12.5% High Exploitation Risk | Directly Exposed |
| CVE-2020-36179 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8, 2.6.7.5 | 20.9% High Exploitation Risk | Directly Exposed |
| CVE-2020-36184 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8 | 10.4% High Exploitation Risk | Directly Exposed |
| CVE-2020-36188 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8, 2.6.7.5 | 10.9% High Exploitation Risk | Directly Exposed |
| CVE-2020-35728 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8 | 12.5% High Exploitation Risk | Directly Exposed |
| CVE-2020-36179 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8, 2.6.7.5 | 20.9% High Exploitation Risk | Directly Exposed |
| CVE-2020-36184 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8 | 10.4% High Exploitation Risk | Directly Exposed |
| CVE-2020-36188 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8, 2.6.7.5 | 10.9% High Exploitation Risk | Directly Exposed |
| CVE-2020-35728 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8 | 12.5% High Exploitation Risk | Directly Exposed |
| CVE-2020-36179 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8, 2.6.7.5 | 20.9% High Exploitation Risk | Directly Exposed |
| CVE-2020-36184 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8 | 10.4% High Exploitation Risk | Directly Exposed |
| CVE-2020-36188 | CRITICAL9.31 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8, 2.6.7.5 | 10.9% High Exploitation Risk | Directly Exposed |
| CVE-2024-37371 | CRITICAL9.1 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2024-37371 | CRITICAL9.1 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2024-37371 | CRITICAL9.1 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2024-37371 | CRITICAL9.1 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2022-1586 | CRITICAL9.1 | libpcre2-8-0 10.36-2 fixed in 10.36-2+deb11u1 | 3.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-1587 | CRITICAL9.1 | libpcre2-8-0 10.36-2 fixed in 10.36-2+deb11u1 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2021-46848 | CRITICAL9.1 | libtasn1-6 4.16.0-2 fixed in 4.16.0-2+deb11u1 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20444 | CRITICAL9.1 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20444 | CRITICAL9.1 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20444 | CRITICAL9.1 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20444 | CRITICAL9.1 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.44 | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20444 | CRITICAL9.1 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.44 | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2022-37865 | CRITICAL9.1 | org.apache.ivy:ivy 2.4.0 fixed in 2.5.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-44981 | CRITICAL9.1 | org.apache.zookeeper:zookeeper 3.4.6 fixed in 3.7.2, 3.8.3, 3.9.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-44981 | CRITICAL9.1 | org.apache.zookeeper:zookeeper 3.4.9 fixed in 3.7.2, 3.8.3, 3.9.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010023 | HIGH8.8 | libc-bin 2.31-13+deb11u3 No fix yet | 3.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010023 | HIGH8.8 | libc6 2.31-13+deb11u3 No fix yet | 3.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42898 | HIGH8.8 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u3 | 6.4% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42898 | HIGH8.8 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u3 | 6.4% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42898 | HIGH8.8 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u3 | 6.4% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42898 | HIGH8.8 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u3 | 6.4% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10673 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.4, 2.6.7.4 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10673 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.4, 2.6.7.4 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10673 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.4, 2.6.7.4 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10672 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 3.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10673 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4, 2.6.7.4 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10968 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 3.6% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10969 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 3.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-11111 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 3.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-11112 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 3.6% Low-Moderate Risk | Directly Exposed |
| CVE-2020-11113 | HIGH8.8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 6.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48734 | HIGH8.8 | commons-beanutils:commons-beanutils 1.9.3 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47561 | HIGH8.8 | org.apache.avro:avro 1.7.7 fixed in 1.11.4 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47561 | HIGH8.8 | org.apache.avro:avro 1.8.2 fixed in 1.11.4 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2022-36364 | HIGH8.8 | org.apache.calcite.avatica:avatica-core 1.11.0 fixed in 1.22.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-9492 | HIGH8.8 | org.apache.hadoop:hadoop-common 3.1.0 fixed in 3.2.2, 3.1.4, 2.10.1 | 4.4% Low-Moderate Risk | Directly Exposed |
| CVE-2021-33036 | HIGH8.8 | org.apache.hadoop:hadoop-yarn-server-common 3.1.0 fixed in 2.10.2, 3.2.3, 3.3.2 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-4450 | HIGH8.62 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 20.4% High Exploitation Risk | Directly Exposed |
| CVE-2019-12086 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.9, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 21.9% High Exploitation Risk | Directly Exposed |
| CVE-2019-14439 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 10.8% High Exploitation Risk | Directly Exposed |
| CVE-2019-12086 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.9, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 21.9% High Exploitation Risk | Directly Exposed |
| CVE-2019-14439 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 10.8% High Exploitation Risk | Directly Exposed |
| CVE-2020-25649 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.6.7.4, 2.9.10.7, 2.10.5.1 | 17.6% High Exploitation Risk | Directly Exposed |
| CVE-2019-12086 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.9, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 21.9% High Exploitation Risk | Directly Exposed |
| CVE-2019-14439 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 10.8% High Exploitation Risk | Directly Exposed |
| CVE-2020-25649 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.6.7.4, 2.9.10.7, 2.10.5.1 | 17.6% High Exploitation Risk | Directly Exposed |
| CVE-2019-12086 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.9, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 21.9% High Exploitation Risk | Directly Exposed |
| CVE-2019-14439 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.9.2, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 10.8% High Exploitation Risk | Directly Exposed |
| CVE-2020-25649 | HIGH8.62 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.6.7.4, 2.9.10.7, 2.10.5.1 | 17.6% High Exploitation Risk | Directly Exposed |
| CVE-2022-40152 | HIGH8.62 | com.fasterxml.woodstox:woodstox-core 5.0.3 fixed in 6.4.0, 5.4.0 | 19.5% High Exploitation Risk | Directly Exposed |
| CVE-2022-25647 | HIGH8.62 | com.google.code.gson:gson 2.2.4 fixed in 2.8.9 | 12.0% High Exploitation Risk | Directly Exposed |
| CVE-2022-25647 | HIGH8.62 | com.google.code.gson:gson 2.8.1 fixed in 2.8.9 | 12.0% High Exploitation Risk | Directly Exposed |
| CVE-2021-35515 | HIGH8.62 | org.apache.commons:commons-compress 1.19 fixed in 1.21 | 11.9% High Exploitation Risk | Directly Exposed |
| CVE-2021-35516 | HIGH8.62 | org.apache.commons:commons-compress 1.19 fixed in 1.21 | 12.7% High Exploitation Risk | Directly Exposed |
| CVE-2021-35517 | HIGH8.62 | org.apache.commons:commons-compress 1.19 fixed in 1.21 | 10.9% High Exploitation Risk | Directly Exposed |
| CVE-2021-36090 | HIGH8.62 | org.apache.commons:commons-compress 1.19 fixed in 1.21 | 13.3% High Exploitation Risk | Directly Exposed |
| CVE-2021-35515 | HIGH8.62 | org.apache.commons:commons-compress 1.4.1 fixed in 1.21 | 11.9% High Exploitation Risk | Directly Exposed |
| CVE-2021-35516 | HIGH8.62 | org.apache.commons:commons-compress 1.4.1 fixed in 1.21 | 12.7% High Exploitation Risk | Directly Exposed |
| CVE-2021-35517 | HIGH8.62 | org.apache.commons:commons-compress 1.4.1 fixed in 1.21 | 10.9% High Exploitation Risk | Directly Exposed |
| CVE-2021-36090 | HIGH8.62 | org.apache.commons:commons-compress 1.4.1 fixed in 1.21 | 13.3% High Exploitation Risk | Directly Exposed |
| CVE-2019-10172 | HIGH8.62 | org.codehaus.jackson:jackson-mapper-asl 1.9.13 No fix yet | 17.0% High Exploitation Risk | Directly Exposed |
| CVE-2021-33813 | HIGH8.62 | org.jdom:jdom 1.1 No fix yet | 19.4% High Exploitation Risk | Directly Exposed |
| CVE-2017-18640 | HIGH8.62 | org.yaml:snakeyaml 1.16 fixed in 1.26 | 26.7% High Exploitation Risk | Directly Exposed |
| CVE-2012-0881 | HIGH8.62 | xerces:xercesImpl 2.9.1 fixed in 2.12.0 | 17.1% High Exploitation Risk | Directly Exposed |
| CVE-2023-2650 | HIGH8.45 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 77.9% Actively Exploited | Directly Exposed |
| CVE-2019-10086 | HIGH8.39 | commons-beanutils:commons-beanutils 1.9.3 fixed in 1.9.4 | 28.8% High Exploitation Risk | Directly Exposed |
