Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Exchange Server MEDIUM 5.7
CVE-2023-36777EPSS 81%

Microsoft Exchange Server Information Disclosure Vulnerability

Patch available
Fix from $1,600 2023-09-12
Exchange Server HIGH 8.0
CVE-2023-36757EPSS 69%

Microsoft Exchange Server Spoofing Vulnerability

Patch available
Fix from $1,950 2023-09-12
Exchange Server HIGH 8.0
CVE-2023-36744EPSS 82%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-09-12
Exchange Server HIGH 8.0
CVE-2023-36745EPSS 81%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-09-12
Exchange Server HIGH 8.0
CVE-2023-36756EPSS 75%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-09-12
Decision Manager HIGH 8.8
CVE-2022-1415

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a…

Mitigation only
Fix from $1,950 2023-09-11
Android HIGH 7.8
CVE-2023-35669

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deseriali…

Patch available
Fix from $1,950 2023-09-11
Agilis Xfs For Opteva CRITICAL 9.8
CVE-2020-19559

An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() p…

No fix yet
Fix from $2,300 2023-09-11
Jscape Mft HIGH 7.2
CVE-2023-4528EPSS 27%

Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (in…

Fix: 2023.1.9+
Fix from $1,950 2023-09-07
Snappy CRITICAL 9.8
CVE-2023-41330

knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerabili…

Fix: 1.4.3+
Fix from $2,300 2023-09-06
Webmethods CRITICAL 9.8
CVE-2023-0925

Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 b…

Mitigation only
Fix from $2,300 2023-09-06
Superset MEDIUM 6.6
CVE-2023-37941EPSS 29%

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to …

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Alienware Command Center HIGH 7.8
CVE-2023-28072

Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious user could po…

Fix: 5.5.51.0+
Fix from $1,950 2023-09-04
Splunk HIGH 8.8
CVE-2023-40595

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serial…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Airflow Spark Provider HIGH 8.8
CVE-2023-40195

Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo…

Fix: 4.1.3+
Fix from $1,950 2023-08-28
Weblogic Framework CRITICAL 9.8
CVE-2023-40571

weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a…

Fix: 0.2.4+
Fix from $2,300 2023-08-25
Yamlbeans HIGH 7.8
CVE-2023-24621

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class …

Fix: after 1.15
Fix from $1,950 2023-08-25
Spring For Apache Kafka HIGH 7.8
CVE-2023-34040

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual c…

Fix: after 3.0.9
Fix from $1,950 2023-08-24
Nacos Spring Project HIGH 8.8
CVE-2023-39106

An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() c…

Fix: after 1.1.1
Fix from $1,950 2023-08-21
Iboot Pdu4a C10 Firmware CRITICAL 9.8
CVE-2023-3259

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address fiel…

Fix: 1.44.0804202+
Fix from $2,300 2023-08-14
Emui HIGH 7.5
CVE-2023-39396

Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2023-08-13
Exchange Server HIGH 8.8
CVE-2023-38181EPSS 11%

Microsoft Exchange Server Spoofing Vulnerability

Patch available
Fix from $1,950 2023-08-08
Exchange Server HIGH 8.0
CVE-2023-38182EPSS 6%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-08-08
Exchange Server HIGH 8.0
CVE-2023-35388EPSS 7%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-08-08
Logisticspipes CRITICAL 9.8
CVE-2023-38689

Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `ObjectInputStream#readObject` on un…

Fix: 0.10.0.71+
Fix from $2,300 2023-08-04
Aerospike Java Client CRITICAL 9.8
CVE-2023-36480

The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, …

Fix: 4.5.0 / 5.2.0+
Fix from $2,300 2023-08-04
Sdk CRITICAL 9.8
CVE-2022-40609

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe dese…

Fix: 7.1.5.19 / 8.0.8.5+
Fix from $2,300 2023-08-02
Yolov5 HIGH 7.8
CVE-2021-31680

Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.

No fix yet
Fix from $1,950 2023-07-31
Yolov3 HIGH 7.8
CVE-2021-31681

Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.

No fix yet
Fix from $1,950 2023-07-31
B2b Advanced Communications MEDIUM 6.5
CVE-2023-24971

IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to t…

Fix: 1.0.0.8+
Fix from $1,600 2023-07-31