Kodem Threat Database

Comprehensive, tamper-evident backups so security teams keep full clarity on CVEs. Prioritize, investigate, and restore with precision.

Critical
Medium
Low
CVE-2020-11022 — jQuery XSS
Package
jquery
Impact
Cross-site scripting vulnerability in jQuery.htmlPrefilter
Fix
Update to jQuery v3.5.0+
Year
2020
CVSS
Severity

Featured CVE’s

Critical
Medium
Low
CVE-2020-11022 — jQuery XSS
Package
jquery
Impact
Cross-site scripting vulnerability in jQuery.htmlPrefilter
Fix
Update to jQuery v3.5.0+
Year
2020
CVSS
Severity
Critical
Medium
Low
CVE-2020-11023 — jQuery XSS
Package
jquery
Impact
Cross-site scripting via HTML manipulation methods
Fix
Update to jQuery v3.5.0+
Year
2020 (trending in 2025)
CVSS
Severity
Critical
Medium
Low
CVE-2021-45046 — Apache Log4j DoS/RCE
Package
org.apache.logging.log4j:log4j-core
Impact
DoS and potential RCE in certain configurations
Fix
Update to Log4j v2.16.0+
Year
2021
CVSS
Severity
Critical
Medium
Low
CVE-2021-44228 — Log4Shell (Apache Log4j)
Package
org.apache.logging.log4j:log4j-core
Impact
Critical RCE via JNDI lookup injection
Fix
Update to Log4j v2.17.1+
Year
2021 (ongoing impact)
CVSS
10
Severity
Critical
Critical
Medium
Low
CVE-2022-29176 — RubyGems Package Takeover
Package
rubygems-update
Impact
Unauthorized gem removal and replacement
Fix
Update RubyGems to v3.3.12+
Year
2022
CVSS
Severity
Critical
Medium
Low
CVE-2022-1471 — SnakeYAML Deserialization RCE
Package
org.yaml:snakeyaml
Impact
Remote code execution via unsafe YAML deserialization
Fix
Update to SnakeYAML v2.0+
Year
2022
CVSS
9.8
Severity
Critical
Critical
Medium
Low
CVE-2023-36617 — Ruby URI ReDoS
Package
uri (Ruby standard library)
Impact
Regular expression denial of service
Fix
Update Ruby to v3.0.6+, v3.1.4+, v3.2.2+
Year
2023
CVSS
Severity
Critical
Medium
Low
CVE-2023-39325 — Go HTTP/2 Rapid Reset
Package
golang.org/x/net/http2
Impact
HTTP/2 rapid reset vulnerability
Fix
Update to golang.org/x/net v0.17.0+
Year
2023
CVSS
Severity
Critical
Medium
Low
CVE-2023-45288 — Go HTTP/2 Rapid Reset
Package
net/http
Impact
HTTP/2 rapid reset attack causing resource exhaustion
Fix
Update to Go v1.21.9+, v1.22.2+
Year
2023
CVSS
Severity
Critical
Medium
Low
CVE-2023-2976 — Google Guava
Package
com.google.guava:guava
Impact
High severity security vulnerability
Fix
Update to Guava v32.0.0+
Year
2023
CVSS
Severity
Critical
Medium
Low
CVE-2023-24329 — Python urllib.parse
Package
Python (affects urllib.parse)
Impact
URL parsing vulnerability leading to security bypass
Fix
Update to Python v3.8.17+, v3.9.17+, v3.10.12+, v3.11.4+
Year
2023
CVSS
Severity
Critical
Medium
Low
CVE-2023-23931 — PyPI cryptography
Package
cryptography
Impact
Security vulnerability in cryptographic operations
Fix
Update to cryptography v39.0.1+
Year
2023
CVSS
Severity
Critical
Medium
Low
CVE-2023-25341 — @ladle/react Unauthorized File Access
Package
@ladle/react
Impact
Unauthorized file access on server due to improper input validation
Fix
Update to @ladle/react v2.5.2+
Year
2023
CVSS
Severity
Critical
Medium
Low
CVE-2024-47535 — Netty
Package
io.netty:netty-*
Impact
High severity security flaw
Fix
Update to Netty v4.1.101.Final+
Year
2024
CVSS
Severity
Critical
Medium
Low
CVE-2024-24789 — Go archive/zip
Package
archive/zip
Impact
Panic in path validation on Windows
Fix
Update to Go v1.21.11+, v1.22.4+
Year
2024
CVSS
Severity
Critical
Medium
Low
CVE-2024-24790 — Go Standard Library
Package
net/netip
Impact
Unexpected behavior in IP address parsing
Fix
Update to Go v1.21.11+, v1.22.4+
Year
2024
CVSS
Severity
Critical
Medium
Low
GO-2024-2687 — HTTP/2 CONTINUATION Frame Attack
Package
golang.org/x/net/http2
Impact
DoS via excessive header data consumption
Fix
Update to golang.org/x/net v0.23.0+
Year
2024
CVSS
Severity
Critical
Medium
Low
CVE-2024-6345 — PyPA Setuptools Code Injection
Package
setuptools
Impact
Code injection via malicious package URLs
Fix
Update to setuptools v70.0+
Year
2024
CVSS
Severity
High
Critical
Medium
Low
CVE-2025-27607 — python-json-logger RCE
Package
python-json-logger
Impact
Supply chain RCE via malicious dependencies (46M+ monthly downloads)
Fix
Update to python-json-logger v3.3.0+
Year
2025
CVSS
Severity
Critical
Medium
Low
CVE-2024-53900 & CVE-2025-23061 — Mongoose RCE
Package
mongoose
Impact
Remote Code Execution via $where operator exploitation
Fix
Update to mongoose v8.9.5+
Year
2024-2025
CVSS
Severity

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo