Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Onbase CRITICAL 9.8
CVE-2020-25258

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …

Fix: after 20.3.10.1000
Fix from $2,300 2020-09-11
Onbase CRITICAL 9.8
CVE-2020-25259

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …

Fix: after 20.3.10.1000
Fix from $2,300 2020-09-11
Onbase CRITICAL 9.8
CVE-2020-25260

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …

Fix: after 20.3.10.1000
Fix from $2,300 2020-09-11
Symphony HIGH 8.8
CVE-2020-17405

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication …

Mitigation only
Fix from $1,950 2020-09-01
F\@st 5280 Router Firmware HIGH 8.8
CVE-2020-24034

Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege es…

No fix yet
Fix from $1,950 2020-09-01
Maven HIGH 7.8
CVE-2020-15777

An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Jav…

Fix: 1.6+
Fix from $1,950 2020-08-25
Active Iq Unified Manager HIGH 8.1
CVE-2020-24616EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An…

Fix: 2.9.10.6+
Fix from $1,950 2020-08-25
Robot Operating System HIGH 8.8
CVE-2020-10289

Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whene…

Patch available
Fix from $1,950 2020-08-20
Websphere Application Server CRITICAL 9.8
CVE-2020-4589EPSS 8%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafte…

Fix: after 9.0.5.4
Fix from $2,300 2020-08-13
Spring Integration CRITICAL 9.8
CVE-2020-5413

Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default o…

Fix: after 19.0
Fix from $2,300 2020-07-31
Gemfire CRITICAL 9.1
CVE-2019-11286

VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2…

Fix: 1.8.2 / 1.9.2+
Fix from $2,300 2020-07-31
Mediace CRITICAL 9.8
CVE-2020-15086

In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification…

Fix: 7.6.5+
Fix from $2,300 2020-07-29
TYPO3 HIGH 8.8
CVE-2020-15098

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th…

Fix: 9.5.20 / 10.4.6+
Fix from $1,950 2020-07-29
Esmpro Manager CRITICAL 9.8
CVE-2020-10917EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not requ…

Mitigation only
Fix from $2,300 2020-07-22
Digital Experience Platform HIGH 8.1
CVE-2020-15842

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle atta…

Fix: 7.3.0+
Fix from $1,950 2020-07-20
Websphere Application Server HIGH 8.8
CVE-2020-4464EPSS 13%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specia…

Fix: after 9.0.5.4
Fix from $1,950 2020-07-17
Airflow CRITICAL 9.8
CVE-2020-11982EPSS 7%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) …

Fix: after 1.10.10
Fix from $2,300 2020-07-17
Mc Works CRITICAL 9.8
CVE-2020-12007

A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a de…

Fix: after 10.95.208.31
Fix from $2,300 2020-07-16
Mc Works HIGH 7.5
CVE-2020-12015

A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This…

Fix: after 10.95.208.31
Fix from $1,950 2020-07-16
Mc Works HIGH 7.5
CVE-2020-12009

A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability…

Fix: after 10.95.208.31
Fix from $1,950 2020-07-16
Scratch Vm CRITICAL 9.8
CVE-2020-14000

MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certa…

Fix: 0.2.0-prerelease.20200714185213+
Fix from $2,300 2020-07-16
Ofbiz MEDIUM 6.1
CVE-2020-9496EPSS 99%

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

No fix yet
Fix from $1,600 2020-07-15
Sharepoint Enterprise Server HIGH 8.8
CVE-2020-1439EPSS 20%

A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of…

Patch available
Fix from $1,950 2020-07-14
Dubbo CRITICAL 9.8
CVE-2020-1948EPSS 16%

This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met…

Fix: after 2.7.6
Fix from $2,300 2020-07-14
Infosphere Information Server HIGH 8.8
CVE-2020-4305

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deseriali…

Fix: after 11.7.1.1
Fix from $1,950 2020-07-09
Jira CRITICAL 9.8
CVE-2020-14172

This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. Th…

Fix: 7.13.0 / 8.5.0+
Fix from $2,300 2020-07-03
Kubernetes Ci HIGH 8.8
CVE-2020-2211

Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types…

Fix: after 1.3
Fix from $1,950 2020-07-02
Beaker MEDIUM 6.8
CVE-2013-7489

The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.

Fix: after 1.11.0
Fix from $1,600 2020-06-26
Wildfly HIGH 7.5
CVE-2020-10740

A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application…

Fix: 20.0.0+
Fix from $1,950 2020-06-22
Tendenci CRITICAL 9.8
CVE-2020-14942

Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py.

Mitigation only
Fix from $2,300 2020-06-21