This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could cause denial of service via HTTP/2 rapid stream reset (CVE-2023-44487) or memory leak (CVE-2025-31650), and potentially achieve remote code execution via Commons BeanUtils (CVE-2025-48734). Disabling HTTP/2 support would fully mitigate the most severe DoS vulnerabilities. Upgrading the Tomcat and Commons BeanUtils packages to patched versions is strongly advised.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2023-44487 | CRITICAL9.75 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.0-M12, 10.1.14, 9.0.81, 8.5.94 | 100.0% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2025-31650 | CRITICAL9.75 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.104, 10.1.40, 11.0.6 | 66.4% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2025-48734 | HIGH8.8 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2019-17563 | HIGH8.62 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 7.0.99, 8.5.50, 9.0.30 | 10.7% High Exploitation Risk | Directly Exposed |
| CVE-2020-11996 | HIGH8.62 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 10.0.0-M5, 9.0.35, 8.5.55 | 26.7% High Exploitation Risk | Directly Exposed |
| CVE-2021-25122 | HIGH8.62 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 10.0.2, 9.0.43, 8.5.63 | 18.1% High Exploitation Risk | Directly Exposed |
| CVE-2024-24549 | HIGH8.62 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 8.5.99, 9.0.86, 10.1.19, 11.0.0-M17 | 23.1% High Exploitation Risk | Directly Exposed |
| CVE-2026-42010 | HIGH8.33 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | HIGH8.33 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-46983 | HIGH8.33 | com.alipay.sofa:hessian 3.3.6 fixed in 3.5.5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-32988 | HIGH8.2 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.4 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-5318 | HIGH8.1 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.1 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2025-5987 | HIGH8.1 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.1 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-45447 | HIGH8.1 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2020-1938 | HIGH8 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.31, 8.5.51, 7.0.100 | 99.3% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2025-24813 | HIGH8 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.3, 10.1.35, 9.0.99 | 99.9% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2025-31651 | HIGH7.84 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.104, 10.1.40, 11.0.6 | 4.2% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-6119 | HIGH7.8 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.4 | 66.6% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2025-55752 | HIGH7.8 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.11, 10.1.45, 9.0.109 | 74.0% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33845 | HIGH7.73 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45445 | HIGH7.73 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66614 | HIGH7.73 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.15, 10.1.50, 9.0.113 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-45490 | HIGH7.5 | libexpat1 2.6.1-2build1 fixed in 2.6.1-2ubuntu0.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-8176 | HIGH7.5 | libexpat1 2.6.1-2build1 fixed in 2.6.1-2ubuntu0.3 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33416 | HIGH7.5 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.6 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-7254 | HIGH7.5 | com.google.protobuf:protobuf-java 3.20.1 fixed in 3.25.5, 4.27.5, 4.28.2 | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2022-3171 | HIGH7.5 | com.google.protobuf:protobuf-java 3.20.1 fixed in 3.21.7, 3.20.3, 3.19.6, 3.16.3 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3635 | HIGH7.5 | com.squareup.okio:okio 3.2.0 fixed in 3.4.0, 1.17.6 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-41881 | HIGH7.5 | io.netty:netty-codec-haproxy 4.1.79.Final fixed in 4.1.86.Final | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2022-42252 | HIGH7.5 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 8.5.83, 9.0.68, 10.0.27, 10.1.1 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-46589 | HIGH7.5 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.0-M11, 10.1.16, 9.0.83, 8.5.96 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-34750 | HIGH7.5 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.0-M21, 10.1.25, 9.0.90 | 4.6% Low-Moderate Risk | Directly Exposed |
| CVE-2025-5372 | HIGH7.48 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-50379 | HIGH7.45 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.2, 10.1.34, 9.0.98 | 41.8% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-37371 | HIGH7.28 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-37371 | HIGH7.28 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-37371 | HIGH7.28 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-37371 | HIGH7.28 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-9484 | HIGH7.28 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 10.0.0-M5, 9.0.35, 8.5.55, 7.0.104 | 56.6% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2019-12418 | HIGH7 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 7.0.99, 8.5.49, 9.0.29 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-25329 | HIGH7 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 10.0.2, 9.0.41, 8.5.61, 7.0.108 | 9.5% Low-Moderate Risk | Directly Exposed |
