Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Gradle HIGH 8.1
CVE-2021-41588

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…

Fix: 2021.1.3+
Fix from $1,950 2021-09-24
Halibut CRITICAL 9.8
CVE-2021-31819

In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each…

Fix: 4.4.7+
Fix from $2,300 2021-09-22
Mylittlebackup CRITICAL 9.8
CVE-2021-39392

The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the …

Fix: after 1.7
Fix from $2,300 2021-09-15
Cerberus Dms CRITICAL 10.0
CVE-2021-37181

A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus…

Patch available
Fix from $2,300 2021-09-14
Parlai HIGH 8.8
CVE-2021-39207

parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is v…

Fix: 1.1.0+
Fix from $1,950 2021-09-10
Parlai CRITICAL 9.8
CVE-2021-24040EPSS 17%

Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input,…

Fix: 1.1.0+
Fix from $2,300 2021-09-10
Dubbo CRITICAL 9.8
CVE-2021-37579EPSS 7%

The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…

Fix: 2.7.13 / 3.0.2+
Fix from $2,300 2021-09-09
Zstack HIGH 8.1
CVE-2021-32836

ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserializat…

Fix: 3.10.12 / 4.1.6+
Fix from $1,950 2021-09-09
Patch Manager HIGH 8.8
CVE-2021-35217EPSS 73%

Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and r…

Fix: after 2020.2.5
Fix from $1,950 2021-09-08
Dubbo CRITICAL 9.8
CVE-2021-36163

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…

Fix: after 3.0.1
Fix from $2,300 2021-09-07
Mrdoc HIGH 7.8
CVE-2021-32568

mrdoc is vulnerable to Deserialization of Untrusted Data

Fix: after 0.7.0
Fix from $1,950 2021-09-06
Orion Platform HIGH 8.8
CVE-2021-35215EPSS 70%

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit …

Fix: after 2020.2.5
Fix from $1,950 2021-09-01
Patch Manager HIGH 8.8
CVE-2021-35216EPSS 81%

Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An …

Fix: 2020.2.6+
Fix from $1,950 2021-09-01
Orion Platform HIGH 8.8
CVE-2021-35218EPSS 76%

Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network acces…

Fix: 2020.2.6+
Fix from $1,950 2021-09-01
Mik.starlight HIGH 8.8
CVE-2021-36231

Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating syste…

No fix yet
Fix from $1,950 2021-08-31
Code Coverage Api HIGH 8.8
CVE-2021-21677

Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from dis…

Fix: after 1.4.0
Fix from $1,950 2021-08-31
Verinice HIGH 8.8
CVE-2021-36981EPSS 6%

In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.

Fix: 1.22.2+
Fix from $1,950 2021-08-31
Rundeck HIGH 8.8
CVE-2021-39132

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an autho…

Fix: 3.3.14 / 3.4.3+
Fix from $1,950 2021-08-30
Developer Be CRITICAL 9.8
CVE-2021-34066

An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to exe…

Fix: 1.0+
Fix from $2,300 2021-08-30
Zxv10 M910 Firmware CRITICAL 9.8
CVE-2021-21741

There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit…

Mitigation only
Fix from $2,300 2021-08-30
Bold Page Builder HIGH 8.8
CVE-2021-24579EPSS 8%

The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any v…

Fix: 3.1.6+
Fix from $1,950 2021-08-30
Codesys HIGH 7.8
CVE-2021-21869

An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development …

Patch available
Fix from $1,950 2021-08-25
Ipados HIGH 7.5
CVE-2021-31010 KEV

A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and…

Fix: 7.6.2 / 10.15.7+
Fix from $1,950 2021-08-24
Fedora HIGH 8.5
CVE-2021-39152EPSS 11%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39150

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux MEDIUM 6.3
CVE-2021-39140EPSS 6%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca…

Fix: 1.4.18+
Fix from $1,600 2021-08-23
Fedora HIGH 8.5
CVE-2021-39153

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39154

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39141EPSS 16%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23