Hsqldb is a lightweight, embedded Java SQL database engine used in applications and systems requiring local or in-process relational data management. Its observed vulnerability surface clusters around the HyperSQL Database product and reflects exposure in code-selection and reflection mechanisms where untrusted input may influence class instantiation or method invocation. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hsqldb over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41853CRITICAL Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By defaul | Oct 6, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hsqldb.
Media articles that mention a CVE ID that affects a product developed by Hsqldb — matched by CVE ID, not by vendor name.