| CVE-2025-32990 | MEDIUM6.97 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42013 | MEDIUM6.97 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5260 | MEDIUM6.97 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-0966 | MEDIUM6.97 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-48988 | MEDIUM6.89 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.8, 10.1.42, 9.0.106 | 53.2% Actively Exploited | Directly Exposed |
| CVE-2026-0861 | MEDIUM6.88 | libc-bin 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0861 | MEDIUM6.88 | libc6 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-25646 | MEDIUM6.88 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.5 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-24122 | MEDIUM6.79 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 10.0.0-M10, 9.0.40, 8.5.60, 7.0.107 | 22.9% High Exploitation Risk | Directly Exposed |
| CVE-2026-25210 | MEDIUM6.63 | libexpat1 2.6.1-2build1 fixed in 2.6.1-2ubuntu0.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-6020 | MEDIUM6.63 | libpam-modules 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-6020 | MEDIUM6.63 | libpam-modules-bin 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-6020 | MEDIUM6.63 | libpam-runtime 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-6020 | MEDIUM6.63 | libpam0g 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-22801 | MEDIUM6.63 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.3 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-29111 | MEDIUM6.63 | libsystemd0 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.14 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-29111 | MEDIUM6.63 | libudev1 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.14 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-46701 | MEDIUM6.5 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.105, 10.1.41, 11.0.7 | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-29857 | MEDIUM6.5 | org.bouncycastle:bcprov-jdk15on 1.69 fixed in 1.78 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33636 | MEDIUM6.46 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-41989 | MEDIUM6.38 | libgcrypt20 1.10.3-2build1 fixed in 1.10.3-2ubuntu0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-33846 | MEDIUM6.38 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-42009 | MEDIUM6.38 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-31115 | MEDIUM6.38 | liblzma5 5.6.1+really5.4.5-1 fixed in 5.6.1+really5.4.5-1ubuntu0.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | libnghttp2-14 1.59.0-1ubuntu0.1 fixed in 1.59.0-1ubuntu0.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-3731 | MEDIUM6.38 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28388 | MEDIUM6.38 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-28389 | MEDIUM6.38 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28390 | MEDIUM6.38 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-6378 | MEDIUM6.38 | ch.qos.logback:logback-classic 1.3.5 fixed in 1.3.12, 1.4.12, 1.2.13 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-6378 | MEDIUM6.38 | ch.qos.logback:logback-core 1.3.5 fixed in 1.3.12, 1.4.12, 1.2.13 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-3509 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.20.1 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2022-3510 | MEDIUM6.38 | com.google.protobuf:protobuf-java 3.20.1 fixed in 3.16.3, 3.19.6, 3.20.3, 3.21.7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-55163 | MEDIUM6.38 | io.grpc:grpc-netty-shaded 1.53.0 fixed in 1.75.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-32731 | MEDIUM6.38 | io.grpc:grpc-protobuf 1.53.0 fixed in 1.53.1, 1.54.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-44893 | MEDIUM6.38 | io.netty:netty-codec-haproxy 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-48059 | MEDIUM6.38 | io.netty:netty-codec-haproxy 4.1.79.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45292 | MEDIUM6.38 | io.opentelemetry:opentelemetry-api 1.29.0 fixed in 1.62.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk15on 1.69 fixed in 1.84 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | org.lz4:lz4-java 1.8.0 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-3833 | MEDIUM6.29 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42011 | MEDIUM6.29 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-10963 | MEDIUM6.29 | libpam-modules 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-10963 | MEDIUM6.29 | libpam-modules-bin 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-10963 | MEDIUM6.29 | libpam-runtime 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-10963 | MEDIUM6.29 | libpam0g 1.5.3-5ubuntu5.1 fixed in 1.5.3-5ubuntu5.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-43869 | MEDIUM6.21 | org.apache.thrift:libthrift 0.14.1 fixed in 0.23.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41293 | MEDIUM6.21 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.118, 10.1.55, 11.0.22 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-41080 | MEDIUM6.1 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 8.5.93, 9.0.80, 10.1.13, 11.0.0-M11 | 6.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-21733 | MEDIUM6.09 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 8.5.64 | 14.3% High Exploitation Risk | Directly Exposed |
