Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Orion Platform HIGH 7.2
CVE-2022-38108EPSS 69%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Fix: 2020.2.6+
Fix from $1,950 2022-10-20
Orion Platform HIGH 7.2
CVE-2022-36957EPSS 13%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Fix: 2020.2.6+
Fix from $1,950 2022-10-20
Orion Platform HIGH 8.8
CVE-2022-36958EPSS 83%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…

Fix: 2020.2.6+
Fix from $1,950 2022-10-20
Opencats CRITICAL 9.8
CVE-2022-43019

OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

No fix yet
Fix from $2,300 2022-10-19
Enterprise Server HIGH 8.8
CVE-2022-23734

A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on …

Fix: 3.2.16 / 3.3.11+
Fix from $1,950 2022-10-19
Dubbo CRITICAL 9.8
CVE-2022-39198

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…

Fix: after 3.0.11
Fix from $2,300 2022-10-18
Phpok CRITICAL 9.8
CVE-2022-40889

Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

No fix yet
Fix from $2,300 2022-10-18
Junos CRITICAL 9.8
CVE-2022-22241

An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data w…

Fix: 19.1+
Fix from $2,300 2022-10-18
GitLab MEDIUM 6.5
CVE-2022-3291

Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can lea…

Fix: 15.2.5 / 15.3.4+
Fix from $1,600 2022-10-17
Gocd HIGH 8.8
CVE-2022-39311

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go…

Fix: 21.1.0+
Fix from $1,950 2022-10-14
Meliscms CRITICAL 9.8
CVE-2022-39297

MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools. Attackers ca…

Fix: 5.0.1+
Fix from $2,300 2022-10-12
Meliscms CRITICAL 9.8
CVE-2022-39298

MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewritting, search optimization an…

Fix: 5.0.1+
Fix from $2,300 2022-10-12
Paint.net CRITICAL 9.8
CVE-2018-18446

dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).

Fix: 4.1.2+
Fix from $2,300 2022-10-12
Paint.net CRITICAL 9.8
CVE-2018-18447

dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).

Fix: 4.1.2+
Fix from $2,300 2022-10-12
Vcenter Server CRITICAL 9.1
CVE-2022-31680EPSS 33%

The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on…

Fix: 6.5+
Fix from $2,300 2022-10-07
Android HIGH 7.8
CVE-2022-26471

In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2022-10-07
Android HIGH 7.8
CVE-2022-26472

In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additio…

Mitigation only
Fix from $1,950 2022-10-07
Exchange Server HIGH 8.0
CVE-2022-41082 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2022-10-03
Debian Linux HIGH 7.5
CVE-2022-42003

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value d…

Fix: 2.12.7.1 / 2.13.3+
Fix from $1,950 2022-10-02
Debian Linux HIGH 7.5
CVE-2022-42004

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to …

Fix: 2.12.7.1 / 2.13.0+
Fix from $1,950 2022-10-02
Moodle CRITICAL 9.8
CVE-2022-40314

A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

Fix: 3.9.17 / 3.11.10+
Fix from $2,300 2022-09-30
C1 Cms HIGH 8.0
CVE-2022-39256

Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrar…

Fix: 6.13+
Fix from $1,950 2022-09-27
Ninja Forms HIGH 7.2
CVE-2022-2903

The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections i…

Fix: 3.6.13+
Fix from $1,950 2022-09-26
Fedora CRITICAL 9.8
CVE-2022-36944EPSS 9%

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction …

Fix: 2.9.0 / 2.13.9+
Fix from $2,300 2022-09-23
Dotci CRITICAL 9.8
CVE-2022-41237

Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co…

Fix: after 2.40.00
Fix from $2,300 2022-09-21
Inlong HIGH 8.8
CVE-2022-40955

In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi…

Fix: 1.3.0+
Fix from $1,950 2022-09-20
Emui CRITICAL 9.1
CVE-2022-39008

The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to …

Mitigation only
Fix from $2,300 2022-09-16
Thinkphp CRITICAL 9.8
CVE-2022-38352EPSS 20%

ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerab…

No fix yet
Fix from $2,300 2022-09-15
Circuitverse HIGH 7.8
CVE-2022-36038

CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in…

Patch available
Fix from $1,950 2022-09-06
Ajax Load More HIGH 7.5
CVE-2022-2433

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export…

Fix: 5.5.4+
Fix from $1,950 2022-09-06