Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2022-39198 A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss… Dubbo after 3.0.11 Fix from $2,3002022-10-18 HIGH 8.8 CVE-2022-40955 In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi… Inlong 1.3.0+ Fix from $1,9502022-09-20 CRITICAL 9.8 CVE-2022-29063 The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier… Ofbiz 18.12.06+ Fix from $2,3002022-09-02 CRITICAL 9.8 CVE-2022-37021 Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A… Geode after 1.13.4 Fix from $2,3002022-08-31 HIGH 8.8 CVE-2022-37022 Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user… Geode after 1.13.2 Fix from $1,9502022-08-31 MEDIUM 6.5 CVE-2022-37023 Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user w… Geode 1.15.0+ Fix from $1,6002022-08-31 HIGH 8.8 CVE-2021-25642 ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation… Hadoop 2.10.2 / 3.2.4+ Fix from $1,9502022-08-25 HIGH 8.8 CVE-2022-24289 Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur… Cayenne 4.2+ Fix from $1,9502022-02-11 HIGH 8.1 CVE-2021-41766 Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology… Karaf 4.3.6+ Fix from $1,9502022-01-26 HIGH 8.8 CVE-2022-23302EPSS 64% JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration… Log4j 1.2.18.1+ Fix from $1,9502022-01-18 HIGH 8.8 CVE-2022-23307EPSS 54% CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j… Chainsaw 1.2.18.1 / 2.0+ Fix from $1,9502022-01-18 CRITICAL 9.8 CVE-2021-43297EPSS 17% A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub… Dubbo 2.6.12 / 2.7.15+ Fix from $2,3002022-01-10 HIGH 7.5 CVE-2021-4104EPSS 81% JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack… Log4j Patch available Fix from $1,9502021-12-14 CRITICAL 10.0 CVE-2021-44228 KEVEPSS 100% Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… Log4j 2.1.0 / 2.3.1+ Fix from $2,3002021-12-10 HIGH 7.5 CVE-2021-26558 Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa… Shardingsphere Ui 5.0.0+ Fix from $1,9502021-11-11 CRITICAL 9.8 CVE-2021-40865EPSS 66% An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 CRITICAL 9.8 CVE-2021-41616 Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR… Ddlutils Mitigation only Fix from $2,3002021-09-30 CRITICAL 9.8 CVE-2021-37579EPSS 7% The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.… Dubbo 2.7.13 / 3.0.2+ Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-36163 In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque… Dubbo after 3.0.1 Fix from $2,3002021-09-07 CRITICAL 9.8 CVE-2021-37578 Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo… Juddi 3.3.10+ Fix from $2,3002021-07-29 CRITICAL 9.8 CVE-2020-9493 A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. Chainsaw 1.2.18.1 / 2.0+ Fix from $2,3002021-06-16 CRITICAL 9.8 CVE-2021-25641EPSS 21% Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before… Dubbo 2.6.9 / 2.7.8+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-30179 Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha… Dubbo 2.6.9 / 2.7.10+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-29200EPSS 55% Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack Ofbiz 17.12.07+ Fix from $2,3002021-04-27 CRITICAL 9.8 CVE-2021-30128EPSS 81% Apache OFBiz has unsafe deserialization prior to 17.12.07 version Ofbiz 17.12.07+ Fix from $2,3002021-04-27 CRITICAL 9.8 CVE-2021-27850EPSS 94% A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,… Tapestry 5.6.2 / 5.7.1+ Fix from $2,3002021-04-15 CRITICAL 9.8 CVE-2021-21347EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21350EPSS 15% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21351EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 8.6 CVE-2021-21349EPSS 47% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23