Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Svi Ms Management System CRITICAL 9.8
CVE-2020-23621

The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserializ…

Mitigation only
Fix from $2,300 2022-05-02
Debian Linux HIGH 7.5
CVE-2022-25647EPSS 12%

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal clas…

Fix: 2.8.9+
Fix from $1,950 2022-05-01
Ureport2 CRITICAL 9.8
CVE-2022-25767

All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, caus…

No fix yet
Fix from $2,300 2022-05-01
Oracle Optimization HIGH 8.8
CVE-2022-29936

USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-f…

No fix yet
Fix from $1,950 2022-04-29
Misp CRITICAL 9.8
CVE-2022-29528

An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.

Fix: 2.4.158+
Fix from $2,300 2022-04-20
Bitbucket Data Center CRITICAL 9.8
CVE-2022-26133EPSS 70%

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 …

Fix: 7.6.14 / 7.17.6+
Fix from $2,300 2022-04-20
Application Development Framework CRITICAL 9.8
CVE-2022-21445 KEVEPSS 62%

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t…

Mitigation only
Fix from $2,300 2022-04-19
Pearweb CRITICAL 9.8
CVE-2022-27158

pearweb < 1.32 suffers from Deserialization of Untrusted Data.

Fix: 1.32.0+
Fix from $2,300 2022-04-15
Geowebcache HIGH 7.2
CVE-2022-24846

GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn ca…

Fix: 1.19.3 / 1.20.2+
Fix from $1,950 2022-04-14
Imunify360 HIGH 7.8
CVE-2021-21956

A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead…

No fix yet
Fix from $1,950 2022-04-14
Cloud Foundation HIGH 7.2
CVE-2022-22957EPSS 23%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13
Cloud Foundation HIGH 7.2
CVE-2022-22958

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13
Software Update HIGH 7.8
CVE-2019-6834

A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with…

Fix: after 2.3.0
Fix from $1,950 2022-04-13
Simatic Energy Manager Basic CRITICAL 9.8
CVE-2022-23450EPSS 36%

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 U…

Fix: 7.3+
Fix from $2,300 2022-04-12
Webex Meetings Online HIGH 8.8
CVE-2022-20763

A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java …

Mitigation only
Fix from $1,950 2022-04-06
Jeesite CRITICAL 9.8
CVE-2020-19229

Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an at…

No fix yet
Fix from $2,300 2022-04-05
Mashzone Nextgen CRITICAL 9.8
CVE-2021-33207

The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.

Fix: after 10.7
Fix from $2,300 2022-04-05
Crater HIGH 7.2
CVE-2022-1032

Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

Fix: 6.0.6+
Fix from $1,950 2022-03-29
Connected Components Workbench HIGH 8.6
CVE-2021-27475

Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows…

Fix: after 12.00.00
Fix from $1,950 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27460

Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without suf…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27462

A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27466

A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifi…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27470

A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s…

Fix: after 10.00
Fix from $2,300 2022-03-23
Veeam HIGH 7.8
CVE-2022-26503

Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local s…

Fix: 4.0.2.2208 / 5.0.3.4708+
Fix from $1,950 2022-03-17
Singoocms.utility CRITICAL 9.8
CVE-2022-0749

This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input afte…

No fix yet
Fix from $2,300 2022-03-17
Suitecrm HIGH 8.8
CVE-2022-23940EPSS 53%

SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achie…

Fix: 7.12.5 / 8.0.4+
Fix from $1,950 2022-03-10
Sinec Network Management System HIGH 7.2
CVE-2022-24282

A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions)…

Mitigation only
Fix from $1,950 2022-03-08
Incapptic Connect HIGH 7.2
CVE-2022-21828

A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified …

No fix yet
Fix from $1,950 2022-03-04
Mimosa Management Platform HIGH 7.5
CVE-2022-0138

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has …

Fix: 1.0.3 / 2.5.4.1+
Fix from $1,950 2022-02-18
Magnolia Cms HIGH 7.8
CVE-2021-46364

A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

Fix: 6.2.4+
Fix from $1,950 2022-02-11