Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Pydio HIGH 8.8
CVE-2019-20453

A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http…

Fix: 8.2.4+
Fix from $1,950 2020-03-17
Shardingsphere CRITICAL 9.8
CVE-2020-1947EPSS 34%

In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …

Mitigation only
Fix from $2,300 2020-03-11
Storage Essentials CRITICAL 9.8
CVE-2017-10992EPSS 10%

In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker…

No fix yet
Fix from $2,300 2020-03-10
Markvision Enterprise HIGH 8.8
CVE-2016-1487

Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deseriali…

Fix: 2.3.0+
Fix from $1,950 2020-03-09
Literate HIGH 8.8
CVE-2020-2158

Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod…

Fix: after 1.0
Fix from $1,950 2020-03-09
Security Management Server CRITICAL 9.8
CVE-2020-5327

Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is expo…

Fix: 10.2.10+
Fix from $2,300 2020-03-06
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-10189 KEVEPSS 100%

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the F…

Fix: 10.0.479+
Fix from $2,300 2020-03-06
Jackson Databind CRITICAL 9.8
CVE-2019-14893

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of ma…

Fix: 2.8.11.5 / 2.9.10+
Fix from $2,300 2020-03-02
Decision Manager CRITICAL 9.8
CVE-2019-14892EPSS 6%

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2020-03-02
Active Iq Unified Manager CRITICAL 9.8
CVE-2020-9547EPSS 18%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engi…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $2,300 2020-03-02
Active Iq Unified Manager CRITICAL 9.8
CVE-2020-9548EPSS 18%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $2,300 2020-03-02
Active Iq Unified Manager CRITICAL 9.8
CVE-2020-9546

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shad…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $2,300 2020-03-02
Airwave HIGH 7.2
CVE-2019-5326

An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP pla…

Fix: 8.2.10.1+
Fix from $1,950 2020-02-27
Jyaml CRITICAL 9.8
CVE-2020-8441

JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinue…

Fix: after 1.3
Fix from $2,300 2020-02-19
Fedora CRITICAL 9.8
CVE-2019-20477EPSS 5%

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a …

Fix: after 5.1.2
Fix from $2,300 2020-02-19
Popup Builder CRITICAL 9.8
CVE-2020-9006EPSS 9%

The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via…

Fix: after 2.6.7.6
Fix from $2,300 2020-02-17
Suitecrm HIGH 7.2
CVE-2020-8801

SuiteCRM through 7.11.11 allows PHAR Deserialization.

Fix: after 7.11.11
Fix from $1,950 2020-02-13
Radargun HIGH 8.8
CVE-2020-2123

Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod…

Fix: after 1.7
Fix from $1,950 2020-02-12
Sql Server HIGH 8.8
CVE-2020-0618 KEVEPSS 99%

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL…

Patch available
Fix from $1,950 2020-02-11
Debian Linux CRITICAL 9.8
CVE-2020-8840EPSS 27%

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC…

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-02-10
Bosch Video Management System Mobile Video Service CRITICAL 9.8
CVE-2020-6770

Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on …

Fix: after 10.0.0.1225
Fix from $2,300 2020-02-07
Nuxeo CRITICAL 9.8
CVE-2013-4521

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods c…

Patch available
Fix from $2,300 2020-02-06
Magento CRITICAL 9.8
CVE-2020-3716EPSS 14%

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulner…

Fix: after 2.3.3
Fix from $2,300 2020-01-29
Xml Rpc CRITICAL 9.8
CVE-2019-17570EPSS 49%

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar…

Patch available
Fix from $2,300 2020-01-23
Maxpro Nvr Xe Firmware CRITICAL 9.8
CVE-2020-6959

The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Buil…

Fix: after 5.6
Fix from $2,300 2020-01-22
Memory Analyzer HIGH 7.8
CVE-2019-17635

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by…

Fix: after 1.9.1
Fix from $1,950 2020-01-17
Enterprise Linux HIGH 8.1
CVE-2020-2604

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE…

Fix: after 13.0.1
Fix from $1,950 2020-01-15
Access Manager CRITICAL 9.8
CVE-2020-2555 KEVEPSS 97%

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are aff…

Fix: after 11.3.2
Fix from $2,300 2020-01-15
Jamf CRITICAL 9.8
CVE-2019-17076

An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial…

Fix: after 10.15.0
Fix from $2,300 2020-01-08
Contao Cms CRITICAL 9.8
CVE-2014-1860

Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

Fix: after 3.2.4
Fix from $2,300 2020-01-08