Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-46279
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5.
Users are recommended to upgrade to the …
Dubbo
Mitigation only
CRITICAL 9.8
CVE-2023-46302
Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail…
Submarine
0.8.0+
CRITICAL 9.8
CVE-2023-47248EPSS 14%
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is …
Pyarrow
after 14.0.0
HIGH 8.8
CVE-2023-39913
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apach…
Uimaj
3.5.0+
CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to…
Activemq
5.15.16 / 5.16.7+
HIGH 7.5
CVE-2023-46227
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.
This issue affects Apache InLong: from 1.4.0 through 1.…
Inlong
1.9.0+
HIGH 7.5
CVE-2023-39410
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of …
Avro
1.11.3+
MEDIUM 6.6
CVE-2023-37941EPSS 29%
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to …
Superset
after 2.1.0
HIGH 8.8
CVE-2023-40195
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo…
Airflow Spark Provider
4.1.3+
CRITICAL 9.8
CVE-2023-38647
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S…
Helix
1.3.0+
CRITICAL 9.8
CVE-2023-37895
Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in…
Jackrabbit
2.20.11 / 2.21.18+
HIGH 7.5
CVE-2023-34434
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.…
Inlong
after 1.7.0
HIGH 8.8
CVE-2023-28754
Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a sp…
Shardingsphere
5.4.0+
CRITICAL 9.8
CVE-2023-26512
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac…
Eventmesh Connector Rabbitmq
after 1.8.0
MEDIUM 5.3
CVE-2023-33008
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon.
A malicious attacker can craft up some JSON input tha…
Johnzon
1.2.21+
MEDIUM 6.5
CVE-2023-34212
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all…
Nifi
after 1.21.0
HIGH 7.5
CVE-2023-31058
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.…
Inlong
after 1.6.0
CRITICAL 9.8
CVE-2023-29215
In Apache Linkis <=1.3.1, due to the lack of effective filtering
of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi…
Linkis
after 1.3.1
CRITICAL 9.8
CVE-2023-29216
In Apache Linkis <=1.3.1, because the parameters are not
effectively filtered, the attacker uses the MySQL data source and malicious parameters to
co…
Linkis
after 1.3.1
HIGH 8.8
CVE-2023-27296
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.
It could be triggered by authenticated users of InLong,…
Inlong
after 1.5.0
HIGH 7.5
CVE-2023-26464
** UNSUPPORTED WHEN ASSIGNED **
When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t…
Log4j
2.0+
CRITICAL 9.8
CVE-2023-23638
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution.
This issue affects Apache Dubbo 2.…
Dubbo
after 3.1.5
HIGH 8.8
CVE-2023-25194EPSS 96%
A possible security vulnerability has been identified in Apache Kafka Connect API.
This requires access to a Kafka Connect worker, and the ability to…
Kafka Connect
after 3.3.2
CRITICAL 9.8
CVE-2023-24997
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.…
Inlong
after 1.5.0
HIGH 8.8
CVE-2022-44645
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…
Linkis
after 1.3.0
CRITICAL 9.8
CVE-2021-32824
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…
Dubbo
2.6.10 / 2.7.10+
CRITICAL 9.8
CVE-2022-46366
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…
Tapestry
4.0.0+
CRITICAL 9.8
CVE-2022-45047
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j…
Sshd
after 2.9.1
CRITICAL 9.8
CVE-2022-45136
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u…
Jena Sdb
after 3.17.0
HIGH 8.8
CVE-2022-39944
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…
Linkis
after 1.2.0