Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Solon CRITICAL 9.8
CVE-2023-48967

Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.

Fix: after 2.5.12
Fix from $2,300 2023-12-04
Nettyrpc CRITICAL 9.8
CVE-2023-48886

A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.

No fix yet
Fix from $2,300 2023-12-01
Jupiter CRITICAL 9.8
CVE-2023-48887

A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.

No fix yet
Fix from $2,300 2023-12-01
Infrasuite Device Master CRITICAL 9.8
CVE-2023-47207EPSS 17%

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local admi…

Mitigation only
Fix from $2,300 2023-11-30
Virtuoso HIGH 7.5
CVE-2023-48952

An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after ru…

No fix yet
Fix from $1,950 2023-11-29
Logback HIGH 7.5
CVE-2023-6378

A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack b…

Fix: 1.2.13 / 1.3.12+
Fix from $1,950 2023-11-29
Publiccms CRITICAL 9.8
CVE-2023-46990

Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep…

No fix yet
Fix from $2,300 2023-11-20
Submarine CRITICAL 9.8
CVE-2023-46302

Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail…

Fix: 0.8.0+
Fix from $2,300 2023-11-20
Coldfusion CRITICAL 9.8
CVE-2023-44350EPSS 65%

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that coul…

Fix: 2021+
Fix from $2,300 2023-11-17
Coldfusion CRITICAL 9.8
CVE-2023-44351EPSS 50%

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that coul…

Fix: 2021+
Fix from $2,300 2023-11-17
Coldfusion CRITICAL 9.8
CVE-2023-44353EPSS 80%

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that coul…

Fix: 2021+
Fix from $2,300 2023-11-17
Yii CRITICAL 9.8
CVE-2023-47130

Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `un…

Fix: 1.1.29+
Fix from $2,300 2023-11-14
Sharepoint Enterprise Server MEDIUM 6.8
CVE-2023-38177

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,600 2023-11-14
Exchange Server HIGH 8.0
CVE-2023-36439

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-11-14
Exchange Server HIGH 8.0
CVE-2023-36050EPSS 39%

Microsoft Exchange Server Spoofing Vulnerability

Patch available
Fix from $1,950 2023-11-14
Exchange Server HIGH 8.0
CVE-2023-36039EPSS 73%

Microsoft Exchange Server Spoofing Vulnerability

Patch available
Fix from $1,950 2023-11-14
Exchange Server HIGH 8.0
CVE-2023-36035EPSS 87%

Microsoft Exchange Server Spoofing Vulnerability

Patch available
Fix from $1,950 2023-11-14
Pyarrow CRITICAL 9.8
CVE-2023-47248EPSS 14%

Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is …

Fix: after 14.0.0
Fix from $2,300 2023-11-09
Uimaj HIGH 8.8
CVE-2023-39913

Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apach…

Fix: 3.5.0+
Fix from $1,950 2023-11-08
Phpfox CRITICAL 9.8
CVE-2023-46817

An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being …

Fix: 4.8.13+
Fix from $2,300 2023-11-03
Transmute Core CRITICAL 9.8
CVE-2023-47204

Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.

Fix: 1.13.5+
Fix from $2,300 2023-11-02
Bitrix24 HIGH 8.8
CVE-2023-1714

Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to exec…

No fix yet
Fix from $1,950 2023-11-01
Sftp Gateway Firmware CRITICAL 9.8
CVE-2023-47174

Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a …

Fix: 3.4.4+
Fix from $2,300 2023-10-31
Frigate HIGH 7.5
CVE-2023-45672

Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerability was identified in the endpo…

Fix: after 0.13.0
Fix from $1,950 2023-10-30
Wp Simple Galleries HIGH 8.8
CVE-2023-5583

The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untr…

Fix: after 1.34
Fix from $1,950 2023-10-30
Android MEDIUM 5.5
CVE-2023-40121

In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local informatio…

Patch available
Fix from $1,600 2023-10-27
Activemq CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to…

Fix: 5.15.16 / 5.16.7+
Fix from $2,300 2023-10-27
Mirth Connect CRITICAL 9.8
CVE-2023-43208 KEVEPSS 83%

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused …

Fix: 4.4.1+
Fix from $2,300 2023-10-26
Essential Blocks HIGH 8.1
CVE-2023-4386

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrus…

Fix: after 4.2.0
Fix from $1,950 2023-10-20
Jetpack Crm HIGH 8.8
CVE-2022-3342

The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_ap…

Fix: after 5.3.1
Fix from $1,950 2023-10-20