Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Cayenne HIGH 8.8
CVE-2022-24289

Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur…

Fix: 4.2+
Fix from $1,950 2022-02-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2022-22005EPSS 17%

Microsoft SharePoint Server Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2022-02-09
Jenkins HIGH 7.5
CVE-2022-0538

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vuln…

Fix: 2.319.3 / 2.334+
Fix from $1,950 2022-02-09
Virtual Appliance HIGH 8.1
CVE-2021-42631EPSS 6%

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

Fix: 19.1.1.13+
Fix from $1,950 2022-01-31
Suitecrm CRITICAL 9.8
CVE-2021-45899

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.

Fix: 7.12.3 / 8.0.2+
Fix from $2,300 2022-01-28
Karaf HIGH 8.1
CVE-2021-41766

Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…

Fix: 4.3.6+
Fix from $1,950 2022-01-26
Debian Linux MEDIUM 5.3
CVE-2022-21341

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Log4j HIGH 8.8
CVE-2022-23302EPSS 64%

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration…

Fix: 1.2.18.1+
Fix from $1,950 2022-01-18
Chainsaw HIGH 8.8
CVE-2022-23307EPSS 54%

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j…

Fix: 1.2.18.1 / 2.0+
Fix from $1,950 2022-01-18
Html2pdf HIGH 8.8
CVE-2021-45394

An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <lin…

Fix: 5.2.4+
Fix from $1,950 2022-01-18
Dubbo CRITICAL 9.8
CVE-2021-43297EPSS 17%

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…

Fix: 2.6.12 / 2.7.15+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2021-42392EPSS 63%

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack…

Fix: after 2.0.204
Fix from $2,300 2022-01-10
WordPress HIGH 7.2
CVE-2022-21663

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm…

Fix: 5.8.3+
Fix from $1,950 2022-01-06
Codeigniter CRITICAL 9.8
CVE-2022-21647EPSS 38%

CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remo…

Fix: 4.1.6+
Fix from $2,300 2022-01-04
Jboss Enterprise Application Platform HIGH 7.2
CVE-2021-20318

The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary …

Mitigation only
Fix from $1,950 2021-12-23
Pytorch Lightning HIGH 7.8
CVE-2021-4118

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

Fix: 1.6.0+
Fix from $1,950 2021-12-23
Ajax.net Professional MEDIUM 5.4
CVE-2021-43853

Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript …

Fix: 21.12.22.1+
Fix from $1,600 2021-12-22
Kace Desktop Authority CRITICAL 9.8
CVE-2021-44029

An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserializa…

Fix: 11.2+
Fix from $2,300 2021-12-22
Wyse Management Suite CRITICAL 9.8
CVE-2021-36336

Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code o…

Fix: after 3.3.1
Fix from $2,300 2021-12-21
Satellite MEDIUM 6.6
CVE-2021-42550

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat…

Fix: 1.0.3+
Fix from $1,600 2021-12-16
Android HIGH 7.8
CVE-2021-0970

In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalat…

Patch available
Fix from $1,950 2021-12-15
Log4j HIGH 7.5
CVE-2021-4104EPSS 81%

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack…

Patch available
Fix from $1,950 2021-12-14
Totop Link CRITICAL 9.8
CVE-2021-24857

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object inje…

Fix: after 1.7.1
Fix from $2,300 2021-12-13
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Avalanche HIGH 8.8
CVE-2021-42125EPSS 82%

An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dan…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche CRITICAL 9.8
CVE-2021-42127EPSS 66%

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via …

Fix: 6.3.3+
Fix from $2,300 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42130EPSS 62%

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to p…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Enterprise Vault CRITICAL 9.8
CVE-2021-44680

An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…

Fix: after 14.1.2
Fix from $2,300 2021-12-06
Enterprise Vault CRITICAL 9.8
CVE-2021-44681

An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…

Fix: after 14.1.2
Fix from $2,300 2021-12-06
Enterprise Vault CRITICAL 9.8
CVE-2021-44682

An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…

Fix: after 14.1.2
Fix from $2,300 2021-12-06