Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.5 CVE-2021-21348EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 CRITICAL 9.9 CVE-2021-21345EPSS 72% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21344EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21346EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21342EPSS 50% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed … Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 7.5 CVE-2021-21341EPSS 78% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-21343EPSS 47% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed … Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 CRITICAL 9.8 CVE-2021-26295EPSS 98% Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF… Ofbiz 17.12.06+ Fix from $2,3002021-03-22 HIGH 8.8 CVE-2020-17532 When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The… Java Chassis 2.1.5+ Fix from $1,9502021-01-25 CRITICAL 9.8 CVE-2020-11995EPSS 6% A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H… Dubbo after 2.7.7 Fix from $2,3002021-01-11 CRITICAL 9.8 CVE-2020-17531EPSS 10% A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok… Tapestry 5.0.1+ Fix from $2,3002020-12-08 CRITICAL 9.8 CVE-2020-11982EPSS 7% An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) … Airflow after 1.10.10 Fix from $2,3002020-07-17 MEDIUM 6.1 CVE-2020-9496EPSS 99% XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 Ofbiz No fix yet Fix from $1,6002020-07-15 CRITICAL 9.8 CVE-2020-1948EPSS 16% This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met… Dubbo after 2.7.6 Fix from $2,3002020-07-14 CRITICAL 9.8 CVE-2018-21234EPSS 8% Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. Hive 5.0.4+ Fix from $2,3002020-05-21 HIGH 7.0 CVE-2020-9484EPSS 57% When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to contr… Tomcat 7.0.108 / 8.5.63+ Fix from $1,9502020-05-20 CRITICAL 9.8 CVE-2020-11972EPSS 6% Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users… Camel after 8.2.2 Fix from $2,3002020-05-14 CRITICAL 9.8 CVE-2020-11973EPSS 7% Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh… Camel after 8.5.0 Fix from $2,3002020-05-14 CRITICAL 9.8 CVE-2020-1964 It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to … Heron Mitigation only Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2019-17564EPSS 37% Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in… Dubbo after 2.7.4 Fix from $2,3002020-04-01 CRITICAL 9.8 CVE-2020-1947EPSS 34% In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load … Shardingsphere Mitigation only Fix from $2,3002020-03-11 CRITICAL 9.8 CVE-2019-17570EPSS 49% An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar… Xml Rpc Patch available Fix from $2,3002020-01-23 CRITICAL 9.8 CVE-2019-17571EPSS 69% Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi… Log4j 4.14.3+ Fix from $2,3002019-12-20 CRITICAL 9.8 CVE-2019-17556 Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being … Olingo after 4.6.0 Fix from $2,3002019-12-04 CRITICAL 9.8 CVE-2019-0195EPSS 15% Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou… Tapestry after 5.4.3 Fix from $2,3002019-09-16 CRITICAL 9.8 CVE-2019-0189EPSS 24% The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and … Ofbiz 16.11.06+ Fix from $2,3002019-09-11 HIGH 7.3 CVE-2019-10086EPSS 30% In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the clas… Commons Beanutils after 1.9.3 Fix from $1,9502019-08-20 CRITICAL 9.8 CVE-2018-11779 In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d… Storm after 1.2.2 Fix from $2,3002019-07-26 CRITICAL 9.8 CVE-2019-0192EPSS 78% In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it… Solr after 6.6.5 Fix from $2,3002019-03-07 CRITICAL 9.8 CVE-2019-0187 Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a… Jmeter Mitigation only Fix from $2,3002019-03-06