cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-21211,https://securityvulnerability.io/vulnerability/CVE-2024-21211,Vulnerability in Oracle Java SE and GraalVM Products Exploitable by Unauthenticated Attackers,"A vulnerability exists in Oracle's Java SE and GraalVM products that allows unauthenticated attackers with network access through various protocols to compromise system integrity. Successful exploitation could enable unauthorized updates, inserts, or deletions of data accessible through these platforms. The vulnerability poses a risk particularly in Java deployments utilizing sandboxed environments for running untrusted code, such as Java Web Start applications or applets. Developers and administrators should review and mitigate potential impacts following Oracle's advisory.",Oracle,"Graalvm,Oracle Java Se",3.7,LOW,0.0004299999854993075,false,false,false,false,,false,false,2024-10-15T19:52:41.883Z,0 CVE-2024-21003,https://securityvulnerability.io/vulnerability/CVE-2024-21003,Java SE and GraalVM Enterprise Edition Vulnerability in Oracle Products,"A vulnerability exists in Oracle Java SE and GraalVM Enterprise Edition that allows an unauthenticated attacker with network access via multiple protocols to potentially compromise affected systems. Exploitation requires human interaction from a user other than the attacker. Successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data in environments where untrusted code is loaded, such as sandboxed Java Web Start applications or applets. This vulnerability poses risks in client-side deployments but does not impact server environments running only trusted code.",Oracle,"Jdk,Jre,Graalvm",3.1,LOW,0.0004299999854993075,false,false,false,false,,false,false,2024-04-16T22:15:00.000Z,0 CVE-2024-21098,https://securityvulnerability.io/vulnerability/CVE-2024-21098,Oracle GraalVM for JDK Vulnerability Could Lead to Partial Denial of Service,"Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",Oracle,"Graalvm,Graalvm For Jdk",3.7,LOW,0.0004299999854993075,false,false,false,false,,false,false,2024-04-16T22:15:00.000Z,0 CVE-2024-20954,https://securityvulnerability.io/vulnerability/CVE-2024-20954,Vulnerability in Oracle GraalVM for JDK and Enterprise Edition,"A vulnerability exists within the Oracle GraalVM for JDK and the GraalVM Enterprise Edition, affecting specific versions of these products. Unauthenticated attackers with network access can exploit this vulnerability via multiple protocols, potentially gaining unauthorized read access to a subset of accessible data. The vulnerability complicates security measures, making it crucial for users to review their configurations and implement necessary updates to safeguard against potential data exfiltration.",Oracle,"Graalvm,Graalvm For Jdk",,,0.0004299999854993075,false,false,false,false,,false,false,2024-04-16T22:15:00.000Z,0 CVE-2024-20955,https://securityvulnerability.io/vulnerability/CVE-2024-20955,Vulnerability in Oracle GraalVM for JDK and Enterprise Edition by Oracle,"A security vulnerability exists in Oracle GraalVM for JDK and GraalVM Enterprise Edition, allowing unauthenticated attackers with network access via multiple protocols to potentially gain unauthorized read access to certain data subsets. The affected versions span across both JDK and Enterprise Edition products, making it vital for users to evaluate the impact on sensitive data. This vulnerability is particularly concerning as it exposes confidential information without requiring authentication.",Oracle,GraalVM Enterprise Edition,3.7,LOW,0.0006099999882280827,false,false,false,false,,false,false,2024-01-16T21:41:20.952Z,0 CVE-2023-22091,https://securityvulnerability.io/vulnerability/CVE-2023-22091,,"Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.8, 21; Oracle GraalVM Enterprise Edition: 20.3.11, 21.3.7 and 22.3.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",Oracle,Graalvm Enterprise Edition,4.8,MEDIUM,0.0006099999882280827,false,false,false,false,,false,false,2023-10-17T22:15:00.000Z,0 CVE-2023-22051,https://securityvulnerability.io/vulnerability/CVE-2023-22051,,"Vulnerability in the Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: GraalVM Compiler). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",Oracle,Graalvm Enterprise Edition,3.7,LOW,0.0006099999882280827,false,false,false,false,,false,false,2023-07-18T21:15:00.000Z,0 CVE-2023-21986,https://securityvulnerability.io/vulnerability/CVE-2023-21986,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Native Image). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GraalVM Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 5.