Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Inlong MEDIUM 6.5
CVE-2025-27526

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability wh…

Fix: 2.2.0+
Fix from $1,600 2025-05-28
Activemq Nms Openwire CRITICAL 9.8
CVE-2025-29953

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client befor…

Fix: 2.1.1+
Fix from $2,300 2025-04-18
Parquet Java CRITICAL 9.8
CVE-2025-30065EPSS 41%

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are reco…

Fix: 1.15.1+
Fix from $2,300 2025-04-01
Seata CRITICAL 9.8
CVE-2024-47552

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.…

Fix: 2.2.0+
Fix from $2,300 2025-03-20
Tomcat CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…

Fix: 9.0.99 / 10.1.35+
Fix from $2,300 2025-03-10
Eventmesh CRITICAL 9.8
CVE-2024-56180

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo…

Fix: 1.11.0+
Fix from $2,300 2025-02-14
Ignite CRITICAL 9.0
CVE-2024-52577

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili…

Fix: 2.17.0+
Fix from $2,300 2025-02-14
Openmeetings CRITICAL 9.8
CVE-2024-54676EPSS 65%

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions …

Fix: 8.0.0+
Fix from $2,300 2025-01-08
Mina CRITICAL 9.8
CVE-2024-52046EPSS 24%

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary…

Fix: 2.0.27 / 2.1.10+
Fix from $2,300 2024-12-25
Hive HIGH 8.3
CVE-2022-41137

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is un…

Patch available
Fix from $1,950 2024-12-05
Arrow CRITICAL 9.8
CVE-2024-52338

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut…

Fix: 17.0.0+
Fix from $2,300 2024-11-28
Hertzbeat HIGH 8.8
CVE-2024-41151

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue …

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Lucene.net HIGH 8.1
CVE-2024-43383

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8…

Mitigation only
Fix from $1,950 2024-10-31
Avro HIGH 7.3
CVE-2024-47561

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgr…

Fix: 1.11.4+
Fix from $1,950 2024-10-03
Lucene Replicator HIGH 8.0
CVE-2024-45772

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before…

Fix: 9.12.0+
Fix from $1,950 2024-09-30
Hertzbeat HIGH 8.8
CVE-2024-42323EPSS 8%

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attac…

Fix: 1.6.0+
Fix from $1,950 2024-09-21
Seata CRITICAL 9.8
CVE-2024-22399

Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seat…

Fix: 1.8.1+
Fix from $2,300 2024-09-16
Hertzbeat HIGH 8.8
CVE-2024-42362

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/…

Fix: 1.6.0+
Fix from $1,950 2024-08-20
Linkis HIGH 8.8
CVE-2023-46801

In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version …

Fix: 1.6.0+
Fix from $1,950 2024-07-15
Linkis HIGH 8.8
CVE-2023-49566

In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSourc…

Fix: 1.6.0+
Fix from $1,950 2024-07-15
Inlong CRITICAL 9.8
CVE-2024-26579

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can by…

Fix: 1.12.0+
Fix from $2,300 2024-05-08
Inlong CRITICAL 9.1
CVE-2024-26580

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use…

Fix: 1.11.0+
Fix from $2,300 2024-03-06
James CRITICAL 9.8
CVE-2023-51518

Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi…

Mitigation only
Fix from $2,300 2024-02-27
Hertzbeat CRITICAL 9.8
CVE-2023-51389

Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co…

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Camel CRITICAL 9.8
CVE-2024-23114

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa…

Fix: 3.21.4 / 4.0.4+
Fix from $2,300 2024-02-20
Camel HIGH 7.8
CVE-2024-22369

Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 b…

Fix: 3.21.4 / 4.0.4+
Fix from $1,950 2024-02-20
Airflow HIGH 7.5
CVE-2023-50943

Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "…

Fix: 2.8.1+
Fix from $1,950 2024-01-24
Inlong HIGH 7.5
CVE-2023-51785

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a…

Fix: after 1.9.0
Fix from $1,950 2024-01-03
Iotdb CRITICAL 9.8
CVE-2023-51656

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended t…

Fix: after 0.13.4
Fix from $2,300 2023-12-21
Dubbo CRITICAL 9.8
CVE-2023-29234EPSS 7%

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…

Fix: after 3.2.4
Fix from $2,300 2023-12-15