Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Jira Cloud HIGH 8.6
CVE-2021-21371

Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the …

Fix: 1.1.21+
Fix from $1,950 2021-03-10
Netweaver Knowledge Management MEDIUM 6.5
CVE-2021-21488

Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w…

Mitigation only
Fix from $1,600 2021-03-09
Qcubed CRITICAL 9.8
CVE-2020-24914EPSS 5%

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileDa…

Fix: after 3.1.1
Fix from $2,300 2021-03-04
Fork Cms HIGH 8.8
CVE-2020-24036

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

Fix: 5.8.3+
Fix from $1,950 2021-03-04
Wp Hotel Booking CRITICAL 9.8
CVE-2020-29047EPSS 16%

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the…

Fix: after 1.10.2
Fix from $2,300 2021-03-03
Tenable.sc HIGH 8.8
CVE-2021-20076

Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged u…

Fix: after 5.17.0
Fix from $1,950 2021-03-03
Exchange Server HIGH 7.8
CVE-2021-26857 KEVEPSS 96%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-03-03
Sharepoint Enterprise Server HIGH 8.8
CVE-2021-24066EPSS 6%

Microsoft SharePoint Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-02-25
Kollect CRITICAL 9.8
CVE-2021-27335

KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections…

Fix: 4.8.16c+
Fix from $2,300 2021-02-18
Hr Portal CRITICAL 9.8
CVE-2021-22855

The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized object…

Mitigation only
Fix from $2,300 2021-02-17
Qlib HIGH 7.2
CVE-2021-23338

This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

Patch available
Fix from $1,950 2021-02-15
Pystemon CRITICAL 9.8
CVE-2021-27213

config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.

Fix: 2021-02-13+
Fix from $2,300 2021-02-14
Ocularis CRITICAL 9.8
CVE-2020-27868EPSS 81%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not r…

Mitigation only
Fix from $2,300 2021-02-12
Netmotion Mobility HIGH 8.1
CVE-2021-26912EPSS 41%

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…

Fix: 11.73 / 12.02+
Fix from $1,950 2021-02-08
Netmotion Mobility HIGH 8.1
CVE-2021-26913EPSS 13%

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…

Fix: 11.73 / 12.02+
Fix from $1,950 2021-02-08
Netmotion Mobility HIGH 8.1
CVE-2021-26914EPSS 78%

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…

Fix: 11.73 / 12.02+
Fix from $1,950 2021-02-08
Netmotion Mobility HIGH 8.1
CVE-2021-26915EPSS 42%

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…

Fix: 11.73 / 12.02+
Fix from $1,950 2021-02-08
Orion Platform CRITICAL 9.8
CVE-2021-25274EPSS 36%

The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…

Fix: 2020.2.4+
Fix from $2,300 2021-02-03
Intellij Idea HIGH 7.8
CVE-2021-25758

In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.

Fix: 2020.3+
Fix from $1,950 2021-02-03
Assuweb CRITICAL 9.8
CVE-2021-3160

Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to i…

Mitigation only
Fix from $2,300 2021-01-28
Mq CRITICAL 9.8
CVE-2020-4682EPSS 8%

IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…

Patch available
Fix from $2,300 2021-01-28
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4888EPSS 62%

IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused b…

Patch available
Fix from $1,950 2021-01-28
Infosphere Information Server CRITICAL 9.8
CVE-2020-27583

IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec…

No fix yet
Fix from $2,300 2021-01-26
Java Chassis HIGH 8.8
CVE-2020-17532

When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The…

Fix: 2.1.5+
Fix from $1,950 2021-01-25
Rosemount Transmitter Interface Software HIGH 7.8
CVE-2020-12525

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data …

Fix: 3.5 / 4.5+
Fix from $1,950 2021-01-22
Active Iq Unified Manager HIGH 8.1
CVE-2021-20190EPSS 7%

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest thre…

Fix: 2.6.7.5 / 2.9.10.7+
Fix from $1,950 2021-01-19
Opencats CRITICAL 9.8
CVE-2021-25294EPSS 11%

OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php …

Fix: after 0.9.5-3
Fix from $2,300 2021-01-18
Onedev CRITICAL 9.8
CVE-2021-21242EPSS 74%

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exe…

Fix: 4.0.3+
Fix from $2,300 2021-01-15
Onedev HIGH 8.8
CVE-2021-21247

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj…

Fix: 4.0.3+
Fix from $1,950 2021-01-15
Onedev HIGH 8.8
CVE-2021-21249

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote …

Fix: 4.0.3+
Fix from $1,950 2021-01-15