Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux CRITICAL 9.8
CVE-2019-17531EPSS 5%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-12
Active Iq Unified Manager CRITICAL 9.8
CVE-2019-17267

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactio…

Fix: 2.8.11.5 / 2.9.10+
Fix from $2,300 2019-10-07
Redis Wrapper CRITICAL 9.8
CVE-2019-17206

Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute…

Fix: 0.3.0+
Fix from $2,300 2019-10-05
Liferay Portal CRITICAL 9.8
CVE-2019-16891EPSS 46%

Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.

Fix: after 6.0.6
Fix from $2,300 2019-10-04
Security Manager CRITICAL 9.8
CVE-2019-12630EPSS 66%

A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitr…

Fix: 4.18+
Fix from $2,300 2019-10-02
Mintinstall HIGH 7.8
CVE-2019-17080EPSS 8%

mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpick…

No fix yet
Fix from $1,950 2019-10-02
Debian Linux CRITICAL 9.8
CVE-2019-16942EPSS 6%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Debian Linux CRITICAL 9.8
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2019-10202EPSS 5%

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…

Mitigation only
Fix from $2,300 2019-10-01
Android CRITICAL 9.8
CVE-2019-9365

In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional…

Mitigation only
Fix from $2,300 2019-09-27
Android MEDIUM 5.5
CVE-2019-9373

In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of servic…

Mitigation only
Fix from $1,600 2019-09-27
Myit Digital Workplace CRITICAL 9.8
CVE-2019-16755

BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-au…

Fix: 18.08.00+
Fix from $2,300 2019-09-26
Inoerp CRITICAL 9.8
CVE-2019-16894

download.php in inoERP 4.15 allows SQL injection through insecure deserialization.

No fix yet
Fix from $2,300 2019-09-26
Service Manager HIGH 8.8
CVE-2019-11666

Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51…

Fix: after 9.62
Fix from $1,950 2019-09-17
Tapestry CRITICAL 9.8
CVE-2019-0195EPSS 15%

Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou…

Fix: after 5.4.3
Fix from $2,300 2019-09-16
Fedora CRITICAL 9.8
CVE-2019-14540EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-09-15
Fedora CRITICAL 9.8
CVE-2019-16335

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-09-15
Pimcore HIGH 8.8
CVE-2019-16317

In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because…

Fix: 5.7.1+
Fix from $1,950 2019-09-14
Ofbiz CRITICAL 9.8
CVE-2019-0189EPSS 24%

The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and …

Fix: 16.11.06+
Fix from $2,300 2019-09-11
Gravitate Qa Tracker CRITICAL 9.8
CVE-2017-18605

The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.

Fix: after 1.2.1
Fix from $2,300 2019-09-10
Sitebuilder Dynamic Components HIGH 7.5
CVE-2017-18604

The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.

Fix: after 1.0
Fix from $1,950 2019-09-10
Alfresco HIGH 7.2
CVE-2019-14224EPSS 5%

An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit…

No fix yet
Fix from $1,950 2019-09-05
Efront Lms HIGH 8.8
CVE-2019-5069

A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially r…

Fix: after 5.2.12
Fix from $1,950 2019-09-05
Eventum CRITICAL 9.8
CVE-2018-11569

Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.

Fix: 3.5.2+
Fix from $2,300 2019-09-05
Formidable Form Builder CRITICAL 9.8
CVE-2019-15780

The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

Fix: 4.02.01+
Fix from $2,300 2019-08-29
Spoon Library CRITICAL 9.8
CVE-2019-15521

Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.

Fix: 1.4.1+
Fix from $2,300 2019-08-26
Newsletters CRITICAL 9.8
CVE-2018-20987

The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.

Fix: 4.6.8.6+
Fix from $2,300 2019-08-22
Mirasys Vms CRITICAL 9.8
CVE-2019-11030

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in S…

Fix: 7.6.1 / 8.3.2+
Fix from $2,300 2019-08-22
Optiontree CRITICAL 9.8
CVE-2019-15319

The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.

Fix: 2.7.0+
Fix from $2,300 2019-08-22
Optiontree CRITICAL 9.8
CVE-2019-15320

The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.

Fix: 2.7.3+
Fix from $2,300 2019-08-22