H2o

Vendor:

First CVE: Jun 9, 2017 · Active for 9 years

28
Total CVEs
Bottom 1%
5.6
Avg CVEs / Year
Bottom 1%
8.0
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact H2o over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2017
9 years ago
Most Recent CVE
May 17, 2026
72 days ago

CVE Severity & Scoring

H2o28 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network26 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (89.3%)
Unknown0 (0.0%)
Required3 (10.7%)
Privileges Required
Low2 (7.1%)
High0 (0.0%)
None26 (92.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
Nov 16, 20239.847NONO
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Ha
May 17, 20269.836NONO
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the
Nov 16, 20237.536NOYES
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises f
Sep 21, 20259.832NONO
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of t
Sep 21, 20259.830NONO
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulatio
Sep 21, 20259.830NONO
A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the
Sep 14, 20249.830NONO
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.
Jun 9, 20179.130NONO
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due
Apr 23, 20269.829NONO
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the
May 17, 20267.528NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.6% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For H2o

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.46.117.50.7%00
3.46.0.429.81.4%00
3.46.0.217.50.7%00
3.46.0.137.50.6%00
3.46.057.40.6%00
3.45.0.638617.10.2%00
3.40.0.426.80.8%00
2.1.019.12.2%00