Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Source Code Management Filter Jervis HIGH 8.8
CVE-2020-2189

Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a…

Fix: after 0.2.1
Fix from $1,950 2020-05-06
Subrion MEDIUM 6.5
CVE-2020-12469

admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value wi…

Fix: after 4.2.1
Fix from $1,600 2020-04-29
Monox CRITICAL 9.8
CVE-2020-12471

MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserial…

Fix: after 5.1.40.5152
Fix from $2,300 2020-04-29
Electric Consciousmap CRITICAL 9.8
CVE-2020-12133EPSS 10%

The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java d…

Fix: after 2.8.1
Fix from $2,300 2020-04-27
One CRITICAL 9.8
CVE-2020-10915EPSS 87%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r…

No fix yet
Fix from $2,300 2020-04-22
One CRITICAL 9.8
CVE-2020-10914EPSS 47%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r…

No fix yet
Fix from $2,300 2020-04-22
Android HIGH 7.8
CVE-2020-0082

In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead …

Mitigation only
Fix from $1,950 2020-04-17
Heron CRITICAL 9.8
CVE-2020-1964

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …

Mitigation only
Fix from $2,300 2020-04-16
Yaml Axis HIGH 8.8
CVE-2020-2179

Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote …

Fix: after 0.2.0
Fix from $1,950 2020-04-16
Amazon Web Services Serverless Application Model HIGH 8.8
CVE-2020-2180

Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co…

Fix: after 1.2.2
Fix from $1,950 2020-04-16
Qradar Security Information And Event Manager MEDIUM 6.3
CVE-2020-4271

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged…

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Qradar Security Information And Event Manager HIGH 8.8
CVE-2020-4272

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request …

Fix: 7.3.3+
Fix from $1,950 2020-04-15
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2020-6219

SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allo…

Mitigation only
Fix from $1,950 2020-04-14
Ejbca CRITICAL 9.8
CVE-2020-11630

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent bet…

Fix: 6.15.2.6 / 7.3.1.2+
Fix from $2,300 2020-04-08
Debian Linux HIGH 8.1
CVE-2020-11619

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.ao…

Fix: 2.9.10.4+
Fix from $1,950 2020-04-07
Debian Linux HIGH 8.1
CVE-2020-11620EPSS 6%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jel…

Fix: 2.9.10.4+
Fix from $1,950 2020-04-07
Dubbo CRITICAL 9.8
CVE-2019-17564EPSS 37%

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in…

Fix: after 2.7.4
Fix from $2,300 2020-04-01
Deskpro HIGH 7.2
CVE-2020-11467

An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style…

Fix: 2019.8.0+
Fix from $1,950 2020-04-01
Js Bson MEDIUM 5.4
CVE-2019-2391

Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour includi…

Fix: 1.1.4+
Fix from $1,600 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11111

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* …

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11112

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11113EPSS 6%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Bson CRITICAL 9.8
CVE-2020-7610

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsot…

Fix: 1.1.4+
Fix from $2,300 2020-03-30
Debian Linux HIGH 8.8
CVE-2020-10969

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPan…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $1,950 2020-03-26
Debian Linux HIGH 8.8
CVE-2020-10968

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.pro…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-26
Factorytalk Services Platform CRITICAL 9.8
CVE-2020-6967EPSS 5%

In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics ex…

Mitigation only
Fix from $2,300 2020-03-23
Liferay Portal CRITICAL 9.8
CVE-2020-7961 KEVEPSS 100%

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JS…

Fix: 7.2.1+
Fix from $2,300 2020-03-20
Debian Linux HIGH 8.8
CVE-2020-10672

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.trans…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-18
Debian Linux HIGH 8.8
CVE-2020-10673EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.type…

Fix: 2.6.7.4 / 2.9.10.4+
Fix from $1,950 2020-03-18
Pydio HIGH 8.8
CVE-2019-20452

A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/s…

Fix: 8.2.4+
Fix from $1,950 2020-03-17