Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Serviceguard For Linux CRITICAL 9.8
CVE-2022-37936

Unauthenticated Java deserialization vulnerability in Serviceguard Manager

Mitigation only
Fix from $2,300 2023-03-01
Debian Linux CRITICAL 9.8
CVE-2023-27372EPSS 100%

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Fix: 3.2.18 / 4.0.10+
Fix from $2,300 2023-02-28
Android HIGH 7.8
CVE-2023-20944

In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esca…

Patch available
Fix from $1,950 2023-02-28
Litedb CRITICAL 9.8
CVE-2022-23535

LiteDB is a small, fast and lightweight .NET NoSQL embedded database. Versions prior to 5.0.13 are subject to Deserialization of Untrusted Data. Lite…

Fix: 5.0.13+
Fix from $2,300 2023-02-24
Buddyforms CRITICAL 9.8
CVE-2023-26326

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated at…

Fix: 2.7.8+
Fix from $2,300 2023-02-23
Seacms CRITICAL 9.8
CVE-2023-0960

A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config…

No fix yet
Fix from $2,300 2023-02-22
C\# Driver HIGH 7.2
CVE-2022-48282

Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which …

Fix: 2.19.0+
Fix from $1,950 2023-02-21
Jd Gui CRITICAL 9.8
CVE-2023-26234

JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.

Patch available
Fix from $2,300 2023-02-21
Aspera Faspex CRITICAL 9.8
CVE-2022-47986 KEVEPSS 100%

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa…

Fix: after 4.4.1
Fix from $2,300 2023-02-17
Orion Platform HIGH 7.2
CVE-2023-23836EPSS 80%

SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-47507EPSS 7%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-38111EPSS 85%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-47503EPSS 24%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-47504EPSS 25%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Exchange Server HIGH 7.2
CVE-2023-21710EPSS 8%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Sql Server HIGH 8.8
CVE-2023-21713

Microsoft SQL Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Azure Data Box Gateway HIGH 7.2
CVE-2023-21703

Azure Data Box Gateway Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Exchange Server HIGH 8.8
CVE-2023-21706

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Exchange Server HIGH 8.8
CVE-2023-21707EPSS 82%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Exchange Server HIGH 8.8
CVE-2023-21529 KEVEPSS 62%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Sql Server 2019 Integration Services HIGH 7.3
CVE-2023-21568

Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Datahub HIGH 8.8
CVE-2023-25558

DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The…

Fix: 0.9.5+
Fix from $1,950 2023-02-11
Imagemagick Engine HIGH 8.8
CVE-2022-3568

The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and i…

Fix: 1.7.6+
Fix from $1,950 2023-02-10
Thinkphp CRITICAL 9.8
CVE-2022-45982

thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a c…

Fix: after 6.0.13
Fix from $2,300 2023-02-08
Kafka Connect HIGH 8.8
CVE-2023-25194EPSS 96%

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to…

Fix: after 3.3.2
Fix from $1,950 2023-02-07
Goanywhere Managed File Transfer HIGH 7.2
CVE-2023-0669 KEVEPSS 100%

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due t…

Fix: 7.1.2+
Fix from $1,950 2023-02-06
Vbulletin CRITICAL 9.8
CVE-2023-25135EPSS 24%

vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati…

No fix yet
Fix from $2,300 2023-02-03
Inlong CRITICAL 9.8
CVE-2023-24997

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.…

Fix: after 1.5.0
Fix from $2,300 2023-02-01
Hutool CRITICAL 9.8
CVE-2023-24162

Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.

No fix yet
Fix from $2,300 2023-01-31
Linkis HIGH 8.8
CVE-2022-44645

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…

Fix: after 1.3.0
Fix from $1,950 2023-01-31