Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Ampache HIGH 8.8
CVE-2017-18375

Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.

No fix yet
Fix from $1,950 2019-05-24
Hazelcast HIGH 8.1
CVE-2016-10750

In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a list…

Fix: 3.11+
Fix from $1,950 2019-05-22
Virim CRITICAL 9.8
CVE-2019-12240

The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.

No fix yet
Fix from $2,300 2019-05-20
Carts Guru CRITICAL 9.8
CVE-2019-12241

The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.

No fix yet
Fix from $2,300 2019-05-20
Debian Linux HIGH 7.5
CVE-2019-12086EPSS 22%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a sp…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,950 2019-05-17
Websphere Application Server CRITICAL 9.8
CVE-2019-4279EPSS 80%

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence …

Fix: after 9.0.0.11
Fix from $2,300 2019-05-17
Symfony HIGH 7.1
CVE-2019-10912

In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user inp…

Fix: 2.8.50 / 3.4.26+
Fix from $1,950 2019-05-16
Logo\! Soft Comfort HIGH 7.8
CVE-2019-10924

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.3). The vulnerability could allow an attacker to execute arbitrary code …

Fix: 8.3+
Fix from $1,950 2019-05-14
Pharstreamwrapper CRITICAL 9.8
CVE-2019-11831EPSS 6%

The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which a…

Fix: 2.1.1 / 3.1.1+
Fix from $2,300 2019-05-09
Pharstreamwrapper CRITICAL 9.8
CVE-2019-11830

PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar st…

Fix: 2.1.1 / 3.1.1+
Fix from $2,300 2019-05-09
Cakephp HIGH 7.5
CVE-2019-11458

An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwr…

Patch available
Fix from $1,950 2019-05-08
Revive Adserver CRITICAL 9.8
CVE-2019-5434EPSS 57%

An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in …

Fix: 4.2.0+
Fix from $2,300 2019-05-06
Smartermail CRITICAL 9.8
CVE-2019-7214EPSS 85%

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the serve…

Fix: 16.3.6985+
Fix from $2,300 2019-04-24
Cms Made Simple HIGH 8.8
CVE-2019-9056

An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersMa…

Mitigation only
Fix from $1,950 2019-04-11
Advance Steel HIGH 7.8
CVE-2019-7361

An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autod…

Mitigation only
Fix from $1,950 2019-04-09
Pimcore HIGH 8.8
CVE-2019-10867EPSS 69%

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will …

Fix: 5.7.1+
Fix from $1,950 2019-04-04
Coapthon HIGH 7.5
CVE-2018-12680

The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a denial of service in applicat…

No fix yet
Fix from $1,950 2019-04-02
Coapthon3 HIGH 7.5
CVE-2018-12679

The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of service in applications that use …

No fix yet
Fix from $1,950 2019-04-02
GitHub CRITICAL 9.8
CVE-2017-18365EPSS 21%

The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute ar…

Fix: 2.8.7+
Fix from $2,300 2019-03-28
Xperience CRITICAL 9.8
CVE-2019-10068 KEVEPSS 96%

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validat…

Fix: 10.0.52 / 11.0.48+
Fix from $2,300 2019-03-26
Cms Made Simple HIGH 8.8
CVE-2019-9055EPSS 12%

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.…

Fix: after 2.2.8
Fix from $1,950 2019-03-26
Cms Made Simple HIGH 8.8
CVE-2019-9057

An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, …

Fix: after 2.2.8
Fix from $1,950 2019-03-26
Cms Made Simple HIGH 8.8
CVE-2019-9061

An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unse…

Fix: after 2.2.8
Fix from $1,950 2019-03-26
Ipycache HIGH 8.8
CVE-2019-7539

A code injection issue was discovered in ipycache through 2016-05-31.

Fix: after 2016-05-31
Fix from $1,950 2019-03-21
Ajera HIGH 8.8
CVE-2018-20221EPSS 10%

Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input…

Fix: after 9.10.16
Fix from $1,950 2019-03-21
Openmrs CRITICAL 9.8
CVE-2018-19276EPSS 99%

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary comman…

Fix: 1.12.1 / 2.0.8+
Fix from $2,300 2019-03-21
Debian Linux HIGH 7.5
CVE-2018-12022EPSS 7%

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…

Patch available
Fix from $1,950 2019-03-21
Debian Linux HIGH 7.5
CVE-2018-12023EPSS 9%

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…

Patch available
Fix from $1,950 2019-03-21
Solr CRITICAL 9.8
CVE-2019-0192EPSS 78%

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it…

Fix: after 6.6.5
Fix from $2,300 2019-03-07
Jmeter CRITICAL 9.8
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a…

Mitigation only
Fix from $2,300 2019-03-06