Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Veeam Backup \& Replication CRITICAL 9.8
CVE-2021-35971

Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remo…

Fix: 10.0.1.4854 / 11.0.0.837+
Fix from $2,300 2021-06-30
Anyoffice HIGH 8.1
CVE-2021-22439

There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability.…

Mitigation only
Fix from $1,950 2021-06-29
Ratpack HIGH 8.8
CVE-2021-29485

Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a ma…

Fix: 1.9.0+
Fix from $1,950 2021-06-29
Jfinal CRITICAL 9.8
CVE-2021-31649

In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute

Fix: after 4.9.08
Fix from $2,300 2021-06-24
Jetson Linux MEDIUM 6.7
CVE-2021-34394

Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker…

Fix: 32.5.1+
Fix from $1,600 2021-06-22
Manuskript HIGH 7.8
CVE-2021-35196

Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is in…

Fix: after 0.12.0
Fix from $1,950 2021-06-21
Chainsaw CRITICAL 9.8
CVE-2020-9493

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

Fix: 1.2.18.1 / 2.0+
Fix from $2,300 2021-06-16
Bridgecrew Checkov HIGH 7.2
CVE-2021-3040

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform f…

Fix: 2.0.139+
Fix from $1,950 2021-06-10
Emq X Broker HIGH 7.5
CVE-2021-33175

EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of …

Fix: 4.2.8+
Fix from $1,950 2021-06-08
Vernemq HIGH 7.5
CVE-2021-33176

VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the hand…

Fix: 1.12.0+
Fix from $1,950 2021-06-08
Invoice Ninja HIGH 8.1
CVE-2021-33898

In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to…

Fix: 4.4.0+
Fix from $1,950 2021-06-06
Bdlib CRITICAL 9.8
CVE-2021-33806

The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObj…

Fix: 1.16.1.7+
Fix from $2,300 2021-06-03
Database Security HIGH 8.0
CVE-2021-23895

Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a…

Fix: 4.8.2+
Fix from $1,950 2021-06-02
Database Security HIGH 8.8
CVE-2021-23894

Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create…

Fix: 4.8.2+
Fix from $1,950 2021-06-02
Dubbo CRITICAL 9.8
CVE-2021-25641EPSS 21%

Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before…

Fix: 2.6.9 / 2.7.8+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30179

Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha…

Fix: 2.6.9 / 2.7.10+
Fix from $2,300 2021-06-01
Reborncore CRITICAL 9.8
CVE-2021-33790

The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of re…

Fix: 3.19.5 / 4.2.10+
Fix from $2,300 2021-05-31
Debian Linux HIGH 8.8
CVE-2021-29505EPSS 77%

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack…

Fix: 1.4.17+
Fix from $1,950 2021-05-28
Survey CRITICAL 9.8
CVE-2021-27852 KEVEPSS 32%

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary …

Fix: 7.0+
Fix from $2,300 2021-05-27
Terraria CRITICAL 9.8
CVE-2021-32075

Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.

Fix: 1.4.2.3+
Fix from $2,300 2021-05-24
All In One Seo HIGH 8.8
CVE-2021-24307EPSS 53%

The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_setti…

Fix: 4.1.0.2+
Fix from $1,950 2021-05-24
Emissary HIGH 7.2
CVE-2021-32634

Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated…

Patch available
Fix from $1,950 2021-05-21
Network Performance Monitor CRITICAL 9.8
CVE-2021-31474EPSS 94%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Au…

Fix: 2020.2.5+
Fix from $2,300 2021-05-21
Redirection For Contact Form 7 HIGH 8.8
CVE-2021-24280

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJ…

Fix: 2.3.4+
Fix from $1,950 2021-05-14
Flask Caching CRITICAL 9.8
CVE-2021-33026EPSS 7%

The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege e…

Fix: after 1.10.1
Fix from $2,300 2021-05-13
Wire CRITICAL 9.1
CVE-2021-29508

Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on t…

No fix yet
Fix from $2,300 2021-05-11
Pandora Fms CRITICAL 9.8
CVE-2021-32098

Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

No fix yet
Fix from $2,300 2021-05-07
Airwave HIGH 7.2
CVE-2021-25152

A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released …

Fix: 8.2.12.1+
Fix from $1,950 2021-04-28
Airwave HIGH 8.8
CVE-2021-25151EPSS 12%

A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released …

Fix: 8.2.12.1+
Fix from $1,950 2021-04-28
WordPress CRITICAL 9.8
CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV…

Fix: 3.7.36 / 3.8.36+
Fix from $2,300 2021-04-28