Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux HIGH 8.5
CVE-2021-39145

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39146EPSS 14%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39147

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39148

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39149

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39151

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.8
CVE-2021-39139

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Codesys HIGH 7.8
CVE-2021-21867

An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Develo…

Patch available
Fix from $1,950 2021-08-18
Codesys HIGH 7.8
CVE-2021-21868

An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Developme…

Patch available
Fix from $1,950 2021-08-18
Tensorflow HIGH 8.8
CVE-2021-37678

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary …

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Cpanel HIGH 7.2
CVE-2021-38585

The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).

Fix: 98.0.1+
Fix from $1,950 2021-08-11
Codeception CRITICAL 9.8
CVE-2021-23420

This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run…

Fix: 3.1.3 / 4.1.22+
Fix from $2,300 2021-08-11
Teamcity CRITICAL 9.8
CVE-2021-37544

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

Fix: 2020.2.4+
Fix from $2,300 2021-08-06
Config Lib HIGH 8.1
CVE-2021-37632

SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn642's Config Lib between 1.0.4…

Fix: 1.0.9+
Fix from $1,950 2021-08-05
Neo4j CRITICAL 9.8
CVE-2021-34371EPSS 13%

Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVaria…

Fix: after 3.4.18
Fix from $2,300 2021-08-05
Development System HIGH 7.8
CVE-2021-21863

A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.1…

Patch available
Fix from $1,950 2021-08-05
Devexpress HIGH 8.8
CVE-2021-36483

DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

Fix: after 21.1
Fix from $1,950 2021-08-04
Development System HIGH 7.8
CVE-2021-21866

A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Develo…

Patch available
Fix from $1,950 2021-08-02
Development System HIGH 7.8
CVE-2021-21864

A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Dev…

Patch available
Fix from $1,950 2021-08-02
Development System HIGH 7.8
CVE-2021-21865

A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Developm…

Patch available
Fix from $1,950 2021-08-02
Concrete Cms HIGH 7.2
CVE-2021-36766

Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/l…

Fix: 8.5.6+
Fix from $1,950 2021-07-30
Partner Engagement Manager CRITICAL 9.8
CVE-2021-29781

IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. B…

Patch available
Fix from $2,300 2021-07-30
Juddi CRITICAL 9.8
CVE-2021-37578

Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo…

Fix: 3.3.10+
Fix from $2,300 2021-07-29
Emc Avamar Server CRITICAL 9.8
CVE-2020-5341

Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data…

Patch available
Fix from $2,300 2021-07-28
Access Management CRITICAL 9.8
CVE-2021-35464 KEVEPSS 100%

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does no…

Fix: 6.5.4 / 14.6.3+
Fix from $2,300 2021-07-22
Sosafe Configurable HIGH 7.8
CVE-2021-22777

A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.

Fix: 1.8.1+
Fix from $1,950 2021-07-21
Sharepoint Foundation HIGH 8.1
CVE-2021-34520

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-07-14
Vapor CRITICAL 9.1
CVE-2021-32742

Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing…

Fix: 4.47.2+
Fix from $2,300 2021-07-09
Clearpass Policy Manager HIGH 7.2
CVE-2021-29150

A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba …

Fix: 6.8.9 / 6.9.6+
Fix from $1,950 2021-07-08
Joomsport CRITICAL 9.8
CVE-2021-24384

The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unse…

Fix: 5.1.8+
Fix from $2,300 2021-07-06