CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2022-23307 CRITICAL

A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.

CVSS 9.8 EPSS 54.41% Jan 18, 2022
CVE-2022-23305 CRITICAL

SQL injection in JDBC Appender in Apache Log4j V1

CVSS 9.8 EPSS 66.54% Jan 18, 2022
CVE-2022-23302 HIGH

Deserialization of untrusted data in JMSSink in Apache Log4j 1.x

CVSS 8.8 EPSS 63.56% Jan 18, 2022
CVE-2021-43797 MEDIUM

HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling

CVSS 6.5 EPSS 2.68% Dec 9, 2021
CVE-2021-37136 HIGH

netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data

CVSS 7.5 EPSS 5.91% Oct 19, 2021
CVE-2021-33037 MEDIUM

Incorrect Transfer-Encoding handling with HTTP/1.0

CVSS 5.3 EPSS 74.67% Jul 12, 2021
CVE-2021-25329 HIGH

Incomplete fix for CVE-2020-9484

CVSS 7.0 EPSS 9.49% Mar 1, 2021
CVE-2021-25122 HIGH

Apache Tomcat h2c request mix-up

CVSS 7.5 EPSS 18.11% Mar 1, 2021
CVE-2020-36179 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS

CVSS 8.8 EPSS 17.07% Jan 6, 2021
CVE-2020-36180 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS

CVSS 8.8 EPSS 4.04% Jan 6, 2021
CVE-2020-36182 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS

CVSS 8.8 EPSS 4.04% Jan 6, 2021
CVE-2020-36183 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool

CVSS 8.1 EPSS 4.91% Jan 6, 2021
CVE-2020-36184 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource

CVSS 8.8 EPSS 8.36% Jan 6, 2021
CVE-2020-36185 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource

CVSS 8.1 EPSS 4.19% Jan 6, 2021
CVE-2020-36186 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource

CVSS 8.1 EPSS 4.19% Jan 6, 2021
CVE-2020-36187 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource

CVSS 8.1 EPSS 4.19% Jan 6, 2021
CVE-2020-36188 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnection…

CVSS 8.1 EPSS 8.79% Jan 6, 2021
CVE-2020-36189 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerC…

CVSS 8.1 EPSS 3.94% Jan 6, 2021
CVE-2020-36181 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS

CVSS 8.8 EPSS 4.04% Jan 6, 2021
CVE-2020-35490 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource

CVSS 8.1 EPSS 6.29% Dec 17, 2020
CVE-2020-35491 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource

CVSS 8.1 EPSS 7.75% Dec 17, 2020
CVE-2020-17527 HIGH

Apache Tomcat: Request header mix-up between HTTP/2 streams

CVSS 7.5 EPSS 24.62% Dec 3, 2020
CVE-2020-25649 HIGH

jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)

CVSS 7.5 EPSS 17.26% Dec 3, 2020
CVE-2020-24750 HIGH

jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration

CVSS 8.1 EPSS 7.33% Sep 17, 2020
CVE-2020-24616 HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource

CVSS 8.1 EPSS 7.58% Aug 25, 2020

Showing 1 to 25 CVEs · page 1 (more available)