Security

Vulnerabilities

Real-time alerts of vulnerabilities across monitored open-source ecosystems.

Ecosystems covered

4

Debian, Maven, Npm & more

Total vulnerabilities tracked

33

From global vulnerability databases

Exclude malware
Package log4j

1.7

Low

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j-layout-template-json

2.7

Low

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j-1.2-api

1.7

Low

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j-core

2.7

Low

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j-core

2.7

Low

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j-core

1.0

Low

Ecosystem: Debian

Package: apache-log4j2

1.7

Low

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j-core

5.2

Medium

Ecosystem: Npm

Package: log4js-vue-log-bus

1.7

Low

Ecosystem: RPM

Package: log4j

6.6

Medium

Ecosystem: Maven

Package: log4j:log4j

1.3

Low

Ecosystem: Debian

Package: node-log4js

2.7

Low

Ecosystem: Debian

Package: apache-log4j1.2

FLAT-DDFQ7 (CVE-2022-23302)

Insecure deserialization In log4j:log4j

6.3

Medium

Ecosystem: Maven

Package: log4j:log4j

8.1

High

Ecosystem: Maven

Package: org.zenframework.z8.dependencies.commons:log4j-1.2.17

FLAT-FDNAX (CVE-2022-21704)

Insecure service configuration In log4js

4.3

Medium

Ecosystem: Npm

Package: log4js

6.3

Medium

Ecosystem: Maven

Package: org.zenframework.z8.dependencies.commons:log4j-1.2.17

4.8

Medium

Ecosystem: Maven

Package: org.ops4j.pax.logging:pax-logging-log4j2

1.3

Low

Ecosystem: Debian

Package: apache-log4j2

2.7

Low

Ecosystem: Debian

Package: apache-log4j2

7.7

High

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j-core

1.3

Low

Ecosystem: Debian

Package: apache-log4j2

0.6

Low

Ecosystem: Debian

Package: apache-log4j2

5.2

Medium

Ecosystem: Maven

Package: org.zenframework.z8.dependencies.commons:log4j-1.2.17

FLAT-L0U75 (CVE-2021-45046)

Insecure deserialization In apache-log4j2

8.4

High

Ecosystem: Debian

Package: apache-log4j2

2.7

Low

Ecosystem: Debian

Package: apache-log4j2

1.3

Low

Ecosystem: Debian

Package: apache-log4j2

2.7

Low

Ecosystem: Maven

Package: org.ops4j.pax.logging:pax-logging-log4j2

FLAT-QC9P8 (CVE-2021-44228)

Remote command execution In apache-log4j2

9.1

Critical

Ecosystem: Debian

Package: apache-log4j2

1.7

Low

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j

1.3

Low

Ecosystem: Debian

Package: apache-log4j1.2

2.7

Low

Ecosystem: Debian

Package: apache-log4j1.2

8.1

High

Ecosystem: Maven

Package: org.zenframework.z8.dependencies.commons:log4j-1.2.17

8.1

High

Ecosystem: Maven

Package: org.apache.logging.log4j:log4j