Last scanned:
AI verdict failed due to an error.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-15467 | MEDIUM6.76 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2026-31789 | MEDIUM5 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | MEDIUM4.86 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45445 | MEDIUM4.64 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | MEDIUM4.5 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | MEDIUM4.5 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | MEDIUM4.5 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | MEDIUM4.5 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28387 | MEDIUM4.13 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.82 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW3.77 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW3.77 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-11187 | LOW3.66 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9231 | LOW3.54 | openssl 3.5.0-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-31790 | LOW3.54 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42764 | LOW3.54 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9230 | LOW3.36 | openssl 3.5.0-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 8.14.1-r0 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-2673 | LOW3.31 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34181 | LOW3.21 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42768 | LOW3.21 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | curl 8.14.1-r0 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-15468 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-66199 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-15469 | LOW2.8 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | curl 8.14.1-r0 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69418 | LOW2.04 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW1.86 | openssl 3.5.0-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-45674 | NONE0 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-47691 | NONE0 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-31789 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-15467 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Not Applicable |
| CVE-2026-31789 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-15467 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Not Applicable |
| CVE-2026-42581 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-66516 | NONE0 | org.apache.tika:tika-core 1.28.4 fixed in 3.2.2 | 79.8% Actively Exploited | Not Applicable |
| CVE-2026-45445 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-45445 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42579 | NONE0 | io.netty:netty-codec-dns 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-42584 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-49268 | NONE0 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.1, 3.0.0-alpha-2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-2332 | NONE0 | org.eclipse.jetty:jetty-http 12.0.17 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-48734 | NONE0 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2025-67030 | NONE0 | org.codehaus.plexus:plexus-utils 3.5.1 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-28387 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-45447 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-25646 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.55-r0 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-28387 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-45447 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-54512 | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-54513 | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-44249 | NONE0 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Not Applicable |
| CVE-2019-7611 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.15, 6.6.1 | 2.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-22801 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-40200 | NONE0 | musl 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-40200 | NONE0 | musl-utils 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22184 | NONE0 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-8698 | NONE0 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 22.0.13, 24.0.8, 25.0.6 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-33636 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-33630 | NONE0 | c-ares 1.34.5-r0 fixed in 1.34.8-r0 | — | Not Applicable |
| CVE-2026-41254 | NONE0 | lcms2 2.16-r0 fixed in 2.19-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69421 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-28388 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-28389 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-28390 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-34183 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-33416 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-69421 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-28388 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-28389 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-28390 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-34183 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-27135 | NONE0 | nghttp2-libs 1.65.0-r0 fixed in 1.68.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-2100 | NONE0 | p11-kit 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-2100 | NONE0 | p11-kit-trust 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-7962 | NONE0 | com.sun.mail:jakarta.mail 1.6.7 fixed in 1.6.8, 2.0.2 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-42583 | NONE0 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-59901 | NONE0 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-58057 | NONE0 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-33870 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42587 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-55831 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-55833 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-56745 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-42585 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56746 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-59899 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-58056 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-55163 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-33871 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-42587 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-56819 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-48043 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-45416 | NONE0 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-50010 | NONE0 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42578 | NONE0 | io.netty:netty-handler-proxy 4.1.119.Final fixed in 4.1.133.Final, 4.2.13.Final | 1.0% Theoretical Threat | Not Applicable |
| CVE-2024-57699 | NONE0 | net.minidev:json-smart 2.5.0 fixed in 2.5.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-3505 | NONE0 | org.bouncycastle:bcpg-jdk15to18 1.78.1 fixed in 1.84 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-5588 | NONE0 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-5588 | NONE0 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-14813 | NONE0 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-5598 | NONE0 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.80.2 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-14813 | NONE0 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.80.2, 1.81.1, 1.84 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-64518 | NONE0 | org.cyclonedx:cyclonedx-core-java 9.1.0 fixed in 11.0.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-1605 | NONE0 | org.eclipse.jetty:jetty-server 12.0.17 fixed in 12.1.6, 12.0.32 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-10051 | NONE0 | org.eclipse.jetty:jetty-server 12.0.17 fixed in 12.0.36, 12.1.10 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-31418 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.13, 8.9.0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2024-23444 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 8.13.0, 7.17.23 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-43709 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.21, 8.13.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-52979 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.25, 8.16.