| CVE-2026-42010 | HIGH8.33 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42581 | HIGH8.33 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42581 | HIGH8.33 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-32988 | HIGH8.2 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u8 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-46751 | HIGH8.2 | org.apache.ivy:ivy 2.4.0 fixed in 2.5.2 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2013-4002 | HIGH8.16 | xerces:xercesImpl 2.9.1 fixed in 2.12.0 | 24.7% High Exploitation Risk | Directly Exposed |
| CVE-2026-45447 | HIGH8.1 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5968 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.8.11.1, 2.9.4, 2.7.9.5 | 7.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10650 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.4 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24616 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.6 | 9.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24750 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.6.7.5, 2.9.10.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35490 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8 | 7.7% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35491 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8 | 9.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36180 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36181 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36182 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36183 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36185 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36186 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36187 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36189 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-20190 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.7, 2.6.7.5 | 7.5% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5968 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.8.11.1, 2.9.4, 2.7.9.5 | 7.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10650 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.4 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24616 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.6 | 9.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24750 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.6.7.5, 2.9.10.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35490 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8 | 7.7% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35491 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8 | 9.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36180 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36181 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36182 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36183 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36185 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36186 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36187 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36189 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-20190 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.7, 2.6.7.5 | 7.5% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5968 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.8.11.1, 2.9.4, 2.7.9.5 | 7.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10650 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.4 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24616 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.6 | 9.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24750 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.6.7.5, 2.9.10.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35490 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8 | 7.7% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35491 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8 | 9.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36180 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36181 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36182 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36183 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36185 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36186 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36187 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36189 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-20190 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.7, 2.6.7.5 | 7.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-10650 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-11619 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 3.6% Low-Moderate Risk | Directly Exposed |
| CVE-2020-11620 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2020-14060 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.5 | 8.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-14061 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.5 | 4.4% Low-Moderate Risk | Directly Exposed |
| CVE-2020-14062 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.5 | 8.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-14195 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.5 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24616 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.6 | 9.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-24750 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.6.7.5, 2.9.10.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35490 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8 | 7.7% Low-Moderate Risk | Directly Exposed |
| CVE-2020-35491 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8 | 9.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36180 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36181 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36182 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8, 2.6.7.5 | 5.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36183 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36185 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36186 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36187 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8 | 5.2% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36189 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.8, 2.6.7.5 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-20190 | HIGH8.1 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.7, 2.6.7.5 | 7.5% Low-Moderate Risk | Directly Exposed |
| CVE-2018-14721 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 10.5% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-14721 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.7, 2.8.11.3, 2.7.9.5 | 10.5% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2017-17485 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.4, 2.8.11, 2.7.9.2 | 50.0% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2017-7525 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.6.7.1, 2.7.9.1, 2.8.9 | 37.9% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-14718 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.7, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 12.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19362 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.8, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-7489 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.8.11.1, 2.9.5, 2.7.9.3, 2.6.7.5 | 20.5% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2019-14540 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 10.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-8840 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.3 | 26.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9547 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9548 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.3% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2017-17485 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.4, 2.8.11, 2.7.9.2 | 50.0% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-14718 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.7, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 12.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19362 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.8, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-7489 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.8.11.1, 2.9.5, 2.7.9.3, 2.6.7.5 | 20.5% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2019-14540 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 10.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-8840 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.3 | 26.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9547 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9548 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.3% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2017-17485 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.4, 2.8.11, 2.7.9.2 | 50.0% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2017-7525 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.6.7.1, 2.7.9.1, 2.8.9 | 37.9% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-14718 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.7, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 12.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19360 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.8, 2.8.11.3, 2.7.9.5 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19361 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.7.9.5, 2.9.8, 2.8.11.3 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19362 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.8, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-7489 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.8.11.1, 2.9.5, 2.7.9.3, 2.6.7.5 | 20.5% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2019-14540 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 10.