Known vulnerabilities in Cryostat

Software: Cryostat
Software CPE: cpe:2.3:a:red_hat:cryostat:*:*:*:*:*:*:*:*
Total vulnerabilities: 156
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cryostat Cryostat is affected by 156 known vulnerabilities: 22 high, 94 medium, 40 low Critical High Medium Low

Vulnerabilities (156)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117610 - Insufficient Verification of Data Authenticity
CVE-2025-40778
CWE-345 Medium
Available
No
4.1.0 23.10.2025 SB2025102373
SB2025102393
SB20251023133
and 60 more
#VU117604 - Predictable Seed in Pseudo-Random Number Generator (PRNG)
CVE-2025-40780
CWE-337 Medium
No
No
4.1.0 23.10.2025 SB2025102373
SB2025102393
SB20251023133
and 41 more
#VU117577 - Resource exhaustion
CVE-2025-8677
CWE-400 Medium
No
No
4.1.0 23.10.2025 SB2025102373
SB2025102393
SB20251023133
and 28 more
#VU117332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-59343
CWE-22 High
No
No
4.0.3 17.10.2025 SB2025101702
SB2025101703
SB2025101704
and 22 more
#VU116213 - Out-of-bounds write
CVE-2025-9230
CWE-787 Medium
No
No
4.1.0 01.10.2025 SB2025100119
SB2025100132
SB2025100133
and 108 more
#VU114770 - Authentication Bypass by Alternate Name
CVE-2025-8415
CWE-289 High
No
No
- 03.09.2025 SB2025090351
#VU114760 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-58056
CWE-444 Medium
No
No
4.1.0 03.09.2025 SB2025090340
SB2025090949
SB20251008161
and 39 more
#VU114080 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-47907
CWE-362 Low
No
No
4.1.0 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 50 more
#VU113156 - Memory corruption
CVE-2025-6965
CWE-119 Medium
No
No
4.1.0 22.07.2025 SB2025072254
SB2025072807
SB2025072890
and 100 more
#VU113028 - Permissions, Privileges, and Access Controls
CVE-2024-56433
CWE-264 Medium
No
No
4.1.0 17.07.2025 SB2025071777
SB2025071778
SB2025071779
and 5 more
#VU112995 - NULL Pointer Dereference
CVE-2025-6395
CWE-476 Medium
No
No
4.0.3 16.07.2025 SB20250716122
SB20250716124
SB20250716141
and 70 more
#VU112994 - NULL Pointer Dereference
CVE-2025-32990
CWE-476 Low
No
No
4.0.3 16.07.2025 SB20250716122
SB20250716123
SB20250716124
and 79 more
#VU112993 - Double Free
CVE-2025-32988
CWE-415 Medium
No
No
4.0.3 16.07.2025 SB20250716122
SB20250716124
SB20250716141
and 73 more
#VU112992 - Heap-based Buffer Overflow
CVE-2025-32989
CWE-122 High
No
No
4.0.3 16.07.2025 SB20250716122
SB20250716124
SB20250716141
and 46 more
#VU112980 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-53905
CWE-22 High
No
No
4.1.0 16.07.2025 SB2025071691
SB2025071770
SB2025071771
and 23 more
#VU112979 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-53906
CWE-22 High
No
No
4.1.0 16.07.2025 SB2025071690
SB2025071770
SB2025071771
and 29 more
#VU105983 - Resource exhaustion
CVE-2025-30204
CWE-400 Medium
No
No
4.0.0 24.03.2025 SB2025032475
SB2025032730
SB2025040333
and 97 more
#VU105946 - Use After Free
CVE-2025-24855
CWE-416 High
No
No
4.0.0 21.03.2025 SB2025031964
SB2025032154
SB2025032155
and 63 more
#VU105461 - Resource exhaustion
CVE-2025-22868
CWE-400 Medium
No
No
4.0.0 10.03.2025 SB2025031013
SB2025031015
SB2025031076
and 89 more
#VU101868 - Resource exhaustion
CVE-2024-45338
CWE-400 Medium
No
No
- 19.12.2024 SB2024121932
SB2024123101
SB2025010619
and 137 more


Showing elements 1 - 20 out of 156