Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2022-39198
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…
Dubbo
after 3.0.11
HIGH 8.8
CVE-2022-40955
In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi…
Inlong
1.3.0+
CRITICAL 9.8
CVE-2022-29063
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier…
Ofbiz
18.12.06+
CRITICAL 9.8
CVE-2022-37021
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A…
Geode
after 1.13.4
HIGH 8.8
CVE-2022-37022
Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user…
Geode
after 1.13.2
MEDIUM 6.5
CVE-2022-37023
Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user w…
Geode
1.15.0+
HIGH 8.8
CVE-2021-25642
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation…
Hadoop
2.10.2 / 3.2.4+
HIGH 8.8
CVE-2022-24289
Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur…
Cayenne
4.2+
HIGH 8.1
CVE-2021-41766
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…
Karaf
4.3.6+
HIGH 8.8
CVE-2022-23302EPSS 64%
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration…
Log4j
1.2.18.1+
HIGH 8.8
CVE-2022-23307EPSS 54%
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j…
Chainsaw
1.2.18.1 / 2.0+
CRITICAL 9.8
CVE-2021-43297EPSS 17%
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…
Dubbo
2.6.12 / 2.7.15+
HIGH 7.5
CVE-2021-4104EPSS 81%
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack…
Log4j
Patch available
CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…
Log4j
2.1.0 / 2.3.1+
HIGH 7.5
CVE-2021-26558
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa…
Shardingsphere Ui
5.0.0+
CRITICAL 9.8
CVE-2021-40865EPSS 66%
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (…
Storm
1.2.4 / 2.1.1+
CRITICAL 9.8
CVE-2021-41616
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…
Ddlutils
Mitigation only
CRITICAL 9.8
CVE-2021-37579EPSS 7%
The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…
Dubbo
2.7.13 / 3.0.2+
CRITICAL 9.8
CVE-2021-36163
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…
Dubbo
after 3.0.1
CRITICAL 9.8
CVE-2021-37578
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo…
Juddi
3.3.10+
CRITICAL 9.8
CVE-2020-9493
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.
Chainsaw
1.2.18.1 / 2.0+
CRITICAL 9.8
CVE-2021-25641EPSS 21%
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before…
Dubbo
2.6.9 / 2.7.8+
CRITICAL 9.8
CVE-2021-30179
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha…
Dubbo
2.6.9 / 2.7.10+
CRITICAL 9.8
CVE-2021-29200EPSS 55%
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Ofbiz
17.12.07+
CRITICAL 9.8
CVE-2021-30128EPSS 81%
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Ofbiz
17.12.07+
CRITICAL 9.8
CVE-2021-27850EPSS 94%
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…
Tapestry
5.6.2 / 5.7.1+
CRITICAL 9.8
CVE-2021-21347EPSS 14%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.8
CVE-2021-21350EPSS 15%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+
CRITICAL 9.1
CVE-2021-21351EPSS 82%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…
Activemq
1.4.16 / 5.5+
HIGH 8.6
CVE-2021-21349EPSS 47%
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…
Activemq
1.4.16 / 5.5+