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-8840 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.3 | 26.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9547 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9548 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.3% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-14718 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.7, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 12.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19360 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.8, 2.8.11.3, 2.7.9.5 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19361 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.7.9.5, 2.9.8, 2.8.11.3 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-19362 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.8, 2.8.11.3, 2.7.9.5, 2.6.7.3 | 10.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2018-7489 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.8.11.1, 2.9.5, 2.7.9.3, 2.6.7.5 | 20.5% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2019-14540 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10, 2.8.11.5, 2.6.7.3 | 10.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-8840 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.3 | 26.6% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9547 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.7% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9548 | HIGH8 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.10.4, 2.8.11.6, 2.7.9.7 | 18.3% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2019-17195 | HIGH8 | com.nimbusds:nimbus-jose-jwt 4.41.1 fixed in 7.9 | 11.0% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2017-7657 | HIGH8 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.2.25.v20180606, 9.3.24.v20180605 | 16.2% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2017-7657 | HIGH8 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.2.25.v20180606, 9.3.24.v20180605 | 16.2% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2022-1471 | HIGH8 | org.yaml:snakeyaml 1.16 fixed in 2.0 | 99.6% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2022-31197 | HIGH8 | org.postgresql:postgresql 9.4.1208.jre7 fixed in 42.2.26, 42.4.1, 42.3.7 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2022-1304 | HIGH7.8 | libcom-err2 1.46.2-2 fixed in 1.46.2-2+deb11u1 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2022-1304 | HIGH7.8 | libext2fs2 1.46.2-2 fixed in 1.46.2-2+deb11u1 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2017-7245 | HIGH7.8 | libpcre3 2:8.39-13 No fix yet | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2017-7246 | HIGH7.8 | libpcre3 2:8.39-13 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2022-1304 | HIGH7.8 | libss2 1.46.2-2 fixed in 1.46.2-2+deb11u1 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33845 | HIGH7.73 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42584 | HIGH7.73 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42584 | HIGH7.73 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-0286 | HIGH7.7 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 62.0% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2024-33599 | HIGH7.6 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33599 | HIGH7.6 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-25638 | HIGH7.57 | dnsjava:dnsjava 2.1.7 fixed in 3.6.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2018-20796 | HIGH7.5 | libc-bin 2.31-13+deb11u3 No fix yet | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2019-9192 | HIGH7.5 | libc-bin 2.31-13+deb11u3 No fix yet | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-20796 | HIGH7.5 | libc6 2.31-13+deb11u3 No fix yet | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2019-9192 | HIGH7.5 | libc6 2.31-13+deb11u3 No fix yet | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2021-33560 | HIGH7.5 | libgcrypt20 1.8.7-6 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-6829 | HIGH7.5 | libgcrypt20 1.8.7-6 No fix yet | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-2509 | HIGH7.5 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u2 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0553 | HIGH7.5 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u5 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0567 | HIGH7.5 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u5 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libgssapi-krb5-2 1.18.3-6+deb11u1 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libk5crypto3 1.18.3-6+deb11u1 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libkrb5-3 1.18.3-6+deb11u1 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libkrb5support0 1.18.3-6+deb11u1 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2017-11164 | HIGH7.5 | libpcre3 2:8.39-13 No fix yet | 3.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20838 | HIGH7.5 | libpcre3 2:8.39-13 No fix yet | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0215 | HIGH7.5 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0464 | HIGH7.5 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 3.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-46828 | HIGH7.5 | libtirpc-common 1.3.1-1 fixed in 1.3.1-1+deb11u1 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2021-46828 | HIGH7.5 | libtirpc3 1.3.1-1 fixed in 1.3.1-1+deb11u1 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-4899 | HIGH7.5 | libzstd1 1.4.8+dfsg-2.1 No fix yet | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36518 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.12.0 fixed in 2.13.2.1, 2.12.6.1 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-46877 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.12.0 fixed in 2.12.6, 2.13.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42003 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.12.0 fixed in 2.12.7.1, 2.13.4.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42004 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.12.0 fixed in 2.12.7.1, 2.13.4 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12022 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36518 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.13.2.1, 2.12.6.1 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42003 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.12.7.1, 2.13.4.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42004 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.12.7.1, 2.13.4 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12022 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36518 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.13.2.1, 2.12.6.1 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42003 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.12.7.1, 2.13.4.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42004 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.12.7.1, 2.13.4 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12022 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12023 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 8.9% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36518 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.13.2.1, 2.12.6.1 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42003 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.12.7.1, 2.13.4.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42004 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.12.7.1, 2.13.4 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12022 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 7.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12023 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.7.9.4, 2.8.11.2, 2.9.6 | 8.9% Low-Moderate Risk | Directly Exposed |
| CVE-2020-36518 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.13.2.1, 2.12.6.1 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42003 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.12.7.1, 2.13.4.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42004 | HIGH7.5 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.12.7.1, 2.13.4 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 2.5.0 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-3171 | HIGH7.5 | com.google.protobuf:protobuf-java 2.5.0 fixed in 3.21.7, 3.20.3, 3.19.6, 3.16.3 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 3.3.0 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-3171 | HIGH7.5 | com.google.protobuf:protobuf-java 3.3.0 fixed in 3.21.7, 3.20.3, 3.19.6, 3.16.3 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 3.3.1 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-3171 | HIGH7.5 | com.google.protobuf:protobuf-java 3.3.1 fixed in 3.21.7, 3.20.3, 3.19.6, 3.16.3 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3635 | HIGH7.5 | com.squareup.okio:okio 1.6.0 fixed in 3.4.0, 1.17.6 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37136 | HIGH7.5 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37137 | HIGH7.5 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 6.3% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37136 | HIGH7.5 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37137 | HIGH7.5 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 6.3% Low-Moderate Risk | Directly Exposed |
| CVE-2015-2156 | HIGH7.5 | io.netty:netty 3.6.2.Final fixed in 3.10.3.Final, 3.9.8.Final | 5.4% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37136 | HIGH7.5 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37137 | HIGH7.5 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 6.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16869 | HIGH7.5 | io.netty:netty-all 4.0.52.Final fixed in 4.1.42.Final | 8.4% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16869 | HIGH7.5 | io.netty:netty-all 4.1.12.Final fixed in 4.1.42.Final | 8.4% Low-Moderate Risk | Directly Exposed |
