Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
H2o
HIGH 8.2
CVE-2023-6569
External Control of File Name or Path in h2oai/h2o-3
No fix yet
Fix from $1,950
2023-12-14
H2o
HIGH 7.5
CVE-2023-6038
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the ser…
No fix yet
Fix from $1,950
2023-11-16
H2o
HIGH 7.1
CVE-2023-6017
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
No fix yet
Fix from $1,950
2023-11-16
H2o
MEDIUM 5.4
CVE-2023-6013
H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.
No fix yet
Fix from $1,600
2023-11-16
H2o
CRITICAL 9.8
CVE-2023-6016EPSS 31%
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
No fix yet
Fix from $2,300
2023-11-16