Technology · Maven
org.apache.geode:geode-core (Maven) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in org.apache.geode:geode-core (Maven): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2022-34870, was published on 25 October 2022.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest org.apache.geode:geode-core (Maven) vulnerabilities
- CVE-2022-34870: Apache Geode vulnerable to Cross-Site ScriptinglowCVSS 3.1EPSS 1.2%
- CVE-2022-37022: Apache Geode versions deserialization of untrusted datawhen using JMX over RMI on Java 11lowCVSS 3.1EPSS 1.5%
- CVE-2022-37023: Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted datalowCVSS 3.1EPSS 1.7%
- CVE-2017-5649: Apache Geode information disclosure vulnerabilitylowCVSS 3EPSS 2.8%
- CVE-2017-9794: Apache Geode gfsh query vulnerabilitylowCVSS 3EPSS 1.2%
- CVE-2017-12622: Apache Geode gfsh authorization vulnerabilitylowCVSS 3EPSS 2.1%
- CVE-2017-9796: Apache Geode OQL bind parameter vulnerabilitylowCVSS 3EPSS 1.5%
- CVE-2017-15696: Apache Geode configuration request authorization vulnerabilitylowCVSS 3EPSS 2.0%
- CVE-2017-15693: Apache Geode unsafe deserialization of application objectslowCVSS 3EPSS 2.5%
- CVE-2017-15692: Apache Geode unsafe deserialization in TcpServerlowCVSS 3EPSS 4.8%
- CVE-2017-9795: Apache Geode OQL method invocation vulnerabilitylowCVSS 3EPSS 4.2%
- CVE-2017-9797: Apache Geode vulnerable to Exposure of Sensitive InformationlowCVSS 3EPSS 1.4%
- CVE-2017-15695: Apache Geode vulnerable to Incorrect AuthorizationlowCVSS 3EPSS 2.6%
- CVE-2019-10091: Apache Geode SSL endpoint verification vulnerabilitylowCVSS 3.1EPSS 1.4%
- CVE-2017-15694: Argument Injection in Apache Geode serverlowCVSS 3EPSS 2.2%
Most severe org.apache.geode:geode-core (Maven) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2022-37023: Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted datalowCVSS 3.1EPSS 1.7%
- CVE-2022-37022: Apache Geode versions deserialization of untrusted datawhen using JMX over RMI on Java 11lowCVSS 3.1EPSS 1.5%
- CVE-2019-10091: Apache Geode SSL endpoint verification vulnerabilitylowCVSS 3.1EPSS 1.4%
- CVE-2022-34870: Apache Geode vulnerable to Cross-Site ScriptinglowCVSS 3.1EPSS 1.2%
- CVE-2017-15692: Apache Geode unsafe deserialization in TcpServerlowCVSS 3EPSS 4.8%
- CVE-2017-9795: Apache Geode OQL method invocation vulnerabilitylowCVSS 3EPSS 4.2%
- CVE-2017-5649: Apache Geode information disclosure vulnerabilitylowCVSS 3EPSS 2.8%
- CVE-2017-15695: Apache Geode vulnerable to Incorrect AuthorizationlowCVSS 3EPSS 2.6%
- CVE-2017-15693: Apache Geode unsafe deserialization of application objectslowCVSS 3EPSS 2.5%
- CVE-2017-15694: Argument Injection in Apache Geode serverlowCVSS 3EPSS 2.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/org-apache-geode-geode-core.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "org.apache.geode:geode-core (Maven) vulnerabilities", https://junglewise.ai/threats/technologies/org-apache-geode-geode-core, 28 September 2026.