| CVE-2019-16869 | HIGH7.5 | io.netty:netty-all 4.1.17.Final fixed in 4.1.42.Final | 8.4% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37136 | HIGH7.5 | io.netty:netty-codec 4.0.52.Final fixed in 4.1.68.Final | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37137 | HIGH7.5 | io.netty:netty-codec 4.0.52.Final fixed in 4.1.68.Final | 6.3% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37136 | HIGH7.5 | io.netty:netty-codec 4.1.17.Final fixed in 4.1.68.Final | 5.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37137 | HIGH7.5 | io.netty:netty-codec 4.1.17.Final fixed in 4.1.68.Final | 6.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-11612 | HIGH7.5 | io.netty:netty-handler 4.1.17.Final fixed in 4.1.46 | 9.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26464 | HIGH7.5 | log4j:log4j 1.2.17 fixed in 2.0 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2023-1370 | HIGH7.5 | net.minidev:json-smart 2.3 fixed in 2.4.9 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-39410 | HIGH7.5 | org.apache.avro:avro 1.7.7 fixed in 1.11.3 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-39410 | HIGH7.5 | org.apache.avro:avro 1.8.2 fixed in 1.11.3 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-37866 | HIGH7.5 | org.apache.ivy:ivy 2.4.0 fixed in 2.5.1 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10099 | HIGH7.5 | org.apache.spark:spark-core_2.11 2.3.0 fixed in 2.3.3 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-1320 | HIGH7.5 | org.apache.thrift:libthrift 0.9.3 fixed in 0.9.3-1, 0.12.0 | 8.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-0205 | HIGH7.5 | org.apache.thrift:libthrift 0.9.3 fixed in 0.13.0 | 9.1% Low-Moderate Risk | Directly Exposed |
| CVE-2020-13949 | HIGH7.5 | org.apache.thrift:libthrift 0.9.3 fixed in 0.14.0 | 6.8% Low-Moderate Risk | Directly Exposed |
| CVE-2018-8012 | HIGH7.5 | org.apache.zookeeper:zookeeper 3.4.6 fixed in 3.4.10, 3.5.4-beta | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2018-8012 | HIGH7.5 | org.apache.zookeeper:zookeeper 3.4.9 fixed in 3.4.10, 3.5.4-beta | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2022-40150 | HIGH7.5 | org.codehaus.jettison:jettison 1.1 fixed in 1.5.2 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-45685 | HIGH7.5 | org.codehaus.jettison:jettison 1.1 fixed in 1.5.2 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2022-45693 | HIGH7.5 | org.codehaus.jettison:jettison 1.1 fixed in 1.5.2 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-1436 | HIGH7.5 | org.codehaus.jettison:jettison 1.1 fixed in 1.5.4 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-40149 | HIGH7.5 | org.codehaus.jettison:jettison 1.1 fixed in 1.5.1 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-40150 | HIGH7.5 | org.codehaus.jettison:jettison 1.3.4 fixed in 1.5.2 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-45685 | HIGH7.5 | org.codehaus.jettison:jettison 1.3.4 fixed in 1.5.2 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2022-45693 | HIGH7.5 | org.codehaus.jettison:jettison 1.3.4 fixed in 1.5.2 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-1436 | HIGH7.5 | org.codehaus.jettison:jettison 1.3.4 fixed in 1.5.4 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-40149 | HIGH7.5 | org.codehaus.jettison:jettison 1.3.4 fixed in 1.5.1 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2017-7656 | HIGH7.5 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.3.24.v20180605, 9.4.11.v20180605 | 6.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-9735 | HIGH7.5 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.4.6.v20170531, 9.3.20.v20170531, 9.2.22.v20170606 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12545 | HIGH7.5 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.4.12.v20180830, 9.3.25.v20180904 | 5.1% Low-Moderate Risk | Directly Exposed |
| CVE-2017-7656 | HIGH7.5 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.3.24.v20180605, 9.4.11.v20180605 | 6.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12545 | HIGH7.5 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.4.12.v20180830, 9.3.25.v20180904 | 5.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34455 | HIGH7.5 | org.xerial.snappy:snappy-java 1.0.5 fixed in 1.1.10.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-43642 | HIGH7.5 | org.xerial.snappy:snappy-java 1.0.5 fixed in 1.1.10.4 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34453 | HIGH7.5 | org.xerial.snappy:snappy-java 1.0.5 fixed in 1.1.10.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34454 | HIGH7.5 | org.xerial.snappy:snappy-java 1.0.5 fixed in 1.1.10.1 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34455 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.4 fixed in 1.1.10.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-43642 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.4 fixed in 1.1.10.4 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34453 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.4 fixed in 1.1.10.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34454 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.4 fixed in 1.1.10.1 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2022-25857 | HIGH7.5 | org.yaml:snakeyaml 1.16 fixed in 1.31 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0361 | HIGH7.4 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u3 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2020-27216 | HIGH7 | org.eclipse.jetty:jetty-webapp 9.3.19.v20170502 fixed in 9.4.33.v20201020, 10.0.0.beta3, 11.0.0.beta3 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-27216 | HIGH7 | org.eclipse.jetty:jetty-webapp 9.3.20.v20170531 fixed in 9.4.33.v20201020, 10.0.0.beta3, 11.0.0.beta3 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-32990 | MEDIUM6.97 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u8 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42013 | MEDIUM6.97 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5260 | MEDIUM6.97 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2021-28169 | MEDIUM6.89 | org.eclipse.jetty:jetty-servlets 9.3.20.v20170531 fixed in 9.4.41, 10.0.3, 11.0.3 | 78.5% Actively Exploited | Directly Exposed |
| CVE-2026-0861 | MEDIUM6.88 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0861 | MEDIUM6.88 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.0.52.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.17.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-4304 | MEDIUM6.79 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 16.2% High Exploitation Risk | Directly Exposed |
| CVE-2019-12384 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 45.2% High Exploitation Risk | Directly Exposed |
| CVE-2019-12814 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.4.0 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 11.0% High Exploitation Risk | Directly Exposed |
| CVE-2019-12384 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 45.2% High Exploitation Risk | Directly Exposed |
| CVE-2019-12814 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.6.7.1 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 11.0% High Exploitation Risk | Directly Exposed |
| CVE-2019-12384 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 45.2% High Exploitation Risk | Directly Exposed |
| CVE-2019-12814 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.7.8 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 11.0% High Exploitation Risk | Directly Exposed |
| CVE-2019-12384 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 45.2% High Exploitation Risk | Directly Exposed |
| CVE-2019-12814 | MEDIUM6.79 | com.fasterxml.jackson.core:jackson-databind 2.9.4 fixed in 2.9.9.1, 2.8.11.4, 2.7.9.6, 2.6.7.3 | 11.0% High Exploitation Risk | Directly Exposed |
| CVE-2021-21295 | MEDIUM6.79 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 18.9% High Exploitation Risk | Directly Exposed |
| CVE-2021-21295 | MEDIUM6.79 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 18.9% High Exploitation Risk | Directly Exposed |
| CVE-2021-21295 | MEDIUM6.79 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 18.9% High Exploitation Risk | Directly Exposed |
| CVE-2023-2650 | MEDIUM6.76 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 77.9% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2025-54920 | MEDIUM6.7 | org.apache.spark:spark-core_2.11 2.3.0 No fix yet | 5.3% Low-Moderate Risk | Directly Exposed |
| CVE-2021-3999 | MEDIUM6.63 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2021-3999 | MEDIUM6.63 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-29111 | MEDIUM6.63 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-29111 | MEDIUM6.63 | libudev1 247.3-7 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-31159 | MEDIUM6.5 | com.amazonaws:aws-java-sdk-s3 1.11.271 fixed in 1.12.261 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2021-37533 | MEDIUM6.5 | commons-net:commons-net 3.6 fixed in 3.9.0 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-43797 | MEDIUM6.5 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-43797 | MEDIUM6.5 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-43797 | MEDIUM6.5 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-43797 | MEDIUM6.5 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.71.Final | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-43797 | MEDIUM6.5 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.71.Final | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34462 | MEDIUM6.5 | io.netty:netty-handler 4.0.52.Final fixed in 4.1.94.Final | 2.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34462 | MEDIUM6.5 | io.netty:netty-handler 4.1.17.Final fixed in 4.1.94.Final | 2.5% Low-Moderate Risk | Directly Exposed |
