📦

jackson-databind

Vendor: fasterxml

Actively Exploited 0 CISA KEV List
PoC / Exploits 62 Code Available
Total RCEs 64 Remote Access
Total CVEs 110 Total Indexed
Avg. EPSS 8.67% Exploit Prob.
Latest CVE CVE-2026-54518 Jun 23

Security Vulnerability Index

Page 3 / 11
8.1 CVSS
CVE-2020-36188
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

EPSS: 10.91%
8.1 CVSS
CVE-2020-36187
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.

EPSS: 5.20%
8.1 CVSS
CVE-2020-36186
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.

EPSS: 5.22%
8.1 CVSS
CVE-2020-36185
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.

EPSS: 5.22%
8.1 CVSS
CVE-2020-36184
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.

EPSS: 10.38%
8.1 CVSS
CVE-2020-36181
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.

EPSS: 5.02%
8.1 CVSS
CVE-2020-35728
Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

EPSS: 12.50%
8.1 CVSS
CVE-2020-35491
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

EPSS: 9.48%
8.1 CVSS
CVE-2020-35490
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

EPSS: 7.69%
7.5 CVSS
CVE-2020-25649
Exploit Found

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

EPSS: 17.61%