Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2018-8021EPSS 53%
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. …
Superset
0.23+
CRITICAL 9.8
CVE-2018-8018EPSS 7%
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deseriali…
Ignite
2.4.8 / 2.5.3+
CRITICAL 9.8
CVE-2018-8013EPSS 19%
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…
Batik
1.10 / 7.2+
HIGH 7.5
CVE-2018-1310
Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE…
Nifi
1.6.0+
CRITICAL 9.8
CVE-2018-1295EPSS 6%
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i…
Ignite
after 2.3.0
CRITICAL 9.8
CVE-2017-15692
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce…
Geode
1.4.0+
HIGH 7.5
CVE-2017-15693
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t…
Geode
1.4.0+
MEDIUM 5.0
CVE-2017-15703
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den…
Nifi
after 1.4.0
CRITICAL 9.8
CVE-2016-6814EPSS 17%
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se…
Groovy
after 2.4.7
CRITICAL 9.8
CVE-2017-5641EPSS 21%
Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. …
Flex Blazeds
8.5.3-00+
CRITICAL 9.8
CVE-2017-12633EPSS 7%
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D…
Camel
2.19.4 / 2.20.1+
CRITICAL 9.8
CVE-2017-12634EPSS 7%
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De…
Camel
2.19.4+
CRITICAL 9.8
CVE-2016-5003EPSS 15%
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…
Ws Xmlrpc
No fix yet
HIGH 7.8
CVE-2017-12628
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex…
James Server
after 3.0.0
CRITICAL 9.8
CVE-2016-8736
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
Openmeetings
3.1.2+
HIGH 8.1
CVE-2017-9805 KEVEPSS 99%
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des…
Struts
2.3.34 / 2.5.13+
HIGH 8.8
CVE-2016-8744
Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal…
Brooklyn
after 0.9.0
HIGH 7.8
CVE-2017-12612
In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched …
Spark
Mitigation only
CRITICAL 9.1
CVE-2016-6793EPSS 8%
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop…
Wicket
1.5.17 / 6.25.0+
CRITICAL 9.8
CVE-2017-5645EPSS 90%
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a …
Log4j
2.8.2+
CRITICAL 9.8
CVE-2016-0779EPSS 10%
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s…
Tomee
after 1.7.3
CRITICAL 9.8
CVE-2016-6809EPSS 8%
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d…
Nutch
after 1.13
CRITICAL 9.8
CVE-2016-8749EPSS 11%
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
Camel
No fix yet
CRITICAL 9.8
CVE-2017-3159EPSS 6%
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to secur…
Camel
after 2.18.1
CRITICAL 9.8
CVE-2016-5019EPSS 8%
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow…
Myfaces Trinidad
1.0.13 / 1.2.15+
HIGH 7.2
CVE-2016-4978EPSS 7%
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache Ac…
Artemis
1.4.0+
CRITICAL 9.8
CVE-2015-6420EPSS 18%
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and…
Commons Collections
3.2.2+