| CVE-2018-11798 | MEDIUM6.5 | org.apache.thrift:libthrift 0.9.3 fixed in 0.12.0 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2024-8184 | MEDIUM6.5 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 12.0.9, 10.0.24, 11.0.24, 9.4.56 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-8184 | MEDIUM6.5 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 12.0.9, 10.0.24, 11.0.24, 9.4.56 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-38749 | MEDIUM6.5 | org.yaml:snakeyaml 1.16 fixed in 1.31 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2022-38751 | MEDIUM6.5 | org.yaml:snakeyaml 1.16 fixed in 1.31 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2022-38752 | MEDIUM6.5 | org.yaml:snakeyaml 1.16 fixed in 1.32 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2022-41854 | MEDIUM6.5 | org.yaml:snakeyaml 1.16 fixed in 1.32 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2022-23437 | MEDIUM6.5 | xerces:xercesImpl 2.9.1 fixed in 2.12.2 | 4.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33846 | MEDIUM6.38 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-42009 | MEDIUM6.38 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2022-41409 | MEDIUM6.38 | libpcre2-8-0 10.36-2 No fix yet | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28388 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-28389 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28390 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-34610 | MEDIUM6.38 | com.cedarsoftware:json-io 2.5.1 fixed in 4.14.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.12.0 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.4.0 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.6.7 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.7.8 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.9.4 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-3509 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.3.0 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-3510 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.3.0 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-3509 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.3.1 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-3510 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.3.1 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-52428 | MEDIUM6.38 | com.nimbusds:nimbus-jose-jwt 4.41.1 fixed in 9.37.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-67721 | MEDIUM6.38 | io.airlift:aircompressor 0.10 fixed in 2.0.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.0.52.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.17.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.0.52.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.0.52.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.17.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.17.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | net.jpountz.lz4:lz4 1.2.0 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-34479 | MEDIUM6.38 | org.apache.logging.log4j:log4j-1.2-api 2.17.1 fixed in 2.25.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-34480 | MEDIUM6.38 | org.apache.logging.log4j:log4j-core 2.17.1 fixed in 2.25.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2024-9823 | MEDIUM6.38 | org.eclipse.jetty:jetty-servlets 9.3.20.v20170531 fixed in 9.4.54, 10.0.18, 11.0.18 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | org.lz4:lz4-java 1.4.0 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-21634 | MEDIUM6.38 | software.amazon.ion:ion-java 1.0.2 fixed in 1.10.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-3833 | MEDIUM6.29 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42011 | MEDIUM6.29 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-43869 | MEDIUM6.21 | org.apache.thrift:libthrift 0.9.3 fixed in 0.23.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2020-13529 | MEDIUM6.1 | libsystemd0 247.3-7 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2020-13529 | MEDIUM6.1 | libudev1 247.3-7 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10241 | MEDIUM6.1 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.2.27.v20190403, 9.3.26.v20190403, 9.4.16.v20190411 | 9.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10241 | MEDIUM6.1 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.2.27.v20190403, 9.3.26.v20190403, 9.4.16.v20190411 | 9.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42012 | MEDIUM6.03 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 11.0.2 fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 14.0.1 fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 16.0.1 fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 19.0 fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-2976 | MEDIUM6.03 | com.google.guava:guava 22.0 fixed in 32.0.0-android | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-4802 | MEDIUM5.95 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u13 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-4802 | MEDIUM5.95 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u13 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-4806 | MEDIUM5.9 | libc-bin 2.31-13+deb11u3 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-4813 | MEDIUM5.9 | libc-bin 2.31-13+deb11u3 No fix yet | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-4806 | MEDIUM5.9 | libc6 2.31-13+deb11u3 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-4813 | MEDIUM5.9 | libc6 2.31-13+deb11u3 No fix yet | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-2236 | MEDIUM5.9 | libgcrypt20 1.8.7-6 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5981 | MEDIUM5.9 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u4 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libgssapi-krb5-2 1.18.3-6+deb11u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libk5crypto3 1.18.3-6+deb11u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5-3 1.18.3-6+deb11u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5support0 1.18.3-6+deb11u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1-6 4.16.0-2 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-10237 | MEDIUM5.9 | com.google.guava:guava 11.0.2 fixed in 24.1.1-android | 5.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-10237 | MEDIUM5.9 | com.google.guava:guava 14.0.1 fixed in 24.1.1-android | 5.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-10237 | MEDIUM5.9 | com.google.guava:guava 16.0.1 fixed in 24.1.1-android | 5.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-10237 | MEDIUM5.9 | com.google.guava:guava 19.0 fixed in 24.1.1-android | 5.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-10237 | MEDIUM5.9 | com.google.guava:guava 22.0 fixed in 24.1.1-android | 5.1% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21409 | MEDIUM5.9 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21409 | MEDIUM5.9 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21409 | MEDIUM5.9 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 4.9% Low-Moderate Risk | Directly Exposed |
| CVE-2021-27568 | MEDIUM5.9 | net.minidev:json-smart 2.3 fixed in 1.3.2, 2.4.1, 2.3.1 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2020-13955 | MEDIUM5.9 | org.apache.calcite:calcite-core 1.16.0 fixed in 1.26.0 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2020-13955 | MEDIUM5.9 | org.apache.calcite:calcite-druid 1.16.0 fixed in 1.26.0 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2019-0201 | MEDIUM5.9 | org.apache.zookeeper:zookeeper 3.4.6 fixed in 3.4.14, 3.5.5 | 9.6% Low-Moderate Risk | Directly Exposed |
| CVE-2019-0201 | MEDIUM5.9 | org.apache.zookeeper:zookeeper 3.4.9 fixed in 3.4.14, 3.5.5 | 9.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-40490 | MEDIUM5.78 | org.asynchttpclient:async-http-client 2.0.37 fixed in 3.0.9, 2.14.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2009-2625 | MEDIUM5.75 | xerces:xercesImpl 2.9.1 fixed in 2.10.0 | 30.4% High Exploitation Risk | Directly Exposed |
| CVE-2026-4105 | MEDIUM5.7 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4105 | MEDIUM5.7 | libudev1 247.3-7 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42014 | MEDIUM5.61 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u4 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4741 | MEDIUM5.6 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2011-3389 | MEDIUM5.59 | libgnutls30 3.7.1-5+deb11u1 No fix yet | 73.3% Actively Exploited | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.31-13+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.31-13+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-6395 | MEDIUM5.52 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | net.jpountz.lz4:lz4 1.2.0 No fix yet | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.4.0 fixed in 1.8.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2021-29425 | MEDIUM5.52 | commons-io:commons-io 2.4 fixed in 2.7 | 10.6% High Exploitation Risk | Directly Exposed |
| CVE-2021-29425 | MEDIUM5.52 | commons-io:commons-io 2.5 fixed in 2.7 | 10.6% High Exploitation Risk | Directly Exposed |
| CVE-2021-29425 | MEDIUM5.52 | commons-io:commons-io 2.6 fixed in 2.7 | 10.6% High Exploitation Risk | Directly Exposed |
