Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

H2database

First CVE: Apr 11, 2018Active for: 8 yearsTotal CVEs: 6

H2database is an embedded relational database engine widely integrated into Java applications and frameworks, where its lightweight footprint and permissive default configurations create a concentrated attack surface. Vulnerabilities affecting the product skew strongly toward critical severity and frequently acquire public exploit code, with the recurrent weakness classes—including cleartext storage of sensitive information, unsafe deserialization, improper input validation, link-following flaws, and argument injection—reflecting both the parser complexity of SQL processing and the risky defaults endemic to embedded database engines. Defenders should treat H2 instances as high-priority targets, particularly where exposed to untrusted input or where application code dynamically constructs database commands; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by H2database over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2018
8 years ago
Most Recent CVE
Nov 23, 2022
1,339 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-42392CRITICAL
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name
Jan 10, 20229.868NONO
CVE-2022-23221CRITICAL
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCR
Jan 19, 20229.867NONO
CVE-2018-10054HIGH
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is
Apr 11, 20188.858NOYES
CVE-2018-14335MEDIUM
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink
Jul 24, 20186.539NOYES
CVE-2021-23463CRITICAL
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives pa
Dec 10, 20219.130NONO
CVE-2022-45868HIGH
The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cl
Nov 23, 20227.826NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
17%
33%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None3 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
16.7% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by H2database.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by H2database — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For H2database's Products

View all 3 CNAs →

Top CWEs