| CVE-2026-42012 | MEDIUM6.03 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-64720 | MEDIUM6.03 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-65018 | MEDIUM6.03 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-66293 | MEDIUM6.03 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22695 | MEDIUM6.03 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4878 | MEDIUM5.95 | libcap2 1:2.66-5ubuntu2 fixed in 1:2.66-5ubuntu2.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-50602 | MEDIUM5.9 | libexpat1 2.6.1-2build1 fixed in 2.6.1-2ubuntu0.2 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-2236 | MEDIUM5.9 | libgcrypt20 1.10.3-2build1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1-6 4.19.0-3build1 fixed in 4.19.0-3ubuntu0.24.04.2 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-45491 | MEDIUM5.88 | libexpat1 2.6.1-2build1 fixed in 2.6.1-2ubuntu0.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-45492 | MEDIUM5.88 | libexpat1 2.6.1-2build1 fixed in 2.6.1-2ubuntu0.1 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42014 | MEDIUM5.61 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.6 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4741 | MEDIUM5.6 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | libc-bin 2.39-0ubuntu8.2 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.39-0ubuntu8.2 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | libc6 2.39-0ubuntu8.2 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.39-0ubuntu8.2 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-6395 | MEDIUM5.52 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-5351 | MEDIUM5.52 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-43512 | MEDIUM5.52 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.118, 10.1.55, 11.0.22 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42498 | MEDIUM5.52 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.118, 10.1.55, 11.0.22 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.8.0 fixed in 1.8.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libsystemd0 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.14 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libsystemd0 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.16 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libudev1 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.14 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libudev1 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.16 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-11226 | MEDIUM5.44 | ch.qos.logback:logback-core 1.3.5 fixed in 1.5.19, 1.3.16 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-0964 | MEDIUM5.35 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-12243 | MEDIUM5.3 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-32989 | MEDIUM5.3 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.4 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4603 | MEDIUM5.3 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12133 | MEDIUM5.3 | libtasn1-6 4.19.0-3build1 fixed in 4.19.0-3ubuntu0.24.04.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-53506 | MEDIUM5.3 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.107, 10.1.43, 11.0.9 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2023-42795 | MEDIUM5.3 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 10.1.14, 9.0.81, 8.5.94, 11.0.0-M12 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45648 | MEDIUM5.3 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.0-M12, 10.1.14, 9.0.81, 8.5.94 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2025-61795 | MEDIUM5.3 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.12, 10.1.47, 9.0.110 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-28162 | MEDIUM5.27 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.4 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-1390 | MEDIUM5.18 | libcap2 1:2.66-5ubuntu2 fixed in 1:2.66-5ubuntu2.2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-64506 | MEDIUM5.18 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc-bin 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.39-0ubuntu8.2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc6 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.39-0ubuntu8.2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.02 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-30171 | MEDIUM5.02 | org.bouncycastle:bcprov-jdk15on 1.69 fixed in 1.78 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2024-2511 | MEDIUM4.81 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2020-1935 | MEDIUM4.8 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 7.0.100, 8.5.51, 9.0.31 | 9.4% Low-Moderate Risk | Directly Exposed |
| CVE-2025-5702 | MEDIUM4.76 | libc-bin 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-5702 | MEDIUM4.76 | libc6 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | libc-bin 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | libc6 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.4 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66382 | MEDIUM4.67 | libexpat1 2.6.1-2build1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-26462 | MEDIUM4.67 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-26462 | MEDIUM4.67 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-26462 | MEDIUM4.67 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-26462 | MEDIUM4.67 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0967 | MEDIUM4.67 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-12798 | MEDIUM4.67 | ch.qos.logback:logback-core 1.3.5 fixed in 1.5.13, 1.3.15 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-33202 | MEDIUM4.67 | org.bouncycastle:bcprov-jdk15on 1.69 fixed in 1.70 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-43515 | MEDIUM4.59 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.118, 10.1.55, 11.0.22 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc-bin 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc-bin 2.39-0ubuntu8.2 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc6 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc6 2.39-0ubuntu8.2 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | libfreetype6 2.13.2+dfsg-1build3 fixed in 2.13.2+dfsg-1ubuntu0.