Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-1462
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin…
Openshift Ai
2.25.7+
HIGH 8.8
CVE-2026-32590
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…
Mirror Registry For Red Hat Openshift
Mitigation only
HIGH 8.8
CVE-2022-1415
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a…
Decision Manager
Mitigation only
HIGH 8.1
CVE-2021-4125
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J…
Openshift
4.6.52 / 4.7.40+
MEDIUM 6.7
CVE-2021-4178
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configure…
Fabric8 Kubernetes
5.0.3 / 5.1.2+
HIGH 7.2
CVE-2021-20318
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary …
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.6
CVE-2021-42550
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat…
Satellite
1.0.3+
HIGH 7.8
CVE-2020-10721
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur…
Fabric8 Maven
after 4.4.1
HIGH 7.5
CVE-2020-10740
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application…
Wildfly
20.0.0+
CRITICAL 9.8
CVE-2019-14892EPSS 6%
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…
Decision Manager
2.6.7.3 / 2.8.11.5+
HIGH 8.1
CVE-2020-2604
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE…
Enterprise Linux
after 13.0.1
CRITICAL 9.8
CVE-2014-3699
eDeploy has RCE via cPickle deserialization of untrusted data
Edeploy
No fix yet
CRITICAL 9.8
CVE-2019-10202EPSS 5%
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2018-11307EPSS 6%
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…
Openshift Container Platform
2.6.7.3 / 2.7.9.4+
HIGH 7.5
CVE-2018-10911
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read…
Virtualization Host
3.12.14 / 4.1.8+
HIGH 7.2
CVE-2016-8648
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera…
Jboss A Mq
Mitigation only
MEDIUM 5.3
CVE-2016-8653
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this …
Jboss A Mq
Mitigation only
HIGH 8.8
CVE-2018-1131
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat…
Jboss Data Grid
Mitigation only
MEDIUM 5.3
CVE-2016-9585
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. …
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.1
CVE-2018-1051
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…
Resteasy
Mitigation only
CRITICAL 9.8
CVE-2015-7501EPSS 83%
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl…
Data Grid
Mitigation only
CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2016-7050
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-3690EPSS 5%
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2017-7504EPSS 29%
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se…
Jboss Enterprise Application Platform
after 4.0
CRITICAL 9.8
CVE-2017-5929EPSS 8%
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
Satellite
1.2.0+
HIGH 8.8
CVE-2016-7065EPSS 12%
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…
Jboss Enterprise Application Platform
No fix yet
CRITICAL 9.8
CVE-2016-6330EPSS 11%
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…
Jboss Operations Network
Mitigation only
CRITICAL 9.8
CVE-2015-8103EPSS 87%
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…
Openshift Container Platform
1.625.2 / 1.638+
HIGH 7.8
CVE-2011-2520
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the bac…
System Config Firewall
after 1.2.29