Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux HIGH 8.8
CVE-2018-19296

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

Fix: 5.2.27 / 6.0.6+
Fix from $1,950 2018-11-16
Unity Express CRITICAL 9.8
CVE-2018-15381EPSS 87%

A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands…

Fix: 9.0.6+
Fix from $2,300 2018-11-08
Superset CRITICAL 9.8
CVE-2018-8021EPSS 53%

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. …

Fix: 0.23+
Fix from $2,300 2018-11-07
Websphere Application Server CRITICAL 9.8
CVE-2018-1851

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper des…

Fix: 18.0.0.3+
Fix from $2,300 2018-10-31
Ubuntu Linux HIGH 7.8
CVE-2018-15686

A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be…

Fix: after 239
Fix from $1,950 2018-10-26
Xenmobile Server HIGH 7.8
CVE-2018-18013

* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supp…

Fix: after 10.8.0
Fix from $1,950 2018-10-24
Pippo CRITICAL 9.8
CVE-2018-18628EPSS 5%

An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize…

Patch available
Fix from $2,300 2018-10-23
Real User Monitoring HIGH 8.8
CVE-2018-18589

A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9…

Mitigation only
Fix from $1,950 2018-10-23
Avaya Aura System Platform CRITICAL 9.8
CVE-2018-15616

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserializatio…

Fix: after 6.4.2
Fix from $2,300 2018-10-17
Weblogic Server CRITICAL 9.8
CVE-2018-3245EPSS 94%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are af…

Patch available
Fix from $2,300 2018-10-17
Pippo CRITICAL 9.8
CVE-2018-18240

Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream'…

Fix: after 1.11.0
Fix from $2,300 2018-10-11
Manageengine Applications Manager HIGH 8.1
CVE-2018-16364EPSS 18%

A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload …

No fix yet
Fix from $1,950 2018-09-26
Monero CRITICAL 9.8
CVE-2018-3972

An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (…

No fix yet
Fix from $2,300 2018-09-26
Coldfusion CRITICAL 9.8
CVE-2018-15965EPSS 26%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data…

Mitigation only
Fix from $2,300 2018-09-25
Coldfusion CRITICAL 9.8
CVE-2018-15957EPSS 28%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data…

Mitigation only
Fix from $2,300 2018-09-25
Coldfusion CRITICAL 9.8
CVE-2018-15958EPSS 26%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data…

Mitigation only
Fix from $2,300 2018-09-25
Coldfusion CRITICAL 9.8
CVE-2018-15959EPSS 26%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data…

Mitigation only
Fix from $2,300 2018-09-25
Processmaker HIGH 8.8
CVE-2016-9045

A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserializa…

No fix yet
Fix from $1,950 2018-09-17
Tcpdf CRITICAL 9.8
CVE-2018-17057EPSS 26%

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

Fix: 3.16.0 / 6.2.22+
Fix from $2,300 2018-09-14
Infinispan HIGH 8.8
CVE-2016-0750

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user cou…

Fix: 9.1.0+
Fix from $1,950 2018-09-11
Websphere Application Server CRITICAL 9.8
CVE-2018-1567

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a…

Fix: after 9.0.0.9
Fix from $2,300 2018-09-07
Virtualization Host HIGH 7.5
CVE-2018-10911

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Docker HIGH 8.8
CVE-2018-15514

HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\p…

No fix yet
Fix from $1,950 2018-09-01
Antivirus \+ Security HIGH 7.8
CVE-2018-10513

A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker …

Fix: after 12.0
Fix from $1,950 2018-08-30
Release Automation CRITICAL 9.8
CVE-2018-15691EPSS 17%

Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute …

Fix: 6.3.0.9945 / 6.4.0.10119+
Fix from $2,300 2018-08-30
Conference Scheduler Cli HIGH 7.8
CVE-2018-14572

In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as dem…

Fix: after 0.10.1
Fix from $1,950 2018-08-28
Easylogin Pro HIGH 8.1
CVE-2018-15576EPSS 10%

An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in…

Fix: after 1.3.0
Fix from $1,950 2018-08-24
Jenkins MEDIUM 5.3
CVE-2018-1999042

A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name…

Fix: after 2.137
Fix from $1,600 2018-08-23
Yeswiki CRITICAL 9.8
CVE-2018-1000641

YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that ca…

Patch available
Fix from $2,300 2018-08-20
Swoole HIGH 7.5
CVE-2018-15503

The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object…

Patch available
Fix from $1,950 2018-08-18