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-14831 | MEDIUM4.5 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | MEDIUM4.5 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | liblzma5 5.6.1+really5.4.5-1 fixed in 5.6.1+really5.4.5-1ubuntu0.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-32732 | MEDIUM4.5 | io.grpc:grpc-protobuf 1.53.0 fixed in 1.53.1, 1.54.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk15on 1.69 fixed in 1.79 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-33201 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.69 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-34447 | MEDIUM4.5 | org.bouncycastle:bcprov-jdk15on 1.69 fixed in 1.78 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.7 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-28164 | MEDIUM4.25 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.4 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM4.25 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-1225 | MEDIUM4.25 | ch.qos.logback:logback-core 1.3.5 fixed in 1.5.25 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 48.7% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 48.7% High Exploitation Risk | Post-Exploit |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.39.3-9ubuntu6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.39.3-9ubuntu6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.39.3-9ubuntu6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-8114 | MEDIUM4 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-4598 | MEDIUM4 | libsystemd0 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-4598 | MEDIUM4 | libudev1 255.4-1ubuntu8.1 fixed in 255.4-1ubuntu8.8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.39.3-9ubuntu6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-9681 | LOW3.9 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.5 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.5 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.82 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW3.82 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-28389 | LOW3.82 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-28390 | LOW3.82 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-4877 | LOW3.82 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | LOW3.77 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW3.77 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-64505 | LOW3.74 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34757 | LOW3.74 | libpng16-16t64 1.6.43-5build1 fixed in 1.6.43-5ubuntu0.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-3596 | LOW3.73 | libgssapi-krb5-2 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.3 | 14.9% High Exploitation Risk | Post-Exploit |
| CVE-2024-3596 | LOW3.73 | libk5crypto3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.3 | 14.9% High Exploitation Risk | Post-Exploit |
| CVE-2024-3596 | LOW3.73 | libkrb5-3 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.3 | 14.9% High Exploitation Risk | Post-Exploit |
| CVE-2024-3596 | LOW3.73 | libkrb5support0 1.20.1-6ubuntu2 fixed in 1.20.1-6ubuntu2.3 | 14.9% High Exploitation Risk | Post-Exploit |
| CVE-2024-56406 | LOW3.72 | perl-base 5.38.2-3.2build2 fixed in 5.38.2-3.2ubuntu0.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2024-9143 | LOW3.7 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.5 | 6.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.12.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-52520 | LOW3.7 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.9, 10.1.43, 9.0.107 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-49125 | LOW3.7 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.8, 10.1.42, 9.0.106 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-31879 | LOW3.66 | wget 1.21.4-1ubuntu4.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-24880 | LOW3.65 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.116, 10.1.52, 11.0.20 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25854 | LOW3.65 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.116, 10.1.53, 11.0.20 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-68973 | LOW3.57 | gpgv 2.4.4-2ubuntu17 fixed in 2.4.4-2ubuntu17.4 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-8058 | LOW3.57 | libc-bin 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-8058 | LOW3.57 | libc6 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-11053 | LOW3.54 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.6 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-11053 | LOW3.54 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.6 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-5535 | LOW3.54 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 5.6% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6119 | LOW3.51 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.4 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2026-1965 | LOW3.47 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-1965 | LOW3.47 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-4438 | LOW3.4 | libc-bin 2.39-0ubuntu8.2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libc6 2.39-0ubuntu8.2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-9820 | LOW3.4 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW3.36 