| CVE-2024-0727 | MEDIUM5.5 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22569 | MEDIUM5.5 | com.google.protobuf:protobuf-java 2.5.0 fixed in 3.16.1, 3.18.2, 3.19.2 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22569 | MEDIUM5.5 | com.google.protobuf:protobuf-java 3.3.0 fixed in 3.16.1, 3.18.2, 3.19.2 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22569 | MEDIUM5.5 | com.google.protobuf:protobuf-java 3.3.1 fixed in 3.16.1, 3.18.2, 3.19.2 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21290 | MEDIUM5.5 | io.netty:netty 3.10.5.Final fixed in 4.0.0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21290 | MEDIUM5.5 | io.netty:netty 3.10.6.Final fixed in 4.0.0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21290 | MEDIUM5.5 | io.netty:netty 3.6.2.Final fixed in 4.0.0 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21290 | MEDIUM5.5 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.59.Final | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-24823 | MEDIUM5.5 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.77.Final | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2021-21290 | MEDIUM5.5 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.59.Final | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-24823 | MEDIUM5.5 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.77.Final | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-15250 | MEDIUM5.5 | junit:junit 4.11 fixed in 4.13.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2020-17521 | MEDIUM5.5 | org.codehaus.groovy:groovy-all 2.4.11 fixed in 2.4.21, 2.5.14, 3.0.7 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-11770 | MEDIUM5.46 | org.apache.spark:spark-core_2.11 2.3.0 No fix yet | 65.9% Actively Exploited | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u8 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libudev1 247.3-7 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libudev1 247.3-7 fixed in 247.3-7+deb11u8 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2018-8024 | MEDIUM5.4 | org.apache.spark:spark-core_2.11 2.3.0 fixed in 2.1.3, 2.2.2, 2.3.1 | 5.5% Low-Moderate Risk | Directly Exposed |
| CVE-2022-31777 | MEDIUM5.4 | org.apache.spark:spark-core_2.11 2.3.0 fixed in 3.2.2 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc-bin 2.31-13+deb11u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc-bin 2.31-13+deb11u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc6 2.31-13+deb11u3 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc6 2.31-13+deb11u3 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12243 | MEDIUM5.3 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u7 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2022-2097 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0465 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0466 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3446 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1v-0~deb11u1 | 5.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3817 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1v-0~deb11u1 | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5678 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12133 | MEDIUM5.3 | libtasn1-6 4.16.0-2 fixed in 4.16.0-2+deb11u2 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29025 | MEDIUM5.3 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.1.108.Final | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29025 | MEDIUM5.3 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.1.108.Final | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2025-27553 | MEDIUM5.3 | org.apache.commons:commons-vfs2 2.1 fixed in 2.10.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2018-1313 | MEDIUM5.3 | org.apache.derby:derby 10.14.1.0 fixed in 10.14.2.0 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2020-13956 | MEDIUM5.3 | org.apache.httpcomponents:httpclient 4.5.2 fixed in 4.5.13, 5.0.3 | 8.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-40167 | MEDIUM5.3 | org.eclipse.jetty:jetty-http 9.3.19.v20170502 fixed in 9.4.52, 10.0.16, 11.0.16, 12.0.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-40167 | MEDIUM5.3 | org.eclipse.jetty:jetty-http 9.3.20.v20170531 fixed in 9.4.52, 10.0.16, 11.0.16, 12.0.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12536 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.4.11.v20180605, 9.3.24.v20180605 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10246 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.2.28.v20190418, 9.3.27.v20190418, 9.4.17.v20190418 | 4.0% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10247 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.2.28.v20190418, 9.3.27.v20190418, 9.4.17.v20190418 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26048 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26049 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14, 12.0.0.beta0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-12536 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.4.11.v20180605, 9.3.24.v20180605 | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10246 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.2.28.v20190418, 9.3.27.v20190418, 9.4.17.v20190418 | 4.0% Low-Moderate Risk | Directly Exposed |
| CVE-2019-10247 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.2.28.v20190418, 9.3.27.v20190418, 9.4.17.v20190418 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26048 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26049 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14, 12.0.0.beta0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-14338 | MEDIUM5.3 | xerces:xercesImpl 2.9.1 fixed in 2.12.0.sp3 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.31-13+deb11u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.31-13+deb11u3 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM5.02 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM5.02 | libgssapi-krb5-2 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libgssapi-krb5-2 1.18.3-6+deb11u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM5.02 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM5.02 | libk5crypto3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libk5crypto3 1.18.3-6+deb11u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM5.02 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM5.02 | libkrb5-3 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5-3 1.18.3-6+deb11u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM5.02 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM5.02 | libkrb5support0 1.18.3-6+deb11u1 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5support0 1.18.3-6+deb11u1 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-7008 | MEDIUM5.02 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u6 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-7008 | MEDIUM5.02 | libudev1 247.3-7 fixed in 247.3-7+deb11u6 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-34477 | MEDIUM5.02 | org.apache.logging.log4j:log4j-core 2.17.1 fixed in 2.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2014-0193 | MEDIUM5 | io.netty:netty 3.6.2.Final fixed in 3.6.9.Final, 3.7.1.Final, 3.8.2.Final, 3.9.1.Final, 4.0.19.Final | 4.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-53864 | MEDIUM4.93 | com.nimbusds:nimbus-jose-jwt 4.41.1 fixed in 10.0.2, 9.37.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-2511 | MEDIUM4.81 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u12 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u12 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2017-16231 | MEDIUM4.67 | libpcre3 2:8.39-13 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2022-3821 | MEDIUM4.67 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-4415 | MEDIUM4.67 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u2 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-3821 | MEDIUM4.67 | libudev1 247.3-7 fixed in 247.3-7+deb11u2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-4415 | MEDIUM4.67 | libudev1 247.3-7 fixed in 247.3-7+deb11u2 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.2.11.dfsg-2+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-47535 | MEDIUM4.67 | io.netty:netty-common 4.1.17.Final fixed in 4.1.115.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-25193 | MEDIUM4.67 | io.netty:netty-common 4.1.17.Final fixed in 4.1.118.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-25710 | MEDIUM4.67 | org.apache.commons:commons-compress 1.19 fixed in 1.26.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-25710 | MEDIUM4.67 | org.apache.commons:commons-compress 1.4.1 fixed in 1.26.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-38750 | MEDIUM4.67 | org.yaml:snakeyaml 1.16 fixed in 1.31 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42496 | MEDIUM4.64 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2019-17571 | MEDIUM4.58 | log4j:log4j 1.2.17 No fix yet | 69.1% Actively Exploited | Post-Exploit |
| CVE-2022-23305 | MEDIUM4.58 | log4j:log4j 1.2.17 No fix yet | 67.5% Actively Exploited | Post-Exploit |
| CVE-2023-0215 | MEDIUM4.5 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0464 | MEDIUM4.5 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 3.7% Low-Moderate Risk | Post-Exploit |
