Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-11111 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
| CVE-2020-11112 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-9546 |
|
Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
|
| CVE-2019-17569 |
|
Vulnerability in apache (CVE-2019-17569)
vulnerability in apache (CVE-2019-17569). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-17571 |
|
Unsafe Deserialization in log4j:log4j (CVE-2019-17571)
vulnerability in log4j:log4j (CVE-2019-17571). Successful exploitation can lead to full system takeover.
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12174 |
|
Vulnerability in apache (CVE-2017-12174)
vulnerability in apache (CVE-2017-12174). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12626 |
|
Vulnerability in org.apache.poi:poi (CVE-2017-12626)
vulnerability in org.apache.poi:poi (CVE-2017-12626). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.17` or later.
|
| CVE-2017-5641 |
|
Unsafe Deserialization in apache (CVE-2017-5641)
vulnerability in apache (CVE-2017-5641). Successful exploitation can lead to full system takeover.
|
| CVE-2017-15700 |
|
Information Disclosure in apache (CVE-2017-15700)
vulnerability in apache (CVE-2017-15700). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12630 |
|
Cross-Site Scripting (XSS) in apache (CVE-2017-12630)
cross-site scripting in apache (CVE-2017-12630). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5663 |
|
SQL Injection in apache (CVE-2017-5663)
SQL injection in apache (CVE-2017-5663). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17671 |
|
Path Traversal in apache (CVE-2017-17671)
path traversal in apache (CVE-2017-17671). Successful exploitation can lead to full system takeover.
|
| CVE-2014-3250 |
|
Vulnerability in apache (CVE-2014-3250)
vulnerability in apache (CVE-2014-3250). Confidential information can be exposed externally.
|
| CVE-2017-15708 |
|
Vulnerability in apache (CVE-2017-15708)
vulnerability in apache (CVE-2017-15708). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11296 |
|
Cross-Site Scripting (XSS) in apache (CVE-2017-11296)
cross-site scripting in apache (CVE-2017-11296). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-15707 |
|
Vulnerability in apache (CVE-2017-15707)
vulnerability in apache (CVE-2017-15707). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-15701 |
|
Vulnerability in c (CVE-2017-15701)
vulnerability in c (CVE-2017-15701). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-15702 |
|
Vulnerability in apache (CVE-2017-15702)
vulnerability in apache (CVE-2017-15702). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12631 |
|
Cross-Site Request Forgery (CSRF) in apache (CVE-2017-12631)
vulnerability in apache (CVE-2017-12631). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14377 |
|
Authentication Bypass in apache (CVE-2017-14377)
authentication bypass in apache (CVE-2017-14377). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12608 |
|
Out-of-Bounds Write in apache (CVE-2017-12608)
out-of-bounds write in apache (CVE-2017-12608). Successful exploitation can lead to full system takeover.
|
| CVE-2017-3157 |
|
Information Disclosure in apache (CVE-2017-3157)
vulnerability in apache (CVE-2017-3157). Confidential information can be exposed externally.
|
| CVE-2017-12607 |
|
Out-of-Bounds Write in dos (CVE-2017-12607)
out-of-bounds write in dos (CVE-2017-12607). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9806 |
|
Out-of-Bounds Write in dos (CVE-2017-9806)
out-of-bounds write in dos (CVE-2017-9806). Successful exploitation can lead to full system takeover.
|
| CVE-2016-6804 |
|
Vulnerability in apache (CVE-2016-6804)
vulnerability in apache (CVE-2016-6804). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000247 |
|
Vulnerability in apache (CVE-2017-1000247)
vulnerability in apache (CVE-2017-1000247). Data can be tampered with by attackers.
|
| CVE-2017-1000194 |
|
Unrestricted File Upload in apache (CVE-2017-1000194)
vulnerability in apache (CVE-2017-1000194). Successful exploitation can lead to full system takeover.
|
| CVE-2014-0219 |
|
Vulnerability in apache (CVE-2014-0219)
vulnerability in apache (CVE-2014-0219). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12633 |
|
Unsafe Deserialization in apache (CVE-2017-12633)
vulnerability in apache (CVE-2017-12633). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12634 |
|
Unsafe Deserialization in apache (CVE-2017-12634)
vulnerability in apache (CVE-2017-12634). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12635 |
|
Privilege Escalation in apache (CVE-2017-12635)
vulnerability in apache (CVE-2017-12635). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12636 |
|
OS Command Injection in apache (CVE-2017-12636)
OS command injection in apache (CVE-2017-12636). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12624 |
|
Vulnerability in apache (CVE-2017-12624)
vulnerability in apache (CVE-2017-12624). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-6803 |
|
Vulnerability in apache (CVE-2016-6803)
vulnerability in apache (CVE-2016-6803). Successful exploitation can lead to full system takeover.
|
| CVE-2017-3166 |
|
Vulnerability in apache (CVE-2017-3166)
vulnerability in apache (CVE-2017-3166). Successful exploitation can lead to full system takeover.
|
| CVE-2015-7501 |
|
Unsafe Deserialization in apache (CVE-2015-7501)
vulnerability in apache (CVE-2015-7501). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12625 |
|
Information Disclosure in apache (CVE-2017-12625)
vulnerability in apache (CVE-2017-12625). Risk of unauthorized operations or information disclosure.
|
| CVE-2012-4449 |
|
Vulnerability in apache (CVE-2012-4449)
vulnerability in apache (CVE-2012-4449). Successful exploitation can lead to full system takeover.
|
| CVE-2012-5636 |
|
Cross-Site Scripting (XSS) in apache (CVE-2012-5636)
cross-site scripting in apache (CVE-2012-5636). Risk of unauthorized operations or information disclosure.
|
| CVE-2013-4366 |
|
Vulnerability in apache (CVE-2013-4366)
vulnerability in apache (CVE-2013-4366). Successful exploitation can lead to full system takeover.
|
| CVE-2014-0072 |
|
Vulnerability in apache (CVE-2014-0072)
vulnerability in apache (CVE-2014-0072). Data can be tampered with by attackers.
|
| CVE-2014-0073 |
|
Vulnerability in apache (CVE-2014-0073)
vulnerability in apache (CVE-2014-0073). Successful exploitation can lead to full system takeover.
|
| CVE-2009-1197 |
|
Vulnerability in apache (CVE-2009-1197)
vulnerability in apache (CVE-2009-1197). Risk of unauthorized operations or information disclosure.
|
| CVE-2009-1198 |
|
Cross-Site Scripting (XSS) in apache (CVE-2009-1198)
cross-site scripting in apache (CVE-2009-1198). Risk of unauthorized operations or information disclosure.
|
| CVE-2012-0881 |
|
Vulnerability in apache (CVE-2012-0881)
vulnerability in apache (CVE-2012-0881). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-0115 |
|
Path Traversal in apache (CVE-2014-0115)
path traversal in apache (CVE-2014-0115). Confidential information can be exposed externally.
|
| CVE-2013-4246 |
|
Vulnerability in c (CVE-2013-4246)
vulnerability in c (CVE-2013-4246). Successful exploitation can lead to full system takeover.
|