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L).",Oracle,Graalvm Enterprise Edition,5.7,MEDIUM,0.00044999999227002263,false,false,false,false,,false,false,2023-04-18T20:15:00.000Z,0 CVE-2022-21634,https://securityvulnerability.io/vulnerability/CVE-2022-21634,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: LLVM Interpreter). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",Oracle,Graalvm Enterprise Edition,7.5,HIGH,0.00044999999227002263,false,false,false,false,,false,false,2022-10-18T00:00:00.000Z,0 CVE-2022-21597,https://securityvulnerability.io/vulnerability/CVE-2022-21597,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaScript). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",Oracle,Graalvm Enterprise Edition,5.3,MEDIUM,0.00044999999227002263,false,false,false,false,,false,false,2022-10-18T00:00:00.000Z,0 CVE-2020-14803,https://securityvulnerability.io/vulnerability/CVE-2020-14803,,"Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",Oracle,"Java Se Jdk And Jre,Graalvm Enterprise Edition",5.3,MEDIUM,0.0031799999997019768,false,false,false,false,,false,false,2020-10-21T14:04:26.000Z,0 CVE-2020-14718,https://securityvulnerability.io/vulnerability/CVE-2020-14718,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: JVMCI). Supported versions that are affected are 19.3.2 and 20.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",Oracle,Graalvm Enterprise Edition,7.2,HIGH,0.00279000005684793,false,false,false,false,,false,false,2020-07-15T17:34:35.000Z,0 CVE-2020-2900,https://securityvulnerability.io/vulnerability/CVE-2020-2900,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Tools). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N).",Oracle,Graalvm Enterprise Edition,3.7,LOW,0.000539999979082495,false,false,false,false,,false,false,2020-04-15T13:29:51.000Z,0 CVE-2020-2799,https://securityvulnerability.io/vulnerability/CVE-2020-2799,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM Enterprise Edition accessible data. CVSS 3.0 Base Score 6.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N).",Oracle,Graalvm Enterprise Edition,6.3,MEDIUM,0.000539999979082495,false,false,false,false,,false,false,2020-04-15T13:29:46.000Z,0 CVE-2020-2802,https://securityvulnerability.io/vulnerability/CVE-2020-2802,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).",Oracle,Graalvm Enterprise Edition,7.7,HIGH,0.000590000010561198,false,false,false,false,,false,false,2020-04-15T13:29:46.000Z,0 CVE-2020-2595,https://securityvulnerability.io/vulnerability/CVE-2020-2595,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). The supported version that is affected is 19.3.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. CVSS 3.0 Base Score 5.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).",Oracle,Graalvm Enterprise Edition,5.8,MEDIUM,0.0008900000248104334,false,false,false,false,,false,false,2020-01-15T16:34:02.000Z,0 CVE-2020-2581,https://securityvulnerability.io/vulnerability/CVE-2020-2581,,Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: LLVM Interpreter). The supported version that is affected is 19.3.0.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.0 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).,Oracle,Graalvm Enterprise Edition,4,MEDIUM,0.0006600000197067857,false,false,false,false,,false,false,2020-01-15T16:34:01.000Z,0 CVE-2019-2986,https://securityvulnerability.io/vulnerability/CVE-2019-2986,,"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: LLVM Interpreter). The supported version that is affected is 19.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).",Oracle,Graalvm Enterprise Edition,7.7,HIGH,0.000590000010561198,false,false,false,false,,false,false,2019-10-16T17:40:57.000Z,0 CVE-2019-2862,https://securityvulnerability.io/vulnerability/CVE-2019-2862,,"Vulnerability in the Oracle GraalVM Enterprise Edition component of Oracle GraalVM (subcomponent: Java). The supported version that is affected is 19.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.0 Base Score 6.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H).",Oracle,Graalvm Enterprise Edition,6.8,MEDIUM,0.0008299999753944576,false,false,false,false,,false,false,2019-07-23T23:15:00.000Z,0 CVE-2019-2813,https://securityvulnerability.io/vulnerability/CVE-2019-2813,,"Vulnerability in the Oracle GraalVM Enterprise Edition component of Oracle GraalVM (subcomponent: GraalVM). The supported version that is affected is 19.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).",Oracle,Graalvm Enterprise Edition,7.7,HIGH,0.000590000010561198,false,false,false,false,,false,false,2019-07-23T23:15:00.000Z,0