Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Datagear HIGH 8.8
CVE-2023-2042

A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functional…

Fix: after 4.5.1
Fix from $1,950 2023-04-14
Toolboxst HIGH 7.8
CVE-2023-1552

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social…

Fix: 7.10+
Fix from $1,950 2023-04-11
Wp Meta Seo HIGH 8.8
CVE-2023-1381

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR d…

Fix: 4.5.5+
Fix from $1,950 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-29215

In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-29216

In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Livecycle Es4 CRITICAL 9.8
CVE-2023-28500

A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operati…

Fix: 11.0.1+
Fix from $2,300 2023-04-06
Secure Network Analytics HIGH 8.8
CVE-2023-20102

A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbi…

Fix: after 7.4.1
Fix from $1,950 2023-04-05
Order HIGH 8.8
CVE-2023-29006

The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an aut…

Fix: 2.7.7+
Fix from $1,950 2023-04-05
Zend Framework CRITICAL 9.8
CVE-2020-29312

An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be…

Fix: after 3.1.3
Fix from $2,300 2023-04-04
Payara Server CRITICAL 9.8
CVE-2023-28462

A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (C…

Fix: after 5.0.0
Fix from $2,300 2023-03-30
Avalanche CRITICAL 9.8
CVE-2022-36974EPSS 84%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36977EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36978EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Quickopc HIGH 7.8
CVE-2022-2561

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is requi…

Fix: 5.63.246+
Fix from $1,950 2023-03-29
Aveva Edge HIGH 7.8
CVE-2022-28685EPSS 17%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Avalanche HIGH 8.8
CVE-2022-36971EPSS 15%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $1,950 2023-03-29
Emui HIGH 7.8
CVE-2023-26547

The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privile…

No fix yet
Fix from $1,950 2023-03-27
Emui HIGH 7.5
CVE-2023-26548

The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2023-03-27
N6854a Firmware CRITICAL 9.8
CVE-2023-1399

N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges i…

Fix: after 2.4.2
Fix from $2,300 2023-03-27
Infrasuite Device Master HIGH 7.8
CVE-2023-1145

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect s…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Inlong HIGH 8.8
CVE-2023-27296

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong,…

Fix: after 1.5.0
Fix from $1,950 2023-03-27
Infrasuite Device Master CRITICAL 9.8
CVE-2023-1133EPSS 50%

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ …

Fix: 1.0.5+
Fix from $2,300 2023-03-27
Infrasuite Device Master HIGH 8.8
CVE-2023-1139

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway servi…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Coldfusion CRITICAL 9.8
CVE-2023-26359 KEVEPSS 18%

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabil…

Patch available
Fix from $2,300 2023-03-23
Lead Generated CRITICAL 9.8
CVE-2023-28667

The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of …

Fix: 1.25+
Fix from $2,300 2023-03-22
Custom Reports HIGH 7.8
CVE-2023-27978EPSS 6%

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload dat…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Snappy CRITICAL 9.8
CVE-2023-28115

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHA…

Fix: 1.4.2+
Fix from $2,300 2023-03-17
Log4j HIGH 7.5
CVE-2023-26464

** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t…

Fix: 2.0+
Fix from $1,950 2023-03-10
Dubbo CRITICAL 9.8
CVE-2023-23638

A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.…

Fix: after 3.1.5
Fix from $2,300 2023-03-08
Yf Exam CRITICAL 9.8
CVE-2023-26779

CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).

No fix yet
Fix from $2,300 2023-03-03