The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.bouncycastle:bcpg-jdk18on to version 1.86 or higher.
Affected versions of this package are vulnerable to Incorrect Authorization in OpenPGPCertificate.getCertificationBy() and getDelegationBy() in the OpenPGP certificate API. An attacker can have a third-party certification or direct-key trust delegation accepted as if it were issued by the certificate by using a component key that signed the request but was never granted CERTIFY_OTHER, such as an online signing subkey or legacy signing-capable subkey. The API resolves the signature against every component key in the issuer certificate, verifies the binding chain and signature, and then attributes the result to the certificate without checking that the signing component had certification authority when the signature was created. Applications that treat these returned chains as proof of identity binding or trusted introducer status can be tricked into trusting an attacker-controlled assertion under the offline primary key’s authority.