Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Fedora MEDIUM 5.3
CVE-2022-21549

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Patch available
Fix from $1,600 2022-07-19
Flexi Soft Designer HIGH 7.8
CVE-2022-27579

A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.…

Fix: 1.9.4+
Fix from $1,950 2022-07-19
Safety Designer HIGH 7.8
CVE-2022-27580

A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 al…

Fix: after 1.11.0
Fix from $1,950 2022-07-19
Workforce Access HIGH 7.8
CVE-2022-1984

This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 ma…

Fix: 7.3.0+
Fix from $1,950 2022-07-19
Infinity CRITICAL 9.8
CVE-2022-24082EPSS 12%

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no…

Fix: 8.7.3+
Fix from $2,300 2022-07-19
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-35405 KEVEPSS 100%

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect…

Fix: 4.3 / 5.5+
Fix from $2,300 2022-07-19
Feed Them Social CRITICAL 9.8
CVE-2022-2437

The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' …

Fix: 2.9.8.6+
Fix from $2,300 2022-07-18
Visualizer HIGH 8.8
CVE-2022-2444

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data…

Fix: 3.7.10+
Fix from $1,950 2022-07-18
Dvr Firmware CRITICAL 9.8
CVE-2021-41419EPSS 9%

QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.

Fix: 2021-12-13+
Fix from $2,300 2022-07-18
Gentics Cms HIGH 8.8
CVE-2022-30981

An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence …

Fix: 5.43.1+
Fix from $1,950 2022-07-17
Insync Client HIGH 7.8
CVE-2021-36665

An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

Fix: 7.0.0+
Fix from $1,950 2022-07-12
Nvflare CRITICAL 9.8
CVE-2022-31604

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and …

Fix: 2.1.2+
Fix from $2,300 2022-07-01
Nvflare CRITICAL 9.8
CVE-2022-31605

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load…

Fix: 2.1.2+
Fix from $2,300 2022-07-01
Opensearch HIGH 8.8
CVE-2022-31115

opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used inst…

Fix: 2.0.2+
Fix from $1,950 2022-06-30
Thinkphp CRITICAL 9.8
CVE-2022-33107EPSS 23%

ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Abstr…

No fix yet
Fix from $2,300 2022-06-29
Android MEDIUM 5.0
CVE-2022-20195

In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial o…

Mitigation only
Fix from $1,600 2022-06-15
Ar8035 Firmware HIGH 7.0
CVE-2021-35095

Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same…

Patch available
Fix from $1,950 2022-06-14
Fastjson CRITICAL 9.8
CVE-2022-25845EPSS 19%

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restric…

Fix: 1.2.83+
Fix from $2,300 2022-06-10
Gatsby CRITICAL 9.8
CVE-2022-25863

The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input thro…

Fix: 2.14.1 / 3.15.2+
Fix from $2,300 2022-06-10
N6854a Firmware CRITICAL 9.8
CVE-2022-1660EPSS 17%

The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker…

Fix: 2.4.0+
Fix from $2,300 2022-06-02
Biograph Horizon Pet\/ct Systems Firmware CRITICAL 9.8
CVE-2022-29875

A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA…

Mitigation only
Fix from $2,300 2022-06-01
In Sight Opc Server CRITICAL 9.8
CVE-2021-32935

The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker…

Fix: after 5.7.4_
Fix from $2,300 2022-05-23
Yaml HIGH 7.5
CVE-2022-28948

An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

Patch available
Fix from $1,950 2022-05-19
Connected Component Workbench HIGH 7.8
CVE-2022-1118EPSS 11%

Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and pr…

Fix: after 13.00.00
Fix from $1,950 2022-05-17
So Listing Tabs CRITICAL 9.8
CVE-2022-24108EPSS 33%

The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potenti…

No fix yet
Fix from $2,300 2022-05-17
Artifactory HIGH 8.8
CVE-2022-0573

JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation …

Fix: 6.23.41 / 7.17.16+
Fix from $1,950 2022-05-16
Phpok CRITICAL 9.8
CVE-2022-29363

Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows atta…

No fix yet
Fix from $2,300 2022-05-12
Booking Calendar HIGH 8.8
CVE-2022-1463

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and includ…

Fix: after 9.1
Fix from $1,950 2022-05-10
Thinkphp CRITICAL 9.8
CVE-2021-23592

The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver cla…

Fix: 6.0.12+
Fix from $2,300 2022-05-06
Orlansoft Erp CRITICAL 9.8
CVE-2020-23620

The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of us…

Mitigation only
Fix from $2,300 2022-05-02