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.6 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2024-4741 | LOW3.36 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 2.9% Low-Moderate Risk | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.4 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.4 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5958 | LOW3.21 | sed 4.9-2build1 fixed in 4.9-2ubuntu0.24.04.1 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-4603 | LOW3.18 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3832 | LOW3.15 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5419 | LOW3.15 | libgnutls30t64 3.8.3-1.1ubuntu3.1 fixed in 3.8.3-1.1ubuntu3.6 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3t64 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-24733 | LOW3.15 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 11.0.15, 10.1.50, 9.0.113 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-43514 | LOW3.15 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.118, 10.1.55, 11.0.22 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-4878 | LOW3.06 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-31790 | LOW3.01 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-40909 | LOW3.01 | perl-base 5.38.2-3.2build2 fixed in 5.38.2-3.2ubuntu0.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-2511 | LOW2.89 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.2 | 54.0% Actively Exploited | Post-Exploit |
| CVE-2025-45582 | LOW2.86 | tar 1.35+dfsg-3build1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-0965 | LOW2.8 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 255.4-1ubuntu8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 255.4-1ubuntu8.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-12801 | LOW2.8 | ch.qos.logback:logback-core 1.3.5 fixed in 1.5.13, 1.3.15 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45445 | LOW2.78 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.9 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-7264 | LOW2.69 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.2 | 16.2% High Exploitation Risk | Post-Exploit |
| CVE-2024-7264 | LOW2.69 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.2 | 16.2% High Exploitation Risk | Post-Exploit |
| CVE-2026-0968 | LOW2.63 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-8277 | LOW2.63 | libssh-4 0.10.6-2build2 fixed in 0.10.6-2ubuntu0.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | LOW2.55 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | LOW2.48 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | LOW2.48 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | LOW2.48 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.9 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.39.3-9ubuntu6 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-30258 | LOW2.4 | gpgv 2.4.4-2ubuntu17 fixed in 2.4.4-2ubuntu17.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.39.3-9ubuntu6 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-13176 | LOW2.4 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.39.3-9ubuntu6 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-9143 | LOW2.22 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.5 | 6.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-24515 | LOW2.12 | libexpat1 2.6.1-2build1 fixed in 2.6.1-2ubuntu0.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW2.04 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.7 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.0.13-0ubuntu3.1 fixed in 3.0.13-0ubuntu3.11 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.13+dfsg1-4ubuntu3 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.13+dfsg1-4ubuntu3 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-0861 | NONE0 | locales 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-4437 | NONE0 | locales 2.39-0ubuntu8.2 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-6238 | NONE0 | locales 2.39-0ubuntu8.2 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-15281 | NONE0 | locales 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-5435 | NONE0 | locales 2.39-0ubuntu8.2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-5702 | NONE0 | locales 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-0395 | NONE0 | locales 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-0915 | NONE0 | locales 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.7 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-4046 | NONE0 | locales 2.39-0ubuntu8.2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-8058 | NONE0 | locales 2.39-0ubuntu8.2 fixed in 2.39-0ubuntu8.6 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-4438 | NONE0 | locales 2.39-0ubuntu8.2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-0167 | NONE0 | curl 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-2219 | NONE0 | dpkg 1.22.6ubuntu6 fixed in 1.22.6ubuntu6.6 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6297 | NONE0 | dpkg 1.22.6ubuntu6 fixed in 1.22.6ubuntu6.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-0167 | NONE0 | libcurl4t64 8.5.0-2ubuntu10.1 fixed in 8.5.0-2ubuntu10.8 | 0.6% Theoretical Threat | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.15.2 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| CVE-2026-41284 | NONE0 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.118, 10.1.55, 11.0.22 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-43513 | NONE0 | org.apache.tomcat.embed:tomcat-embed-core 8.5.46 fixed in 9.0.118, 10.1.55, 11.0.22 | 0.5% Theoretical Threat | Not Applicable |