Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-14062 |
|
Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
|
| CVE-2020-10683 |
|
XXE (XML External Entity) in dom4j-project (CVE-2020-10683)
vulnerability in dom4j-project (CVE-2020-10683). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11619 |
|
Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11111 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
| CVE-2020-11112 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10968 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2020-9548 |
|
Unsafe Deserialization in fasterxml (CVE-2020-9548)
vulnerability in fasterxml (CVE-2020-9548). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9546 |
|
Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
|
| CVE-2019-17569 |
|
Vulnerability in apache (CVE-2019-17569)
vulnerability in apache (CVE-2019-17569). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-17571 |
|
Unsafe Deserialization in log4j:log4j (CVE-2019-17571)
vulnerability in log4j:log4j (CVE-2019-17571). Successful exploitation can lead to full system takeover.
|
| CVE-2019-10219 |
|
Cross-Site Scripting (XSS) in redhat (CVE-2019-10219)
cross-site scripting in redhat (CVE-2019-10219). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-16168 |
|
Vulnerability in c (CVE-2019-16168)
vulnerability in c (CVE-2019-16168). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-15213 |
|
Use-After-Free in c (CVE-2019-15213)
vulnerability in c (CVE-2019-15213). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-13118 |
|
Vulnerability in nokogiri (CVE-2019-13118)
vulnerability in nokogiri (CVE-2019-13118). Confidential information can be exposed externally. Exploitable via ``numbers.c``. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-11068 |
|
Vulnerability in nokogiri (CVE-2019-11068)
vulnerability in nokogiri (CVE-2019-11068). Successful exploitation can lead to full system takeover. Exploitable via ``xsltCheckRead``. Mitigation: upgrade to `1.10.3` or later.
|
| CVE-2019-7317 |
|
Use-After-Free in c (CVE-2019-7317)
vulnerability in c (CVE-2019-7317). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-6109 |
|
Vulnerability in c (CVE-2019-6109)
vulnerability in c (CVE-2019-6109). Confidential information can be exposed externally.
|
| CVE-2018-1258 |
|
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
|
| CVE-2017-5753 |
|
Vulnerability in intel (CVE-2017-5753)
vulnerability in intel (CVE-2017-5753). Confidential information can be exposed externally.
|
| CVE-2017-14583 |
|
Vulnerability in dos (CVE-2017-14583)
vulnerability in dos (CVE-2017-14583). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-6904 |
|
Vulnerability in netapp (CVE-2016-6904)
vulnerability in netapp (CVE-2016-6904). Successful exploitation can lead to full system takeover.
|
| CVE-2017-15707 |
|
Vulnerability in apache (CVE-2017-15707)
vulnerability in apache (CVE-2017-15707). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-15517 |
|
Information Disclosure in netapp (CVE-2017-15517)
vulnerability in netapp (CVE-2017-15517). Confidential information can be exposed externally.
|
| CVE-2017-15516 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-15516)
vulnerability in csrf (CVE-2017-15516). Successful exploitation can lead to full system takeover.
|
| CVE-2016-8610 |
|
Vulnerability in dos (CVE-2016-8610)
vulnerability in dos (CVE-2016-8610). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5201 |
|
Information Disclosure in netapp (CVE-2017-5201)
vulnerability in netapp (CVE-2017-5201). Confidential information can be exposed externally.
|
| CVE-2017-11461 |
|
Vulnerability in netapp (CVE-2017-11461)
vulnerability in netapp (CVE-2017-11461). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-16642 |
|
Out-of-Bounds Read in c (CVE-2017-16642)
vulnerability in c (CVE-2017-16642). Confidential information can be exposed externally.
|
| CVE-2017-15906 |
|
Vulnerability in c (CVE-2017-15906)
vulnerability in c (CVE-2017-15906). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10378 |
|
Vulnerability in c (CVE-2017-10378)
vulnerability in c (CVE-2017-10378). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10379 |
|
Authorization Flaw in c (CVE-2017-10379)
vulnerability in c (CVE-2017-10379). Confidential information can be exposed externally.
|
| CVE-2017-10384 |
|
Vulnerability in c (CVE-2017-10384)
vulnerability in c (CVE-2017-10384). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10388 |
|
Vulnerability in c (CVE-2017-10388)
vulnerability in c (CVE-2017-10388). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10346 |
|
Vulnerability in c (CVE-2017-10346)
vulnerability in c (CVE-2017-10346). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10347 |
|
Vulnerability in c (CVE-2017-10347)
vulnerability in c (CVE-2017-10347). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10348 |
|
Vulnerability in c (CVE-2017-10348)
vulnerability in c (CVE-2017-10348). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10349 |
|
Vulnerability in c (CVE-2017-10349)
vulnerability in c (CVE-2017-10349). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10350 |
|
Vulnerability in c (CVE-2017-10350)
vulnerability in c (CVE-2017-10350). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10355 |
|
Vulnerability in c (CVE-2017-10355)
vulnerability in c (CVE-2017-10355). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10356 |
|
Vulnerability in c (CVE-2017-10356)
vulnerability in c (CVE-2017-10356). Confidential information can be exposed externally.
|
| CVE-2017-10357 |
|
Vulnerability in c (CVE-2017-10357)
vulnerability in c (CVE-2017-10357). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10365 |
|
Vulnerability in c (CVE-2017-10365)
vulnerability in c (CVE-2017-10365). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10320 |
|
Vulnerability in c (CVE-2017-10320)
vulnerability in c (CVE-2017-10320). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10345 |
|
Vulnerability in c (CVE-2017-10345)
vulnerability in c (CVE-2017-10345). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10281 |
|
Vulnerability in c (CVE-2017-10281)
vulnerability in c (CVE-2017-10281). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10285 |
|
Vulnerability in c (CVE-2017-10285)
vulnerability in c (CVE-2017-10285). Successful exploitation can lead to full system takeover.
|