Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Parquet Java | 0 ~ 1.15.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | After reviewing the provided Proof of Concept (PoC) for CVE-2025-30065, it appears that the vulnerability exploits the deserialization mechanism in Apache Parquet's handling of Avro schemas, particularly through the use of the default property to instantiate arbitrary classes. | https://github.com/h3st4k3r/CVE-2025-30065 | POC Details |
| 2 | PoC | https://github.com/bjornhels/CVE-2025-30065 | POC Details |
| 3 | CVE-2025-30065 PoC | https://github.com/ron-imperva/CVE-2025-30065-PoC | POC Details |
| 4 | None | https://github.com/mouadk/parquet-rce-poc-CVE-2025-30065 | POC Details |
| 5 | A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked as CVE-2025-30065, this flaw affects Apache Parquet ≤ 1.15.0. All users must upgrade to version 1.15.1 immediately to mitigate exploitation risks. | https://github.com/ThreatRadarAI/TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation | POC Details |
| 6 | None | https://github.com/F5-Labs/parquet-canary-exploit-rce-poc-CVE-2025-30065 | POC Details |
| 7 | CVE-2025-30065 | https://github.com/B1ack4sh/Blackash-CVE-2025-30065 | POC Details |
| 8 | CVE-2025-30065 | https://github.com/Ashwesker/Blackash-CVE-2025-30065 | POC Details |
| 9 | CVE-2025-30065 | https://github.com/Ashwesker/Ashwesker-CVE-2025-30065 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-30676 | Apache OFBiz: Stored XSS Vulnerability | |
| CVE-2025-30177 | Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering | |
| CVE-2024-56325 | Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . au | |
| CVE-2025-29868 | Apache Answer: Using externally referenced images can leak user privacy. | |
| CVE-2025-27427 | Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAdd |
No comments yet