Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Requests CRITICAL 9.8
CVE-2021-29476

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests…

Patch available
Fix from $2,300 2021-04-27
Ofbiz CRITICAL 9.8
CVE-2021-29200EPSS 55%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Ofbiz CRITICAL 9.8
CVE-2021-30128EPSS 81%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Metasploit HIGH 8.8
CVE-2020-7385

By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that…

Fix: 4.19.0+
Fix from $1,950 2021-04-23
Orion Platform HIGH 7.8
CVE-2021-27277

This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2.…

Mitigation only
Fix from $1,950 2021-04-22
Manageengine Opmanager CRITICAL 9.8
CVE-2021-3287EPSS 51%

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

Fix: 12.5+
Fix from $2,300 2021-04-22
Magento CRITICAL 9.8
CVE-2021-21426

Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, the…

Fix: 19.4.13 / 20.0.9+
Fix from $2,300 2021-04-21
Bridgecrew Checkov HIGH 7.2
CVE-2021-3035

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform f…

Fix: 2.0.26+
Fix from $1,950 2021-04-20
Tapestry CRITICAL 9.8
CVE-2021-27850EPSS 94%

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…

Fix: 5.6.2 / 5.7.1+
Fix from $2,300 2021-04-15
Ajaxsearchpro HIGH 7.2
CVE-2021-29654

AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote …

Fix: 4.20.8+
Fix from $1,950 2021-04-14
Storage Monitoring And Reporting CRITICAL 9.8
CVE-2021-21524

Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticate…

Fix: 4.5.0.1+
Fix from $2,300 2021-04-12
Facebook HIGH 8.1
CVE-2021-24217

The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be su…

Fix: 3.0.0+
Fix from $1,950 2021-04-12
Rv340 Firmware MEDIUM 6.3
CVE-2021-1413

Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an …

Fix: 1.0.0.3.21 / 1.0.03.21+
Fix from $1,600 2021-04-08
Rv340 Firmware MEDIUM 6.3
CVE-2021-1414

Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an …

Fix: 1.0.03.21+
Fix from $1,600 2021-04-08
Rv340 Firmware MEDIUM 6.3
CVE-2021-1415

Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an …

Fix: 1.0.03.21+
Fix from $1,600 2021-04-08
Patch Manager HIGH 7.8
CVE-2021-27240

This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must fir…

Mitigation only
Fix from $1,950 2021-03-29
Activemq CRITICAL 9.8
CVE-2021-21347EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq HIGH 7.5
CVE-2021-21348EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq HIGH 8.6
CVE-2021-21349EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21350EPSS 15%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21351EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq HIGH 7.5
CVE-2021-21341EPSS 78%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21342EPSS 50%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq HIGH 7.5
CVE-2021-21343EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed …

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21344EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21346EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Ofbiz CRITICAL 9.8
CVE-2021-26295EPSS 98%

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OF…

Fix: 17.12.06+
Fix from $2,300 2021-03-22
Jms Client CRITICAL 9.8
CVE-2020-36282

JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted …

Fix: 1.15.2 / 2.2.0+
Fix from $2,300 2021-03-12
Five Star Restaurant Menu CRITICAL 9.8
CVE-2020-29045EPSS 31%

The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on t…

Fix: after 2.2.0
Fix from $2,300 2021-03-11