Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Onedev CRITICAL 9.8
CVE-2021-21243EPSS 54%

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted da…

Fix: 4.0.3+
Fix from $2,300 2021-01-15
Airwave Glass CRITICAL 9.8
CVE-2020-24639EPSS 7%

There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airw…

Fix: 1.3.3+
Fix from $2,300 2021-01-15
Thinkadmin CRITICAL 9.8
CVE-2020-23653

An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/con…

Fix: after 6.0
Fix from $2,300 2021-01-13
Jenkins HIGH 8.0
CVE-2021-21604

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content …

Fix: after 2.274
Fix from $1,950 2021-01-13
Collaborator HIGH 8.8
CVE-2020-26118

In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vu…

Fix: after 13.3.13302
Fix from $1,950 2021-01-11
Dubbo CRITICAL 9.8
CVE-2020-11995EPSS 6%

A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H…

Fix: after 2.7.7
Fix from $2,300 2021-01-11
Debian Linux HIGH 8.1
CVE-2020-36183

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36179EPSS 21%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common…

Patch available
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36180EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Patch available
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36182EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36184EPSS 10%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Patch available
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36185EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36186EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36187EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36188EPSS 11%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36189

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36181EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Patch available
Fix from $1,950 2021-01-06
Insider Threat Management Server CRITICAL 9.8
CVE-2020-10655

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…

Fix: 7.9.1+
Fix from $2,300 2021-01-06
Insider Threat Management Server CRITICAL 9.8
CVE-2020-10656

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…

Fix: 7.9.1+
Fix from $2,300 2021-01-06
Insider Threat Management Server HIGH 7.2
CVE-2020-10657

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAler…

Fix: 7.9.1+
Fix from $1,950 2021-01-06
Insider Threat Management Server CRITICAL 9.8
CVE-2020-10658

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…

Fix: 7.9.1+
Fix from $2,300 2021-01-06
Insider Threat Management HIGH 8.8
CVE-2020-8884

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to e…

Fix: 7.4.2 / 7.5.3+
Fix from $1,950 2021-01-06
Sterling B2b Integrator HIGH 8.8
CVE-2019-4728

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute…

Fix: after 6.0.3.2
Fix from $1,950 2021-01-05
Nxlog HIGH 7.5
CVE-2020-35488EPSS 8%

The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a…

Fix: 3.0.2272+
Fix from $1,950 2021-01-05
Laminas Http CRITICAL 9.8
CVE-2021-3007EPSS 75%

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if t…

Fix: 2.14.2+
Fix from $2,300 2021-01-04
Newsletter HIGH 8.8
CVE-2020-35932

Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as s…

Fix: 6.8.2+
Fix from $1,950 2021-01-01
Post Grid HIGH 8.8
CVE-2020-35938

PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP…

Fix: 1.22.16 / 2.0.73+
Fix from $1,950 2021-01-01
Post Grid HIGH 8.8
CVE-2020-35939

PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrar…

Fix: 1.22.16 / 2.0.73+
Fix from $1,950 2021-01-01
Qdpm HIGH 8.8
CVE-2020-26165

qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php beca…

Fix: after 9.1
Fix from $1,950 2020-12-31
Nukeviet CRITICAL 9.8
CVE-2019-7725

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization forma…

Fix: 4.3.04+
Fix from $2,300 2020-12-31