Known vulnerabilities in Cryostat - page 4

Software: Cryostat
Software CPE: cpe:2.3:a:red_hat:cryostat:*:*:*:*:*:*:*:*
Total vulnerabilities: 156
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cryostat Cryostat is affected by 156 known vulnerabilities: 22 high, 94 medium, 40 low Critical High Medium Low

Vulnerabilities (156)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU92075 - UNIX Symbolic Link (Symlink) Following
CVE-2024-35235
CWE-61 Low
Available
No
- 13.06.2024 SB2024061389
SB2024061398
SB2024061399
and 29 more
#VU89219 - Observable discrepancy
CVE-2024-30171
CWE-203 Medium
No
No
3.0.0 07.05.2024 SB2024050731
SB2024050734
SB2024061019
and 59 more
#VU88666 - Improper input validation
CVE-2024-21011
CWE-20 Low
No
No
- 17.04.2024 SB2024041764
SB2024041765
SB2024041766
and 132 more
#VU88667 - Improper input validation
CVE-2024-21068
CWE-20 Low
No
No
- 17.04.2024 SB2024041764
SB2024041765
SB2024041766
and 72 more
#VU88668 - Improper input validation
CVE-2024-21094
CWE-20 Low
No
No
- 17.04.2024 SB2024041764
SB2024041765
SB2024041766
and 126 more
#VU88669 - Improper input validation
CVE-2024-21012
CWE-20 Low
No
No
- 17.04.2024 SB2024041764
SB2024041765
SB2024041766
and 68 more
#VU88533 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-32487
CWE-78 Medium
No
No
- 15.04.2024 SB2024041531
SB2024041533
SB2024042949
and 63 more
#VU88189 - Missing release of memory after effective lifetime
CVE-2024-1023
CWE-401 Medium
No
No
- 05.04.2024 SB2024040542
SB2024042554
SB2024042918
and 10 more
#VU87830 - Missing release of memory after effective lifetime
CVE-2024-1394
CWE-401 Medium
No
No
- 26.03.2024 SB2024032646
SB2024032647
SB2024032648
and 54 more
#VU87671 - Cryptographic Issues
CVE-2024-28834
CWE-310 Medium
No
No
- 20.03.2024 SB2024032057
SB2024032058
SB2024032059
and 111 more
#VU86230 - Resource exhaustion
CVE-2023-52425
CWE-400 Medium
No
No
- 07.02.2024 SB2024020750
SB2024020754
SB2024020765
and 120 more
#VU84568 - Observable discrepancy
CVE-2023-6135
CWE-203 Medium
No
No
- 19.12.2023 SB2023121946
SB2023122118
SB2024010201
and 33 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
- 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU83900 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46218
CWE-200 Low
No
No
- 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 87 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
- 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU79523 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-35939
CWE-59 Low
No
No
- 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU79522 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-35937
CWE-367 Low
No
No
- 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU79521 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-35938
CWE-59 Low
No
No
- 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU76238 - Expected Behavior Violation
CVE-2023-28322
CWE-440 Medium
No
No
- 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 88 more
#VU63553 - Integer overflow
CVE-2021-43618
CWE-190 Medium
No
No
- 24.05.2022 SB2021121654
SB2022052401
SB2021120223
and 85 more


Showing elements 61 - 80 out of 156