| CVE-2020-11979 | MEDIUM4.5 | org.apache.ant:ant 1.9.1 fixed in 1.10.9 | 8.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3184 | MEDIUM4.5 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-28834 | MEDIUM4.5 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-14831 | MEDIUM4.5 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u9 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | MEDIUM4.5 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u10 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | liblzma5 5.2.5-2.1~deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libsystemd0 247.3-7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libsystemd0 247.3-7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libsystemd0 247.3-7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libudev1 247.3-7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libudev1 247.3-7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libudev1 247.3-7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.0.52.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.17.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-6763 | MEDIUM4.5 | org.eclipse.jetty:jetty-http 9.3.19.v20170502 fixed in 12.0.12 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2024-6763 | MEDIUM4.5 | org.eclipse.jetty:jetty-http 9.3.20.v20170531 fixed in 12.0.12 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2024-28085 | MEDIUM4.4 | libblkid1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28085 | MEDIUM4.4 | libmount1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28085 | MEDIUM4.4 | libsmartcols1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28085 | MEDIUM4.4 | libuuid1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29131 | MEDIUM4.4 | org.apache.commons:commons-configuration2 2.1.1 fixed in 2.10.1 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29133 | MEDIUM4.4 | org.apache.commons:commons-configuration2 2.1.1 fixed in 2.10.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.4 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.5 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.6 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42250 | MEDIUM4.25 | libbz2-1.0 1.0.8-4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.31-13+deb11u3 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.31-13+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.31-13+deb11u3 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.31-13+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-28835 | MEDIUM4.25 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libgssapi-krb5-2 1.18.3-6+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libk5crypto3 1.18.3-6+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5-3 1.18.3-6+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5support0 1.18.3-6+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM4.25 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM4.13 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-4039 | MEDIUM4.08 | libgcc-s1 10.2.1-6 No fix yet | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2023-4039 | MEDIUM4.08 | libstdc++6 10.2.1-6 No fix yet | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-68161 | MEDIUM4.08 | org.apache.logging.log4j:log4j-core 2.17.1 fixed in 2.25.3 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2022-4304 | MEDIUM4.07 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 16.2% High Exploitation Risk | Post-Exploit |
| CVE-2019-8457 | MEDIUM4.06 | libdb5.3 5.3.28+dfsg1-0.8 No fix yet | 45.4% High Exploitation Risk | Post-Exploit |
| CVE-2022-37434 | MEDIUM4.06 | zlib1g 1:1.2.11.dfsg-2+deb11u1 fixed in 1:1.2.11.dfsg-2+deb11u2 | 15.9% High Exploitation Risk | Post-Exploit |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-4598 | MEDIUM4 | libsystemd0 247.3-7 fixed in 247.3-7+deb11u7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-4598 | MEDIUM4 | libudev1 247.3-7 fixed in 247.3-7+deb11u7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2018-1334 | MEDIUM4 | org.apache.spark:spark-core_2.11 2.3.0 fixed in 2.1.3, 2.2.2, 2.3.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc-bin 2.31-13+deb11u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33601 | MEDIUM4 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc6 2.31-13+deb11u3 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33601 | MEDIUM4 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-3715 | LOW3.98 | bash 5.1-2+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2020-16156 | LOW3.98 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u4 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2023-47038 | LOW3.98 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u3 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-48962 | LOW3.98 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.82 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW3.82 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-28389 | LOW3.82 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-28390 | LOW3.82 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-42497 | LOW3.82 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9538 | LOW3.82 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2020-1945 | LOW3.78 | org.apache.ant:ant 1.9.1 fixed in 1.9.15, 1.10.8 | 1.9% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69419 | LOW3.77 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW3.7 | libapt-pkg6.0 2.2.4 No fix yet | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-9143 | LOW3.7 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 6.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.4 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.9 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2013-7397 | LOW3.65 | com.ning:async-http-client 1.8.16 fixed in 1.9.0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2013-7398 | LOW3.65 | com.ning:async-http-client 1.8.16 fixed in 1.9.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2005-2541 | LOW3.6 | tar 1.34+dfsg-1 No fix yet | 4.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gpgv 2.2.27-2+deb11u2 fixed in 2.2.27-2+deb11u3 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-8058 | LOW3.57 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-8058 | LOW3.57 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u14 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-5535 | LOW3.54 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 5.6% Low-Moderate Risk | Post-Exploit |
| CVE-2024-33602 | LOW3.4 | libc-bin 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-33602 | LOW3.4 | libc6 2.31-13+deb11u3 fixed in 2.31-13+deb11u10 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-9820 | LOW3.4 | libgnutls30 3.7.1-5+deb11u1 fixed in 3.7.1-5+deb11u9 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl1.1 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-49128 | LOW3.4 | com.fasterxml.jackson.core:jackson-core 2.12.0 fixed in 2.13.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-49128 | LOW3.4 | com.fasterxml.jackson.core:jackson-core 2.4.0 fixed in 2.13.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-49128 | LOW3.4 | com.fasterxml.jackson.core:jackson-core 2.6.7 fixed in 2.13.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-49128 | LOW3.4 | com.fasterxml.jackson.core:jackson-core 2.7.8 fixed in 2.13.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-49128 | LOW3.4 | com.fasterxml.jackson.core:jackson-core 2.9.4 fixed in 2.13.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.0.52.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW3.36 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u4 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2024-4741 | LOW3.36 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 2.9% Low-Moderate Risk | Post-Exploit |
| CVE-2016-2781 | LOW3.31 | coreutils 8.32-4+b1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-15649 | LOW3.31 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-0727 | LOW3.3 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2022-48303 | LOW3.3 | tar 1.34+dfsg-1 fixed in 1.34+dfsg-1+deb11u1 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2021-36373 | LOW3.3 | org.apache.ant:ant 1.9.1 fixed in 1.9.16, 1.10.11 | 2.5% Low-Moderate Risk | Post-Exploit |
| CVE-2021-36374 | LOW3.3 | org.apache.ant:ant 1.9.1 fixed in 1.9.16, 1.10.11 | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5958 | LOW3.21 | sed 4.7-1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2022-2097 | LOW3.18 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0465 | LOW3.18 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0466 | LOW3.18 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3446 | LOW3.18 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1v-0~deb11u1 | 5.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3817 | LOW3.18 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1v-0~deb11u1 | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5678 | LOW3.18 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | mount 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2022-4450 | LOW3.1 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1n-0+deb11u4 | 20.4% High Exploitation Risk | Post-Exploit |
| CVE-2023-36479 | LOW3.1 | org.eclipse.jetty:jetty-servlets 9.3.20.v20170531 fixed in 9.4.52, 10.0.16, 11.0.16 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-69420 | LOW3.01 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-40909 | LOW3.01 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2021-34428 | LOW2.98 | org.eclipse.jetty:jetty-server 9.3.19.v20170502 fixed in 9.4.41, 10.0.3, 11.0.3 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2021-34428 | LOW2.98 | org.eclipse.jetty:jetty-server 9.3.20.v20170531 fixed in 9.4.41, 10.0.3, 11.0.3 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-45447 | LOW2.92 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2023-31484 | LOW2.92 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u4 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-31486 | LOW2.92 | perl-base 5.32.1-4+deb11u2 No fix yet | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2511 | LOW2.89 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 54.0% Actively Exploited | Post-Exploit |