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-7307 | NONE0 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.6.2 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-42198 | NONE0 | org.postgresql:postgresql 42.7.2 fixed in 42.7.11 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-41249 | NONE0 | org.springframework:spring-core 6.1.15 fixed in 6.2.11 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-41848 | NONE0 | org.springframework:spring-core 6.1.15 fixed in 7.0.8, 6.2.19 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-41851 | NONE0 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69419 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-34182 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69419 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-34182 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-22235 | NONE0 | org.springframework.boot:spring-boot 3.3.6 fixed in 3.3.11, 3.4.5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-64720 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-65018 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-66293 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22695 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-40973 | NONE0 | org.springframework.boot:spring-boot 3.3.6 fixed in 4.0.6, 3.5.14 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-45673 | NONE0 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-2673 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-5545 | NONE0 | libcurl 8.14.1-r0 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-2673 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-59888 | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-67735 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-41417 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42580 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-59900 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-43827 | NONE0 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-43828 | NONE0 | org.apache.shiro:shiro-web 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-0636 | NONE0 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-0636 | NONE0 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-11143 | NONE0 | org.eclipse.jetty:jetty-http 12.0.17 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2020-7019 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.9.0, 6.8.12 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2021-22144 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.17, 7.13.3 | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2023-49921 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.16, 8.11.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-11226 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.19, 1.3.16 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-34181 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-42768 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-34181 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-42768 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-9341 | NONE0 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-11187 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Not Applicable |
| CVE-2025-64506 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-11187 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-22227 | NONE0 | io.projectreactor.netty:reactor-netty-http 1.0.39 fixed in 1.3.0-M5, 1.2.8 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2018-3824 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.9, 6.2.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-62408 | NONE0 | c-ares 1.34.5-r0 fixed in 1.34.6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-9231 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-31790 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-42764 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-15468 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-66199 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69420 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-22796 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-42769 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42770 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-9076 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-9231 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-31790 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-42764 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-15468 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-66199 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69420 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-22796 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-42769 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42770 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-9076 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-13151 | NONE0 | libtasn1 4.20.0-r0 fixed in 4.21.0-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-9340 | NONE0 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2019-7614 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.2, 7.2.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-41850 | NONE0 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-59921 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-9230 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2025-9230 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2025-15469 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22795 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-7383 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-15469 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22795 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-7383 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-6042 | NONE0 | musl 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-6042 | NONE0 | musl-utils 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27171 | NONE0 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-42766 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-42767 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-9086 | NONE0 | libcurl 8.14.1-r0 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2026-42766 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-42767 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-54514 | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-54515 | NONE0 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-48976 | NONE0 | commons-fileupload:commons-fileupload 1.5 fixed in 1.6.0 | 67.3% Actively Exploited | Not Applicable |
| CVE-2026-50020 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-59898 | NONE0 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-47244 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-50560 | NONE0 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-8916 | NONE0 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-8916 | NONE0 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2021-22135 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2021-22137 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-2575 | NONE0 | org.keycloak:keycloak-saml-adapter-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-2575 | NONE0 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-41852 | NONE0 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-34180 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-34180 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-1225 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.25 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2020-7021 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.14, 7.10.0 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2025-10148 | NONE0 | libcurl 8.14.1-r0 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-68160 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-68160 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-64505 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-34757 | NONE0 | libpng 1.6.47-r0 fixed in 1.6.57-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-47554 | NONE0 | commons-io:commons-io 2.8.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-69418 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-69418 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-45536 | NONE0 | io.netty:netty-transport-native-epoll 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-45536 | NONE0 | io.netty:netty-transport-native-kqueue 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-12194 | NONE0 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.2 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-45446 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-45446 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-48924 | NONE0 | org.apache.commons:commons-lang3 3.13.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-46394 | NONE0 | ssl_client 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-9232 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2025-9232 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2020-7020 | NONE0 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.13, 7.9.2 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-23901 | NONE0 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.1.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-9092 | NONE0 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-4575 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.1-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-4575 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.1-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-4575 | NONE0 | openssl 3.5.0-r0 fixed in 3.5.1-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-10532 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.34 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-9828 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.33 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-mfg7-5gfp-c4w3 | NONE0 | io.netty:netty-codec-dns 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty.ee8:jetty-ee8-security 12.0.17 fixed in 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 12.0.17 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-6790 | NONE0 | org.eclipse.jetty:jetty-server 12.0.17 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-8384 | NONE0 | org.eclipse.jetty:jetty-util 12.0.17 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-22233 | NONE0 | org.springframework:spring-context 6.1.15 fixed in 6.2.7, 6.1.20 | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.