Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux CRITICAL 9.8
CVE-2019-20330EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-01-03
Spring Framework CRITICAL 9.8
CVE-2016-1000027EPSS 32%

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data…

Fix: 6.0.0+
Fix from $2,300 2020-01-02
Debian Linux MEDIUM 6.5
CVE-2019-14466

The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per…

Patch available
Fix from $1,600 2019-12-31
Tinywall HIGH 7.8
CVE-2019-19470

Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affect…

Fix: 2.1.13+
Fix from $1,950 2019-12-30
C1 Cms HIGH 8.8
CVE-2019-18211

An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of …

Fix: after 6.6
Fix from $1,950 2019-12-23
Log4j CRITICAL 9.8
CVE-2019-17571EPSS 69%

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi…

Fix: 4.14.3+
Fix from $2,300 2019-12-20
Open Journal System HIGH 8.8
CVE-2019-19909

An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injectio…

Fix: 3.1.2-2+
Fix from $1,950 2019-12-19
Iphone Os CRITICAL 9.8
CVE-2019-8662EPSS 10%

This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able…

Fix: 5.3 / 10.14.6+
Fix from $2,300 2019-12-18
TYPO3 HIGH 8.8
CVE-2019-19849

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and…

Fix: 8.7.30 / 9.5.12+
Fix from $1,950 2019-12-17
Dv2eemvc CRITICAL 9.8
CVE-2019-18956EPSS 6%

Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2,…

Fix: 1.0.30 / 1.1.2+
Fix from $2,300 2019-12-17
Views Dynamic Field CRITICAL 9.8
CVE-2019-19826

The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.in…

Fix: after 6.x-1.4
Fix from $2,300 2019-12-16
Edeploy CRITICAL 9.8
CVE-2014-3699

eDeploy has RCE via cPickle deserialization of untrusted data

No fix yet
Fix from $2,300 2019-12-15
Phpfastcache CRITICAL 9.8
CVE-2019-16774

In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.

Fix: 5.0.13+
Fix from $2,300 2019-12-12
Sppa T3000 Application Server CRITICAL 9.8
CVE-2019-18316

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…

Mitigation only
Fix from $2,300 2019-12-12
Sppa T3000 Application Server CRITICAL 9.8
CVE-2019-18283EPSS 5%

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without au…

No fix yet
Fix from $2,300 2019-12-12
Debian Linux HIGH 8.1
CVE-2019-17358

Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An auth…

Fix: after 1.2.7
Fix from $1,950 2019-12-12
Matrix HIGH 7.5
CVE-2019-19373

An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where …

Fix: 5.5.0.3 / 5.5.1.8+
Fix from $1,950 2019-12-11
Ui For Asp.net Ajax CRITICAL 9.8
CVE-2019-18935 KEVEPSS 100%

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploi…

Fix: after 2020.1.114
Fix from $2,300 2019-12-11
Nolio CRITICAL 9.8
CVE-2019-19230

An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacke…

Patch available
Fix from $2,300 2019-12-09
Olingo CRITICAL 9.8
CVE-2019-17556

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being …

Fix: after 4.6.0
Fix from $2,300 2019-12-04
Emc Storage Monitoring And Reporting CRITICAL 10.0
CVE-2019-18580

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated…

Mitigation only
Fix from $2,300 2019-11-26
Rv016 Multi Wan Vpn Firmware HIGH 8.8
CVE-2019-15271 KEVEPSS 6%

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker…

Fix: 4.2.3.10+
Fix from $1,950 2019-11-26
Security Identity Manager HIGH 8.8
CVE-2019-4561

IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted…

Mitigation only
Fix from $1,950 2019-11-20
Exchange Server CRITICAL 9.8
CVE-2019-1373EPSS 18%

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Re…

Patch available
Fix from $2,300 2019-11-12
Magento HIGH 7.2
CVE-2019-8141

A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticate…

Fix: 2.1.19 / 2.2.10+
Fix from $1,950 2019-11-06
Authentication Service HIGH 7.8
CVE-2019-18631

The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and…

Patch available
Fix from $1,950 2019-11-05
Teamcity CRITICAL 9.8
CVE-2019-18364

In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

Fix: 2019.1.4+
Fix from $2,300 2019-10-31
Openafs HIGH 7.5
CVE-2019-18601

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series o…

Fix: 1.6.24 / 1.8.5+
Fix from $1,950 2019-10-29
Mapr CRITICAL 9.8
CVE-2019-12017

A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login a…

Fix: 5.2.2+
Fix from $2,300 2019-10-24
Mule Runtime CRITICAL 9.8
CVE-2019-13116EPSS 5%

The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, rela…

Fix: 3.8.0+
Fix from $2,300 2019-10-16