Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

H2o Project

First CVE: Jun 9, 2017Active for: 9 yearsTotal CVEs: 30

H2O Project maintains a machine-learning platform library with a narrow product footprint but notable use in data-science and analytics workflows. Observed vulnerabilities cluster around use-after-free conditions, reflecting the memory-management complexity typical of performance-oriented numerical libraries; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
Bottom 1%
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by H2o Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2017
9 years ago
Most Recent CVE
Jul 16, 2026
8 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-6016CRITICAL
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
Nov 16, 20239.847NONO
CVE-2026-8751CRITICAL
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Ha
May 17, 20269.836NONO
CVE-2023-6038HIGH
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the
Nov 16, 20237.536NOYES
CVE-2026-44436HIGH
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack th
Jul 16, 20267.534NONO
CVE-2025-6544CRITICAL
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises f
Sep 21, 20259.832NONO
CVE-2025-10769CRITICAL
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of t
Sep 21, 20259.830NONO
CVE-2025-10768CRITICAL
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulatio
Sep 21, 20259.830NONO
CVE-2024-8862CRITICAL
A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the
Sep 14, 20249.830NONO
CVE-2016-7835CRITICAL
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.
Jun 9, 20179.130NONO
CVE-2026-3960CRITICAL
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due
Apr 23, 20269.829NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
13%
53%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (6.7%)
Network28 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (90.0%)
Unknown0 (0.0%)
Required3 (10.0%)
Privileges Required
Low2 (6.7%)
High0 (0.0%)
None28 (93.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.3% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by H2o Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by H2o Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For H2o Project's Products

View all 5 CNAs →

Top CWEs