| CVE-2022-1304 | LOW2.81 | e2fsprogs 1.46.2-2 fixed in 1.46.2-2+deb11u1 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2022-1304 | LOW2.81 | logsave 1.46.2-2 fixed in 1.46.2-2+deb11u1 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-4641 | LOW2.8 | login 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | mount 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-4641 | LOW2.8 | passwd 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.34+dfsg-1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-4016 | LOW2.8 | libprocps8 2:3.3.17-5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2021-36084 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2021-36085 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2021-36086 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-36087 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libsystemd0 247.3-7 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 247.3-7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libudev1 247.3-7 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 247.3-7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 11.0.2 fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 14.0.1 fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 16.0.1 fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 19.0 fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2020-8908 | LOW2.8 | com.google.guava:guava 22.0 fixed in 32.0.0-android | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | LOW2.7 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | mount 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-12087 | LOW2.7 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-28085 | LOW2.64 | bsdutils 1:2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-28085 | LOW2.64 | mount 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-28085 | LOW2.64 | util-linux 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34180 | LOW2.55 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u8 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-48959 | LOW2.55 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-48961 | LOW2.55 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | login 1:4.8.1-1 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | passwd 1:4.8.1-1 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2017-18018 | LOW2.4 | coreutils 8.32-4+b1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-30258 | LOW2.4 | gpgv 2.2.27-2+deb11u2 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpgv 2.2.27-2+deb11u2 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2013-4235 | LOW2.4 | login 1:4.8.1-1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-13176 | LOW2.4 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2013-4235 | LOW2.4 | passwd 1:4.8.1-1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2022-2047 | LOW2.29 | org.eclipse.jetty:jetty-http 9.3.19.v20170502 fixed in 9.4.47, 10.0.10, 11.0.10 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-2047 | LOW2.29 | org.eclipse.jetty:jetty-http 9.3.20.v20170531 fixed in 9.4.47, 10.0.10, 11.0.10 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-5278 | LOW2.24 | coreutils 8.32-4+b1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW2.22 | apt 2.2.4 No fix yet | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9143 | LOW2.22 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u2 | 6.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW2.04 | openssl 1.1.1n-0+deb11u3 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.8.1-1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.8.1-1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-3219 | LOW1.68 | gpgv 2.2.27-2+deb11u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | login 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | passwd 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW1.68 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-4016 | LOW1.68 | procps 2:3.3.17-5 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2023-39804 | LOW1.68 | tar 1.34+dfsg-1 fixed in 1.34+dfsg-1+deb11u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-29491 | NONE0 | libncurses6 6.2+20201114-2+deb11u1 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncurses6 6.2+20201114-2+deb11u1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | libncursesw6 6.2+20201114-2+deb11u1 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncursesw6 6.2+20201114-2+deb11u1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam-modules 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam0g 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | libtinfo6 6.2+20201114-2+deb11u1 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libtinfo6 6.2+20201114-2+deb11u1 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | ncurses-base 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.2+20201114-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | ncurses-bin 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-bin 6.2+20201114-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2017-15288 | NONE0 | org.scala-lang:scala-compiler 2.11.0 fixed in 2.10.7, 2.11.12, 2.12.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2022-29458 | NONE0 | ncurses-base 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u1 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-29458 | NONE0 | ncurses-bin 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u1 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-50495 | NONE0 | libncurses6 6.2+20201114-2+deb11u1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncursesw6 6.2+20201114-2+deb11u1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libtinfo6 6.2+20201114-2+deb11u1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.2+20201114-2 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-bin 6.2+20201114-2 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam-modules 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam0g 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-4039 | NONE0 | gcc-10-base 10.2.1-6 No fix yet | 0.7% Theoretical Threat | Not Applicable |
| CVE-2023-4039 | NONE0 | gcc-9-base 9.3.0-22 No fix yet | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam0g 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-modules 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam0g 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-6141 | NONE0 | libncurses6 6.2+20201114-2+deb11u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libncursesw6 6.2+20201114-2+deb11u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libtinfo6 6.2+20201114-2+deb11u1 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-base 6.2+20201114-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-bin 6.2+20201114-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| TEMP-0841856-B18BAF | NONE0 | bash 5.1-2+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| DLA-4485-1 | NONE0 | ca-certificates 20210119 fixed in 20230311+deb12u1~deb11u1 | — | Not Applicable |
| CVE-2025-6297 | NONE0 | dpkg 1.20.11 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-53613 | NONE0 | libblkid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libblkid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libmount1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libmount1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2025-27587 | NONE0 | libssl1.1 1.1.1n-0+deb11u3 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-53613 | NONE0 | libuuid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libuuid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | login 1:4.8.1-1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | mount 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | mount 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2025-27587 | NONE0 | openssl 1.1.1n-0+deb11u3 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | passwd 1:4.8.1-1 No fix yet | — | Not Applicable |
| CVE-2026-7010 | NONE0 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| TEMP-0517018-A83CE6 | NONE0 | sysvinit-utils 2.96-7+deb11u1 No fix yet | — | Not Applicable |
| TEMP-0290435-0B57B5 | NONE0 | tar 1.34+dfsg-1 No fix yet | — | Not Applicable |
| DLA-3972-1 | NONE0 | tzdata 2021a-1+deb11u4 fixed in 2024b-0+deb11u1 | — | Not Applicable |
| DLA-4085-1 | NONE0 | tzdata 2021a-1+deb11u4 fixed in 2025a-0+deb11u1 | — | Not Applicable |
| DLA-4105-1 | NONE0 | tzdata 2021a-1+deb11u4 fixed in 2025b-0+deb11u1 | — | Not Applicable |
| DLA-4403-1 | NONE0 | tzdata 2021a-1+deb11u4 fixed in 2025b-0+deb11u2 | — | Not Applicable |
| DLA-4569-1 | NONE0 | tzdata 2021a-1+deb11u4 fixed in 2026b-0+deb11u1 | — | Not Applicable |
| CVE-2026-53613 | NONE0 | util-linux 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | util-linux 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.12.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.4.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.6.7 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.7.8 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.9.4 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| CVE-2024-36114 | NONE0 | io.airlift:aircompressor 0.10 fixed in 0.27 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-42583 | NONE0 | io.netty:netty-codec 4.0.52.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42583 | NONE0 | io.netty:netty-codec 4.1.17.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-30474 | NONE0 | org.apache.commons:commons-vfs2 2.1 fixed in 2.10.0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2024-23454 | NONE0 | org.apache.hadoop:hadoop-common 3.1.0 fixed in 3.4.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-29869 | NONE0 | org.apache.hive:hive-exec 3.1.3 fixed in 4.0.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-23953 | NONE0 | org.apache.hive:hive-llap-common 3.1.3 fixed in 4.0.0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2024-23945 | NONE0 | org.apache.hive:hive-service 3.1.3 fixed in 4.0.0 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2026-45300 | NONE0 | org.asynchttpclient:async-http-client 2.0.37 fixed in 3.0.10, 2.15.0 | 0.3% Theoretical Threat | Not Applicable |
| GHSA-58qw-p7qm-5rvh | NONE0 | org.eclipse.jetty:jetty-xml 9.3.19.v20170502 fixed in 10.0.16, 11.0.16, 12.0.0, 9.4.52.v20230823 | — | Not Applicable |
| GHSA-58qw-p7qm-5rvh | NONE0 | org.eclipse.jetty:jetty-xml 9.3.20.v20170531 fixed in 10.0.16, 11.0.16, 12.0.0, 9.4.52.v20230823 | — | Not Applicable |