Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Activemq HIGH 7.5
CVE-2021-21348EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21344EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21346EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21342EPSS 50%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq HIGH 7.5
CVE-2021-21341EPSS 78%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq HIGH 7.5
CVE-2021-21343EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Ofbiz CRITICAL 9.8
CVE-2021-26295EPSS 98%

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF…

Fix: 17.12.06+
Fix from $2,300 2021-03-22
Java Chassis HIGH 8.8
CVE-2020-17532

When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The…

Fix: 2.1.5+
Fix from $1,950 2021-01-25
Dubbo CRITICAL 9.8
CVE-2020-11995EPSS 6%

A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H…

Fix: after 2.7.7
Fix from $2,300 2021-01-11
Tapestry CRITICAL 9.8
CVE-2020-17531EPSS 10%

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok…

Fix: 5.0.1+
Fix from $2,300 2020-12-08
Airflow CRITICAL 9.8
CVE-2020-11982EPSS 7%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) …

Fix: after 1.10.10
Fix from $2,300 2020-07-17
Ofbiz MEDIUM 6.1
CVE-2020-9496EPSS 99%

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

No fix yet
Fix from $1,600 2020-07-15
Dubbo CRITICAL 9.8
CVE-2020-1948EPSS 16%

This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met…

Fix: after 2.7.6
Fix from $2,300 2020-07-14
Hive CRITICAL 9.8
CVE-2018-21234EPSS 8%

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

Fix: 5.0.4+
Fix from $2,300 2020-05-21
Tomcat HIGH 7.0
CVE-2020-9484EPSS 57%

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to contr…

Fix: 7.0.108 / 8.5.63+
Fix from $1,950 2020-05-20
Camel CRITICAL 9.8
CVE-2020-11972EPSS 6%

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users…

Fix: after 8.2.2
Fix from $2,300 2020-05-14
Camel CRITICAL 9.8
CVE-2020-11973EPSS 7%

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh…

Fix: after 8.5.0
Fix from $2,300 2020-05-14
Heron CRITICAL 9.8
CVE-2020-1964

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …

Mitigation only
Fix from $2,300 2020-04-16
Dubbo CRITICAL 9.8
CVE-2019-17564EPSS 37%

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in…

Fix: after 2.7.4
Fix from $2,300 2020-04-01
Shardingsphere CRITICAL 9.8
CVE-2020-1947EPSS 34%

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …

Mitigation only
Fix from $2,300 2020-03-11
Xml Rpc CRITICAL 9.8
CVE-2019-17570EPSS 49%

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar…

Patch available
Fix from $2,300 2020-01-23
Log4j CRITICAL 9.8
CVE-2019-17571EPSS 69%

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi…

Fix: 4.14.3+
Fix from $2,300 2019-12-20
Olingo CRITICAL 9.8
CVE-2019-17556

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being …

Fix: after 4.6.0
Fix from $2,300 2019-12-04
Tapestry CRITICAL 9.8
CVE-2019-0195EPSS 15%

Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou…

Fix: after 5.4.3
Fix from $2,300 2019-09-16
Ofbiz CRITICAL 9.8
CVE-2019-0189EPSS 24%

The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and …

Fix: 16.11.06+
Fix from $2,300 2019-09-11
Commons Beanutils HIGH 7.3
CVE-2019-10086EPSS 30%

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the clas…

Fix: after 1.9.3
Fix from $1,950 2019-08-20
Storm CRITICAL 9.8
CVE-2018-11779

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…

Fix: after 1.2.2
Fix from $2,300 2019-07-26
Solr CRITICAL 9.8
CVE-2019-0192EPSS 78%

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it…

Fix: after 6.6.5
Fix from $2,300 2019-03-07
Jmeter CRITICAL 9.8
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a…

Mitigation only
Fix from $2,300 2019-03-06