Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Optiontree CRITICAL 9.8
CVE-2019-15321

The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.

Fix: 2.7.3+
Fix from $2,300 2019-08-22
Patreon Wordpress CRITICAL 9.8
CVE-2018-20984

The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.

Fix: 1.2.2+
Fix from $2,300 2019-08-22
Commons Beanutils HIGH 7.3
CVE-2019-10086EPSS 30%

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the clas…

Fix: after 1.9.3
Fix from $1,950 2019-08-20
Commerce Cloud CRITICAL 9.8
CVE-2019-0344 KEVEPSS 7%

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex…

Mitigation only
Fix from $2,300 2019-08-14
Debian Linux HIGH 7.5
CVE-2019-14439EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either global…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,950 2019-07-30
Storm CRITICAL 9.8
CVE-2018-11779

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…

Fix: after 1.2.2
Fix from $2,300 2019-07-26
Xstream CRITICAL 9.8
CVE-2019-10173EPSS 95%

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has…

Fix: after 8.2.2
Fix from $2,300 2019-07-23
Slanger CRITICAL 9.8
CVE-2019-1010306

Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted reque…

Patch available
Fix from $2,300 2019-07-15
Osbs Client HIGH 7.2
CVE-2019-10135

A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed t…

Fix: 0.56.1+
Fix from $1,950 2019-07-11
Openshift Container Platform CRITICAL 9.8
CVE-2018-11307EPSS 6%

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…

Fix: 2.6.7.3 / 2.7.9.4+
Fix from $2,300 2019-07-09
TYPO3 HIGH 8.8
CVE-2019-12747

TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.

Fix: after 9.5.7
Fix from $1,950 2019-07-09
Debian Linux MEDIUM 5.9
CVE-2019-12384EPSS 45%

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core clas…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,600 2019-06-24
Cloudtest CRITICAL 9.8
CVE-2019-11011

Akamai CloudTest before 58.30 allows remote code execution.

Fix: 58.30+
Fix from $2,300 2019-06-21
Ethereumj CRITICAL 9.8
CVE-2018-15890

An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/EC…

No fix yet
Fix from $2,300 2019-06-20
Debian Linux MEDIUM 5.9
CVE-2019-12814EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a s…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,600 2019-06-19
Misp HIGH 7.2
CVE-2019-12868EPSS 6%

app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-…

Patch available
Fix from $1,950 2019-06-18
Shopware HIGH 8.8
CVE-2019-12799EPSS 55%

In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can …

Fix: after 5.6.0
Fix from $1,950 2019-06-13
Coldfusion CRITICAL 9.8
CVE-2019-7840EPSS 17%

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Su…

Mitigation only
Fix from $2,300 2019-06-12
Experience Platform HIGH 8.8
CVE-2019-11080EPSS 14%

Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user …

Fix: 9.1.1+
Fix from $1,950 2019-06-06
Intelligent Management Center HIGH 8.8
CVE-2019-11950EPSS 6%

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $1,950 2019-06-05
Intelligent Management Center HIGH 8.8
CVE-2019-11956EPSS 6%

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $1,950 2019-06-05
Intelligent Management Center HIGH 8.8
CVE-2019-5350EPSS 6%

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $1,950 2019-06-05
Intelligent Management Center CRITICAL 9.8
CVE-2019-11944EPSS 13%

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $2,300 2019-06-05
Intelligent Management Center CRITICAL 9.8
CVE-2019-11945EPSS 79%

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $2,300 2019-06-05
Godot CRITICAL 9.8
CVE-2019-10069

In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.

Fix: 2.1+
Fix from $2,300 2019-05-31
Cms CRITICAL 9.8
CVE-2019-9874 KEVEPSS 84%

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo…

Fix: after 8.2
Fix from $2,300 2019-05-31
Cms HIGH 8.8
CVE-2019-9875 KEVEPSS 14%

Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi…

Fix: after 9.1
Fix from $1,950 2019-05-31
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2019-6980

Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.

Fix: 8.7.11 / 8.8.9+
Fix from $2,300 2019-05-29
Coldfusion CRITICAL 9.8
CVE-2019-7091EPSS 26%

ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Suc…

Mitigation only
Fix from $2,300 2019-05-24
E107 HIGH 8.8
CVE-2016-10753

e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.

No fix yet
Fix from $1,950 2019-05-24