- OpenJDK Security Advisory Acknowledgment (January 2023)
- OpenJDK Security Advisory Acknowledgment (July 2023)
- OpenJDK Security Advisory Acknowledgment (July 2026)
- Oracle Security-in-Depth Contributor (October 2022)
- Oracle Security-in-Depth Contributor (January 2023)
- Oracle Security-in-Depth Contributor (April 2023)
- Oracle Security-in-Depth Contributor (July 2023)
- Oracle Security-in-Depth Contributor (October 2023)
- Oracle Security-in-Depth Contributor (January 2026)
| Vendor | Product | CVE-ID | Type |
|---|---|---|---|
| Apache | Log4j2 | CVE-2021-45046 | RCE |
| Spring | Spring Framework | CVE-2022-22950 | Denial of Service |
| Oracle | WebLogic | CVE-2022-21441 | Denial of Service |
| Apache | Tomcat | CVE-2022-29885 | Denial of Service |
| Apache | Shiro | CVE-2022-32532 | Authentication Bypass |
| Oracle | WebLogic | CVE-2022-21557 | RCE |
| Oracle | WebLogic | CVE-2022-21560 | Denial of Service |
| Oracle | SOA Suite | CVE-2022-21562 | RCE |
| Oracle | WebLogic | CVE-2022-21564 | Denial of Service |
| Oracle | Siebel CRM | CVE-2022-21598 | RCE |
| Oracle | WebLogic | CVE-2022-21616 | Denial of Service |
| Oracle | SOA Suite | CVE-2022-21622 | RCE |
| Oracle | Enterprise Manager | CVE-2022-21623 | RCE |
| Apache | SystemDS | CVE-2022-26477 | Denial of Service |
| Apache | IoTDB | CVE-2022-43766 | Denial of Service |
| Apache | Causeway | CVE-2022-42466 | Stored XSS |
| Apache | Batik | CVE-2022-41704 | RCE |
| Apache | Batik | CVE-2022-42890 | RCE |
| Apache | ManifoldCF | CVE-2022-45910 | Information Disclosure |
| Apache | StreamPark | CVE-2022-45801 | Information Disclosure |
| Apache | DolphinScheduler | CVE-2022-45875 | RCE |
| Apache | DolphinScheduler | CVE-2023-49109 | RCE |
| Apache | Dolphinscheduler | CVE-2023-50270 | Logic Flaw |
| Apache | DolphinScheduler | CVE-2023-49068 | Information Disclosure |
| Apache | DolphinScheduler | CVE-2023-51770 | Arbitrary File Read |
| Oracle | BI Publisher | CVE-2023-21832 | RCE |
| Oracle | WebLogic | CVE-2023-21839 | RCE |
| Oracle | BI Publisher | CVE-2023-21846 | RCE |
| Apache | Kafka | CVE-2023-25194 | RCE |
| Apache | Airflow | CVE-2023-28706 | RCE |
| Oracle | WebLogic | CVE-2023-21931 | RCE |
| Oracle | WebLogic | CVE-2023-21960 | Denial of Service |
| Oracle | WebLogic | CVE-2023-21964 | Denial of Service |
| Oracle | WebLogic | CVE-2023-21979 | RCE |
| Oracle | WebLogic | CVE-2023-22031 | Denial of Service |
| Apache | Felix | CVE-2023-38435 | XSS |
| Apache | Airflow | CVE-2023-39553 | Arbitrary File Read |
| Oracle | WebLogic | CVE-2023-22069 | RCE |
| Oracle | WebLogic | CVE-2023-22086 | RCE |
| Oracle | WebLogic | CVE-2023-22089 | RCE |
| Apache | Helix | CVE-2023-38647 | RCE |
| Apache | Kerby | CVE-2023-25613 | Information Disclosure |
| Apache | Linkis | CVE-2023-27603 | RCE |
| Apache | InLong | CVE-2023-34434 | Arbitrary File Read |
| Metabase | Metabase | CVE-2023-37470 | RCE |
| Apache | Derby | CVE-2022-46337 | Information Disclosure |
| Apache | Solr | CVE-2023-50298 | Information Disclosure |
| Oracle | WebLogic | CVE-2024-21006 | RCE |
| Apache | Kylin | CVE-2024-23590 | Logic Flaw |
| Apache | OFBiz | CVE-2024-38856 | RCE |
| Oracle | FMW Installer | CVE-2024-21190 | RCE |
| Apache | ZooKeeper | CVE-2024-51504 | Authentication Bypass |
| Apache | Ambari | CVE-2024-51941 | RCE |
| Apache | Zeppelin | CVE-2024-31867 | Information Disclosure |
| Apache | Kafka | CVE-2025-27817 | Arbitrary File Read |
| Apache | Kafka | CVE-2025-27818 | RCE |
| Apache | Shiro | CVE-2026-23901 | Timing Side Channel |
| Apache | OpenMeetings | CVE-2026-34020 | Information Disclosure |
| Apache | OpenMeetings | CVE-2026-33266 | Information Disclosure |
| Apache | OpenMeetings | CVE-2026-33005 | Logic Flaw |
| Oracle | MySQL | CVE-2026-34317 | Denial of Service |
| Oracle | MySQL | CVE-2026-34318 | Information Disclosure |
| Oracle | MySQL | CVE-2026-34319 | Denial of Service |
| DataEase | DataEase | CVE-2026-45534 | RCE |
| DataEase | DataEase | CVE-2026-45532 | Path Traversal |
| DataEase | DataEase | CVE-2026-45419 | Arbitrary File Write |
| DataEase | DataEase | CVE-2026-45417 | SQL Injection |
| Apache | ActiveMQ | CVE-2026-42588 | RCE |
| Apache | ActiveMQ | CVE-2026-42253 | Stored XSS |
| Apache | Calcite | CVE-2026-46718 | RCE |
| Oracle | MySQL | CVE-2026-46863 | Denial of Service |
| Apache | Kvrocks | CVE-2026-46751 | Denial of Service |
| Apache | Kvrocks | CVE-2026-41566 | Logic Flaw |
| mchange | c3p0 | CVE-2026-55153 | Deserialization Vulnerability |
| Oracle | Java SE | CVE-2026-47057 | Denial of Service |
| Oracle | Java SE | CVE-2026-47058 | Information Disclosure |
| Oracle | MySQL | CVE-2026-47064 | Denial of Service |
| IBM | DB2 JDBC | CVE-2026-9762 | RCE |
| GeoTools | GeoTools | CVE-2026-76904 | SQL Injection |
| GeoServer | GeoServer | CVE-2026-76904 | SQL Injection |
| Apache | Tomcat | CVE-2026-66299 | Denial of Service |
| Apache | Tomcat | CVE-2026-68525 | Security Constraint Bypass |
| Apache | Tomcat | CVE-2026-66422 | Role Constraint Bypass |
| Apache | Tomcat | CVE-2026-65927 | Access Control Bypass |
| Apache | Tomcat | CVE-2026-65905 | Replay Attack |
| Apache | Tomcat | CVE-2026-65182 | Security Constraint Bypass |
| Apache | Doris | CVE-2026-31377 | Improper Authentication |
| Apache | APR | CVE-2026-32327 | Denial of Service |
| Apache | HTTP Server | CVE-2026-46729 | Denial of Service |
| Apache | HTTP Server | CVE-2026-63045 | Improper Validation |
| Apache | HTTP Server | CVE-2026-63718 | HTTP Smuggling |