CVE-2022-23307 CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a c... 8.8 - HIGH 2022-01-18 2023-02-24
CVE-2022-23305 By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inser... 9.8 - CRITICAL 2022-01-18 2023-02-24
CVE-2022-23302 JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to... 8.8 - HIGH 2022-01-18 2023-02-24
CVE-2021-42550 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.6 - MEDIUM 2021-12-16 2022-12-12
CVE-2020-9493 A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. 9.8 - CRITICAL 2021-06-16 2022-04-08
CVE-2020-9488 Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to ... 3.7 - LOW 2020-04-27 2022-05-12
CVE-2018-8088 org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended... 9.8 - CRITICAL 2018-03-20 2022-01-31
CVE-2017-5929 Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. 9.8 - CRITICAL 2017-03-13 2022-04-18

