Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux HIGH 8.1
CVE-2020-35728EPSS 13%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2020-12-27
Debian Linux HIGH 8.1
CVE-2020-35490EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Fix: 2.9.10.8+
Fix from $1,950 2020-12-17
Debian Linux HIGH 8.1
CVE-2020-35491EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Fix: 2.9.10.8+
Fix from $1,950 2020-12-17
Jsonpickle CRITICAL 9.8
CVE-2020-22083EPSS 6%

jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been …

Fix: after 1.4.1
Fix from $2,300 2020-12-17
Lean CRITICAL 9.8
CVE-2020-20136

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNam…

Fix: after 2.4.0.1
Fix from $2,300 2020-12-14
Spinnaker HIGH 8.8
CVE-2020-9301

Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. T…

Fix: 1.21.5 / 1.22.4+
Fix from $1,950 2020-12-11
Exchange Server HIGH 8.4
CVE-2020-17144 KEVEPSS 37%

Microsoft Exchange Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2020-12-10
Tapestry CRITICAL 9.8
CVE-2020-17531EPSS 10%

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok…

Fix: 5.0.1+
Fix from $2,300 2020-12-08
Archive Tar HIGH 7.8
CVE-2020-28948EPSS 47%

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

Fix: 1.4.11 / 7.75+
Fix from $1,950 2020-11-19
Security Manager CRITICAL 9.8
CVE-2020-27131EPSS 88%

Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker …

Fix: after 4.22
Fix from $2,300 2020-11-17
Xoonips CRITICAL 9.8
CVE-2020-5664

Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 3.49
Fix from $2,300 2020-11-16
Welcart E Commerce HIGH 8.8
CVE-2020-28339

The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not …

Fix: 1.9.36+
Fix from $1,950 2020-11-07
Dbschemareader HIGH 8.0
CVE-2020-26207

DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschem…

Fix: 2.7.4.3+
Fix from $1,950 2020-11-04
WordPress CRITICAL 9.8
CVE-2020-28032EPSS 16%

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

Fix: 5.5.2+
Fix from $2,300 2020-11-02
Fabric8 Maven HIGH 7.8
CVE-2020-10721

A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur…

Fix: after 4.4.1
Fix from $1,950 2020-10-22
Magento HIGH 7.2
CVE-2020-15244

In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to…

Fix: 20.0.4+
Fix from $1,950 2020-10-21
Intelligent Management Center CRITICAL 9.8
CVE-2020-24648EPSS 11%

A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Cente…

Fix: 7.3+
Fix from $2,300 2020-10-19
Update HIGH 7.8
CVE-2020-7811

Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine …

Fix: after 3.0.32.0
Fix from $1,950 2020-10-12
Pcvue CRITICAL 9.8
CVE-2020-26867

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely e…

Fix: 12.0.17+
Fix from $2,300 2020-10-12
Mybatis HIGH 8.1
CVE-2020-26945

MyBatis before 3.5.6 mishandles deserialization of object streams.

Fix: 3.5.6+
Fix from $1,950 2020-10-10
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4280EPSS 73%

IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-sup…

Fix: after 7.4.1
Fix from $1,950 2020-10-08
Ozeki Ng Sms Gateway HIGH 7.2
CVE-2020-14030

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (an…

Fix: after 4.17.6
Fix from $1,950 2020-09-30
Soy Cms CRITICAL 9.8
CVE-2020-15188EPSS 5%

SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code w…

Fix: 3.0.2.328+
Fix from $2,300 2020-09-18
Debian Linux HIGH 8.1
CVE-2020-24750EPSS 7%

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcompon…

Fix: 2.6.7.5 / 2.9.10.6+
Fix from $1,950 2020-09-17
Scadapack 7x Remote Connect HIGH 7.8
CVE-2020-7528

A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary co…

Fix: after 3.6.3.574
Fix from $1,950 2020-09-16
Scadapack X70 Security Administrator HIGH 7.8
CVE-2020-7532

A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitra…

Fix: after 1.2.0
Fix from $1,950 2020-09-16
Fluffycogs HIGH 8.8
CVE-2020-15172

The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Discord users can use specially …

Fix: 2.0.38+
Fix from $1,950 2020-09-15
Yii CRITICAL 10.0
CVE-2020-15148EPSS 79%

Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. T…

Fix: 2.0.38+
Fix from $2,300 2020-09-15
Maximo Asset Management HIGH 8.8
CVE-2020-4521EPSS 6%

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe …

Fix: 7.6.0.10 / 7.6.1.2+
Fix from $1,950 2020-09-15
Nippy HIGH 7.8
CVE-2020-24164

A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payloa…

Fix: 2.14.2+
Fix from $1,950 2020-09-11