Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-27526
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability wh…
Inlong
2.2.0+
CRITICAL 9.8
CVE-2025-29953
Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.
This issue affects Apache ActiveMQ NMS OpenWire Client befor…
Activemq Nms Openwire
2.1.1+
CRITICAL 9.8
CVE-2025-30065EPSS 41%
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code
Users are reco…
Parquet Java
1.15.1+
CRITICAL 9.8
CVE-2024-47552
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): from 2.0.0 before 2.…
Seata
2.2.0+
CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…
Tomcat
9.0.99 / 10.1.35+
CRITICAL 9.8
CVE-2024-56180
CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo…
Eventmesh
1.11.0+
CRITICAL 9.0
CVE-2024-52577
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili…
Ignite
2.17.0+
CRITICAL 9.8
CVE-2024-54676EPSS 65%
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions …
Openmeetings
8.0.0+
CRITICAL 9.8
CVE-2024-52046EPSS 24%
The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process
incoming serialized data but lacks the necessary…
Mina
2.0.27 / 2.1.10+
HIGH 8.3
CVE-2022-41137
Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is un…
Hive
Patch available
CRITICAL 9.8
CVE-2024-52338
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut…
Arrow
17.0.0+
HIGH 8.8
CVE-2024-41151
Deserialization of Untrusted Data vulnerability in Apache HertzBeat.
This vulnerability can only be exploited by authorized attackers.
This issue …
Hertzbeat
1.6.1+
HIGH 8.1
CVE-2024-43383
Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator.
This issue affects Apache Lucene.NET's Replicator library: from 4.8…
Lucene.net
Mitigation only
HIGH 7.3
CVE-2024-47561
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgr…
Avro
1.11.4+
HIGH 8.0
CVE-2024-45772
Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.
This issue affects Apache Lucene's replicator module: from 4.4.0 before…
Lucene Replicator
9.12.0+
HIGH 8.8
CVE-2024-42323EPSS 8%
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).
This vulnerability can only be exploited by authorized attac…
Hertzbeat
1.6.0+
CRITICAL 9.8
CVE-2024-22399
Deserialization of Untrusted Data vulnerability in Apache Seata.
When developers disable authentication on the Seata-Server and do not use the Seat…
Seata
1.8.1+
HIGH 8.8
CVE-2024-42362
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/…
Hertzbeat
1.6.0+
HIGH 8.8
CVE-2023-46801
In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version …
Linkis
1.6.0+
HIGH 8.8
CVE-2023-49566
In Apache Linkis <=1.5.0, due to the lack of effective filtering
of parameters, an attacker configuring malicious
db2
parameters in the DataSourc…
Linkis
1.6.0+
CRITICAL 9.8
CVE-2024-26579
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,
the attackers can by…
Inlong
1.12.0+
CRITICAL 9.1
CVE-2024-26580
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can
use…
Inlong
1.11.0+
CRITICAL 9.8
CVE-2023-51518
Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data.
Gi…
James
Mitigation only
CRITICAL 9.8
CVE-2023-51389
Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co…
Hertzbeat
1.4.1+
CRITICAL 9.8
CVE-2024-23114
Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa…
Camel
3.21.4 / 4.0.4+
HIGH 7.8
CVE-2024-22369
Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 b…
Camel
3.21.4 / 4.0.4+
HIGH 7.5
CVE-2023-50943
Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "…
Airflow
2.8.1+
HIGH 7.5
CVE-2023-51785
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a…
Inlong
after 1.9.0
CRITICAL 9.8
CVE-2023-51656
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.
Users are recommended t…
Iotdb
after 0.13.4
CRITICAL 9.8
CVE-2023-29234EPSS 7%
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…
Dubbo
after 3.2.4