Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Sofa Hessian CRITICAL 9.8
CVE-2019-9212

SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.…

Fix: after 4.0.2
Fix from $2,300 2019-02-27
Drupal HIGH 8.1
CVE-2019-6340 KEVEPSS 92%

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to a…

Fix: 8.5.11 / 8.6.10+
Fix from $1,950 2019-02-21
Joomla\! CRITICAL 9.8
CVE-2019-7743

An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protectio…

Fix: after 3.9.2
Fix from $2,300 2019-02-12
Mpdf HIGH 8.8
CVE-2019-1000005

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class…

Fix: after 7.1.7
Fix from $1,950 2019-02-04
Drupal HIGH 8.0
CVE-2019-6338

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. …

Fix: 7.62 / 8.5.9+
Fix from $1,950 2019-01-22
Cosin CRITICAL 9.8
CVE-2019-6503

There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading…

No fix yet
Fix from $2,300 2019-01-22
Web Infrastructure Platform CRITICAL 9.8
CVE-2018-20732

SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

Fix: 9.4+
Fix from $2,300 2019-01-17
Fedora CRITICAL 9.8
CVE-2019-6446EPSS 18%

An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code vi…

Fix: after 1.16.0
Fix from $2,300 2019-01-16
Pydio CRITICAL 9.8
CVE-2018-20718

In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a prefer…

Fix: 8.2.2+
Fix from $2,300 2019-01-15
Chrome HIGH 8.8
CVE-2018-6162

Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Debian Linux CRITICAL 9.8
CVE-2018-14718EPSS 13%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14719EPSS 10%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt an…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14720EPSS 8%

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19360EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms c…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19361EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from po…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19362EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core cla…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Buck CRITICAL 9.8
CVE-2018-6331

Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lea…

Fix: 2018.06.25.01+
Fix from $2,300 2018-12-31
Pear Archive Tar HIGH 8.8
CVE-2018-1000888EPSS 19%

PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with…

Fix: after 1.4.3
Fix from $1,950 2018-12-28
Ubilling CRITICAL 9.8
CVE-2018-1000827

Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, den…

Fix: after 0.9.2
Fix from $2,300 2018-12-20
Zoneminder CRITICAL 9.8
CVE-2018-1000832EPSS 6%

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, …

Fix: after 1.32.2
Fix from $2,300 2018-12-20
Zoneminder CRITICAL 9.8
CVE-2018-1000833

ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, …

Fix: after 1.32.2
Fix from $2,300 2018-12-20
Megamek CRITICAL 9.8
CVE-2018-1000824

MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, deni…

Fix: 0.45.1+
Fix from $2,300 2018-12-20
WordPress CRITICAL 9.8
CVE-2018-20148EPSS 27%

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XML…

Fix: 4.9.9 / 5.0.1+
Fix from $2,300 2018-12-14
Websphere Application Server CRITICAL 9.8
CVE-2018-1904

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client …

Fix: after 9.0.0.9
Fix from $2,300 2018-12-11
Jenkins CRITICAL 9.8
CVE-2018-1000861 KEVEPSS 98%

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/mai…

Fix: after 2.153
Fix from $2,300 2018-12-10
Rails HIGH 7.5
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserializ…

Fix: 4.2.11 / 5.0.7.1+
Fix from $1,950 2018-11-30
Vt Designer HIGH 8.8
CVE-2018-18987

VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity,…

Mitigation only
Fix from $1,950 2018-11-30
Vanilla HIGH 7.2
CVE-2018-19499

Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in…

Fix: 2.5.5 / 2.6.2+
Fix from $1,950 2018-11-23
PHP HIGH 7.5
CVE-2018-19396

ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call f…

Fix: after 7.1.24
Fix from $1,950 2018-11-20
Debian Linux HIGH 7.2
CVE-2018-19274EPSS 5%

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deseria…

Fix: 3.2.4+
Fix from $1,950 2018-11-17