Known Vulnerabilities for products from Jboss
Listed below are 14 of the newest known vulnerabilities associated with the vendor "Jboss".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76166 json | Not Provided | 2026-08-19 | 2026-08-20 | |
| CVE-2026-15562 json | Not Provided | 2026-08-11 | 2026-08-13 | |
| CVE-2026-15555 json | Not Provided | 2026-08-11 | 2026-08-12 | |
| CVE-2026-14180 json | Not Provided | 2026-08-11 | 2026-08-11 | |
| CVE-2025-12543 json | Not Provided | 2026-01-07 | 2026-08-19 | |
| CVE-2025-2251 json | Not Provided | 2025-04-07 | 2026-08-19 | |
| CVE-2024-1459 json | Not Provided | 2024-02-12 | 2026-08-04 | |
| CVE-2023-5379 json | Not Provided | 2023-12-12 | 2026-08-04 | |
| CVE-2018-1041 json | A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty ... | 7.5 - HIGH | 2018-02-15 | 2019-10-09 |
| CVE-2017-12149 json | Not Provided | 2017-10-04 | 2026-08-13 | |
| CVE-2016-2094 json | The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not... | Not Provided | 2016-05-06 | 2026-05-06 |
| CVE-2014-0170 json | Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read ... | Not Provided | 2014-09-30 | 2026-05-06 |
| CVE-2012-3428 json | The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjuncti... | Not Provided | 2012-12-20 | 2026-04-29 |
| CVE-2010-1428 json | Not Provided | 2010-04-28 | 2026-08-14 | |
| CVE-2008-3273 json | JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote att... | Not Provided | 2008-08-10 | 2026-04-23 |
| CVE-2007-6433 json | The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote atta... | Not Provided | 2007-12-18 | 2026-04-23 |
| CVE-2007-1354 json | The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 befor... | Not Provided | 2007-07-27 | 2026-04-23 |
| CVE-2007-1157 json | Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privil... | Not Provided | 2007-03-02 | 2026-04-23 |
| CVE-2007-1036 json | The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allow... | Not Provided | 2007-02-21 | 2026-04-23 |
| CVE-2006-5750 json | Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4... | Not Provided | 2006-11-27 | 2026-04-23 |
Known software with vulnerabilities from Jboss
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Jboss | Jboss | 3.0.8 |