Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Quarkus HIGH 7.5
CVE-2026-50559

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.…

Fix: 3.20.6.2 / 3.27.4.1+
Fix from $1,950 2026-06-19
Quarkus HIGH 8.2
CVE-2026-39852

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, …

Fix: 3.20.6.1 / 3.27.3.1+
Fix from $1,950 2026-05-05
Quarkus HIGH 7.5
CVE-2025-66560

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerabi…

Fix: 3.20.5 / 3.27.2+
Fix from $1,950 2026-01-07
Quarkus CRITICAL 9.1
CVE-2024-12225

A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for regist…

Fix: 3.15.3.1+
Fix from $2,300 2025-05-06
Quarkus CRITICAL 9.8
CVE-2023-6267

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is …

Fix: 2.13.9 / 3.2.9+
Fix from $2,300 2024-01-25
Quarkus HIGH 7.5
CVE-2023-5720

A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information…

Fix: 3.2.8+
Fix from $1,950 2023-11-15
Quarkus HIGH 7.5
CVE-2023-1584

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, w…

Fix: 2.13.8+
Fix from $1,950 2023-10-04
Quarkus HIGH 7.5
CVE-2022-4147

Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the …

Fix: 2.13.5 / 2.14.2+
Fix from $1,950 2022-12-06
Quarkus CRITICAL 9.8
CVE-2022-2466

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

Fix: 2.10.4+
Fix from $2,300 2022-08-31
Quarkus HIGH 8.8
CVE-2022-0981

A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This fla…

Fix: 2.7.1+
Fix from $1,950 2022-03-23