Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Helix CRITICAL 9.8
CVE-2023-38647

An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S…

Fix: 1.3.0+
Fix from $2,300 2023-07-26
Jackrabbit CRITICAL 9.8
CVE-2023-37895

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in…

Fix: 2.20.11 / 2.21.18+
Fix from $2,300 2023-07-25
Inlong HIGH 7.5
CVE-2023-34434

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.…

Fix: after 1.7.0
Fix from $1,950 2023-07-25
Zenon HIGH 7.5
CVE-2023-3324

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…

Fix: after 11.0.0
Fix from $1,950 2023-07-24
Coldfusion CRITICAL 9.8
CVE-2023-38203 KEVEPSS 97%

Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vu…

Patch available
Fix from $2,300 2023-07-20
Shardingsphere HIGH 8.8
CVE-2023-28754

Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a sp…

Fix: 5.4.0+
Fix from $1,950 2023-07-19
Eventmesh Connector Rabbitmq CRITICAL 9.8
CVE-2023-26512

CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac…

Fix: after 1.8.0
Fix from $2,300 2023-07-17
Razer Central HIGH 7.8
CVE-2023-3513

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access…

Fix: after 7.11.0.558
Fix from $1,950 2023-07-14
C300 Firmware HIGH 7.5
CVE-2023-25770

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notific…

Fix: after 520.2tcu2
Fix from $1,950 2023-07-13
User Registration HIGH 8.8
CVE-2023-3343

The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untru…

Fix: after 3.0.1
Fix from $1,950 2023-07-13
Coldfusion CRITICAL 9.8
CVE-2023-29300 KEVEPSS 100%

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untruste…

Mitigation only
Fix from $2,300 2023-07-12
Platform CRITICAL 9.8
CVE-2023-36825

Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability prese…

Fix: 14.5.0+
Fix from $2,300 2023-07-11
Windows Server 2012 HIGH 7.8
CVE-2023-35317

Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-07-11
Sharepoint Server HIGH 8.8
CVE-2023-33160

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-07-11
Sharepoint Server HIGH 8.8
CVE-2023-33134

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-07-11
Infrasuite Device Master CRITICAL 9.8
CVE-2023-34347

​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remo…

Fix: 1.0.7+
Fix from $2,300 2023-07-10
Johnzon MEDIUM 5.3
CVE-2023-33008

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input tha…

Fix: 1.2.21+
Fix from $1,600 2023-07-07
Endpoint Manager CRITICAL 9.8
CVE-2023-28323

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit…

Fix: 2022+
Fix from $2,300 2023-07-01
Paceart Optima HIGH 8.8
CVE-2023-31222EPSS 28%

Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an…

Fix: 1.12+
Fix from $1,950 2023-06-29
Android MEDIUM 5.5
CVE-2023-21205

In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-06-28
Android MEDIUM 6.7
CVE-2023-21209

In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of …

Mitigation only
Fix from $1,600 2023-06-28
Fortinac CRITICAL 9.8
CVE-2023-33299EPSS 24%

A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to exe…

Fix: after 9.2.7
Fix from $2,300 2023-06-23
Open Xchange Appsuite Backend HIGH 8.8
CVE-2023-26436

Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserializa…

Fix: 7.10.6+
Fix from $1,950 2023-06-20
Solon CRITICAL 9.8
CVE-2023-35839

A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.

Fix: 2.3.3+
Fix from $2,300 2023-06-19
Icefrog HIGH 8.8
CVE-2023-3308

A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template …

No fix yet
Fix from $1,950 2023-06-18
Android HIGH 7.8
CVE-2023-21124

In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege…

Patch available
Fix from $1,950 2023-06-15
Exchange Server HIGH 8.8
CVE-2023-32031EPSS 81%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-06-14
Exchange Server HIGH 8.0
CVE-2023-28310EPSS 25%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-06-14
Igss Dashboard HIGH 7.8
CVE-2023-3001EPSS 32%

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload dat…

Fix: 16.0.0.23131+
Fix from $1,950 2023-06-14
Crmeb CRITICAL 9.8
CVE-2023-3234

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_im…

Fix: after 4.6.0
Fix from $2,300 2023-06-14