Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Data Center Expert HIGH 8.8
CVE-2022-32521

A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deseriali…

Fix: 7.9.0+
Fix from $1,950 2023-01-30
Vrealize Log Insight HIGH 7.5
CVE-2022-31710

vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrust…

Fix: 8.10.2+
Fix from $1,950 2023-01-26
Opentext Extended Ecm HIGH 8.8
CVE-2022-45923

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker …

Fix: after 22.4
Fix from $1,950 2023-01-18
Weblogic Server HIGH 7.5
CVE-2023-21839 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Patch available
Fix from $1,950 2023-01-18
Predictapp CRITICAL 9.8
CVE-2022-4890

A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file …

Fix: 2022-03-20+
Fix from $2,300 2023-01-16
Tiki HIGH 8.8
CVE-2023-22850

Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.

Fix: 24.1+
Fix from $1,950 2023-01-14
Datax Web CRITICAL 9.8
CVE-2022-46478

The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary comma…

Fix: after 2.1.2
Fix from $2,300 2023-01-13
Infrasuite Device Master HIGH 8.8
CVE-2022-41778

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect servic…

Fix: after 00.00.01a
Fix from $1,950 2023-01-13
Visual Studio Code HIGH 7.8
CVE-2023-21779

Visual Studio Code Remote Code Execution Vulnerability

Fix: 1.74.3+
Fix from $1,950 2023-01-10
Exchange Server HIGH 8.0
CVE-2023-21745

Microsoft Exchange Server Spoofing Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Exchange Server HIGH 8.0
CVE-2023-21762

Microsoft Exchange Server Spoofing Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Sharepoint Foundation HIGH 8.8
CVE-2023-21744

Microsoft SharePoint Server Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Fedora HIGH 7.5
CVE-2023-21538

.NET Denial of Service Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Spitfire HIGH 8.8
CVE-2022-47083EPSS 18%

A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via…

No fix yet
Fix from $1,950 2023-01-10
Nuxeo MEDIUM 6.1
CVE-2021-32828

The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vu…

Fix: after 11.5.109
Fix from $1,600 2023-01-05
Dubbo CRITICAL 9.8
CVE-2021-32824

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…

Fix: 2.6.10 / 2.7.10+
Fix from $2,300 2023-01-03
Xstream HIGH 7.5
CVE-2022-41966EPSS 9%

XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack…

Fix: 1.4.20+
Fix from $1,950 2022-12-28
Debian Linux HIGH 8.1
CVE-2020-10650

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via igni…

Fix: 2.9.10.4+
Fix from $1,950 2022-12-26
Harmonyos HIGH 7.5
CVE-2022-41596

The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of …

Fix: 2.1+
Fix from $1,950 2022-12-20
Ruoyi CRITICAL 9.8
CVE-2021-38241

Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.

Fix: 4.6.1+
Fix from $2,300 2022-12-16
Replicator CRITICAL 9.8
CVE-2021-33420

A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable functio…

Fix: 1.0.4+
Fix from $2,300 2022-12-15
Skycaiji CRITICAL 9.8
CVE-2022-44351

Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.

No fix yet
Fix from $2,300 2022-12-07
Hope Boot CRITICAL 9.8
CVE-2022-44371

hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).

No fix yet
Fix from $2,300 2022-12-07
Activerecord CRITICAL 9.8
CVE-2022-32224

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 whic…

Fix: 5.2.8.1 / 6.0.5.1+
Fix from $2,300 2022-12-05
Tapestry CRITICAL 9.8
CVE-2022-46366

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…

Fix: 4.0.0+
Fix from $2,300 2022-12-02
Snakeyaml CRITICAL 9.8
CVE-2022-1471EPSS 100%

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an a…

Fix: 2.0+
Fix from $2,300 2022-12-01
Orion Platform HIGH 8.8
CVE-2022-36964EPSS 17%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Super Xray HIGH 7.8
CVE-2022-41958

super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. A…

Fix: 0.7+
Fix from $1,950 2022-11-25
Optica CRITICAL 9.8
CVE-2022-41875

A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads.…

Fix: 0.10.2+
Fix from $2,300 2022-11-23
Yii CRITICAL 9.8
CVE-2022-41922

`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. T…

Fix: 1.1.27+
Fix from $2,300 2022-11-23