📦

jackson-databind

Vendor: fasterxml

Actively Exploited 0 CISA KEV List
PoC / Exploits 62 Code Available
Total RCEs 64 Remote Access
Total CVEs 110 Total Indexed
Avg. EPSS 8.67% Exploit Prob.
Latest CVE CVE-2026-54518 Jun 23

Security Vulnerability Index

Page 4 / 11
8.1 CVSS
CVE-2020-24750
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

EPSS: 7.33%
8.1 CVSS
CVE-2020-24616
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

EPSS: 9.42%
8.1 CVSS
CVE-2020-14195
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).

EPSS: 4.55%
8.1 CVSS
CVE-2020-14060
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).

EPSS: 8.61%
8.1 CVSS
CVE-2020-14062
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

EPSS: 8.07%
8.1 CVSS
CVE-2020-14061
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).

EPSS: 4.46%
8.1 CVSS
CVE-2020-11620
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

EPSS: 5.64%
8.1 CVSS
CVE-2020-11619
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

EPSS: 3.61%
8.8 CVSS
CVE-2020-11113
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

EPSS: 6.28%
8.8 CVSS
CVE-2020-11112
RCE Exploit Found

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).

EPSS: 3.58%