Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2023-46279 Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the … Dubbo Mitigation only Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-46302 Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail… Submarine 0.8.0+ Fix from $2,3002023-11-20 CRITICAL 9.8 CVE-2023-47248EPSS 14% Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is … Pyarrow after 14.0.0 Fix from $2,3002023-11-09 HIGH 8.8 CVE-2023-39913 Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apach… Uimaj 3.5.0+ Fix from $1,9502023-11-08 CRITICAL 9.8 CVE-2023-46604 KEVEPSS 100% The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to… Activemq 5.15.16 / 5.16.7+ Fix from $2,3002023-10-27 HIGH 7.5 CVE-2023-46227 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.… Inlong 1.9.0+ Fix from $1,9502023-10-19 HIGH 7.5 CVE-2023-39410 When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of … Avro 1.11.3+ Fix from $1,9502023-09-29 MEDIUM 6.6 CVE-2023-37941EPSS 29% If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to … Superset after 2.1.0 Fix from $1,6002023-09-06 HIGH 8.8 CVE-2023-40195 Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo… Airflow Spark Provider 4.1.3+ Fix from $1,9502023-08-28 CRITICAL 9.8 CVE-2023-38647 An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S… Helix 1.3.0+ Fix from $2,3002023-07-26 CRITICAL 9.8 CVE-2023-37895 Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in… Jackrabbit 2.20.11 / 2.21.18+ Fix from $2,3002023-07-25 HIGH 7.5 CVE-2023-34434 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.… Inlong after 1.7.0 Fix from $1,9502023-07-25 HIGH 8.8 CVE-2023-28754 Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a sp… Shardingsphere 5.4.0+ Fix from $1,9502023-07-19 CRITICAL 9.8 CVE-2023-26512 CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac… Eventmesh Connector Rabbitmq after 1.8.0 Fix from $2,3002023-07-17 MEDIUM 5.3 CVE-2023-33008 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input tha… Johnzon 1.2.21+ Fix from $1,6002023-07-07 MEDIUM 6.5 CVE-2023-34212 The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all… Nifi after 1.21.0 Fix from $1,6002023-06-12 HIGH 7.5 CVE-2023-31058 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.… Inlong after 1.6.0 Fix from $1,9502023-05-22 CRITICAL 9.8 CVE-2023-29215 In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-29216 In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co… Linkis after 1.3.1 Fix from $2,3002023-04-10 HIGH 8.8 CVE-2023-27296 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong,… Inlong after 1.5.0 Fix from $1,9502023-03-27 HIGH 7.5 CVE-2023-26464 ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t… Log4j 2.0+ Fix from $1,9502023-03-10 CRITICAL 9.8 CVE-2023-23638 A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.… Dubbo after 3.1.5 Fix from $2,3002023-03-08 HIGH 8.8 CVE-2023-25194EPSS 96% A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to… Kafka Connect after 3.3.2 Fix from $1,9502023-02-07 CRITICAL 9.8 CVE-2023-24997 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.… Inlong after 1.5.0 Fix from $2,3002023-02-01 HIGH 8.8 CVE-2022-44645 In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when… Linkis after 1.3.0 Fix from $1,9502023-01-31 CRITICAL 9.8 CVE-2021-32824 Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb… Dubbo 2.6.10 / 2.7.10+ Fix from $2,3002023-01-03 CRITICAL 9.8 CVE-2022-46366 Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1… Tapestry 4.0.0+ Fix from $2,3002022-12-02 CRITICAL 9.8 CVE-2022-45047 Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j… Sshd after 2.9.1 Fix from $2,3002022-11-16 CRITICAL 9.8 CVE-2022-45136 Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u… Jena Sdb after 3.17.0 Fix from $2,3002022-11-14 HIGH 8.8 CVE-2022-39944 In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when… Linkis after 1.2.0 Fix from $1,9502022-10-26