CVE-2022-22963
- EPSS 94.46%
- Published 01.04.2022 23:15:13
- Last modified 13.03.2025 16:36:53
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access ...
CVE-2022-22965
- EPSS 94.44%
- Published 01.04.2022 23:15:13
- Last modified 10.04.2025 16:56:46
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Sp...
CVE-2021-43859
- EPSS 2.4%
- Published 01.02.2022 12:15:08
- Last modified 23.05.2025 16:53:31
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resul...
CVE-2021-44832
- EPSS 53.59%
- Published 28.12.2021 20:15:08
- Last modified 21.11.2024 06:31:34
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has ...
CVE-2021-39152
- EPSS 67.83%
- Published 23.08.2021 19:15:13
- Last modified 23.05.2025 16:47:47
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed inp...
CVE-2021-39150
- EPSS 2.31%
- Published 23.08.2021 19:15:12
- Last modified 23.05.2025 16:48:02
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed inp...
CVE-2021-39140
- EPSS 0.12%
- Published 23.08.2021 19:15:10
- Last modified 23.05.2025 16:50:34
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload r...
CVE-2021-39154
- EPSS 0.71%
- Published 23.08.2021 18:15:13
- Last modified 23.05.2025 16:47:35
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39141
- EPSS 81.84%
- Published 23.08.2021 18:15:12
- Last modified 23.05.2025 16:52:36
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39144
- EPSS 94.41%
- Published 23.08.2021 18:15:12
- Last modified 23.05.2025 16:49:25
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user...