Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-44832 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.
|
| CVE-2021-45105 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-45105). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.1` or later.
|
| CVE-2021-41184 |
|
Cross-Site Scripting (XSS) in jquery-ui (CVE-2021-41184)
cross-site scripting in jquery-ui (CVE-2021-41184). Data can be tampered with by attackers. Mitigation: upgrade to `1.13.0` or later.
|
| CVE-2021-41182 |
|
Cross-Site Scripting (XSS) in jquery-ui (CVE-2021-41182)
cross-site scripting in jquery-ui (CVE-2021-41182). Data can be tampered with by attackers. Exploitable via ``altField``. Mitigation: upgrade to `1.13.0` or later.
|
| CVE-2021-2351 |
|
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unau...
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Su...
|
| CVE-2021-36374 |
|
Vulnerability in apache (CVE-2021-36374)
vulnerability in apache (CVE-2021-36374). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-36373 |
|
Vulnerability in apache (CVE-2021-36373)
vulnerability in apache (CVE-2021-36373). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-29425 |
|
Vulnerability in apache (CVE-2021-29425)
vulnerability in apache (CVE-2021-29425). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-36183 |
|
Unsafe Deserialization in apache (CVE-2020-36183)
vulnerability in apache (CVE-2020-36183). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36182 |
|
Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36179 |
|
Unsafe Deserialization in apache (CVE-2020-36179)
vulnerability in apache (CVE-2020-36179). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36180 |
|
Unsafe Deserialization in apache (CVE-2020-36180)
vulnerability in apache (CVE-2020-36180). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36189 |
|
Unsafe Deserialization in fasterxml (CVE-2020-36189)
vulnerability in fasterxml (CVE-2020-36189). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36188 |
|
Unsafe Deserialization in fasterxml (CVE-2020-36188)
vulnerability in fasterxml (CVE-2020-36188). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36187 |
|
Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36186 |
|
Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36185 |
|
Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36184 |
|
Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36181 |
|
Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35728 |
|
Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
|
| CVE-2020-17521 |
|
Vulnerability in apache (CVE-2020-17521)
vulnerability in apache (CVE-2020-17521). Confidential information can be exposed externally.
|
| CVE-2020-9488 |
|
Vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488)
vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.2` or later.
|
| CVE-2020-11619 |
|
Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-11112 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
| CVE-2020-11111 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10968 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2020-9548 |
|
Unsafe Deserialization in fasterxml (CVE-2020-9548)
vulnerability in fasterxml (CVE-2020-9548). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9546 |
|
Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
|
| CVE-2019-10219 |
|
Cross-Site Scripting (XSS) in redhat (CVE-2019-10219)
cross-site scripting in redhat (CVE-2019-10219). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10150 |
|
Vulnerability in c (CVE-2017-10150)
vulnerability in c (CVE-2017-10150). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-10149 |
|
Vulnerability in c (CVE-2017-10149)
vulnerability in c (CVE-2017-10149). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-3501 |
|
Vulnerability in c (CVE-2017-3501)
vulnerability in c (CVE-2017-3501). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-7103 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2016-7103)
cross-site scripting in jqueryui (CVE-2016-7103). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-4055 |
|
Vulnerability in dos (CVE-2016-4055)
vulnerability in dos (CVE-2016-4055). Risk of unauthorized operations or information disclosure.
|