Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Intelligent Management Center CRITICAL 9.8
CVE-2017-12557EPSS 80%

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

Fix: after 7.3
Fix from $2,300 2018-02-15
Network Automation CRITICAL 9.8
CVE-2016-8511EPSS 15%

A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v1…

Mitigation only
Fix from $2,300 2018-02-15
Operations Orchestration CRITICAL 9.8
CVE-2016-8519EPSS 28%

A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.

Fix: 10.70+
Fix from $2,300 2018-02-15
Infinispan HIGH 8.8
CVE-2017-15089

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authentica…

Fix: after 9.1.6
Fix from $1,950 2018-02-15
Pipeline Supporting Apis HIGH 8.8
CVE-2018-1000058

Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to J…

Fix: after 2.17
Fix from $1,950 2018-02-09
Validform Builder CRITICAL 9.8
CVE-2018-1000059

ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute …

Mitigation only
Fix from $2,300 2018-02-09
Singledop HIGH 7.8
CVE-2018-1000045

NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This …

Patch available
Fix from $1,950 2018-02-09
Pyblock HIGH 7.8
CVE-2018-1000046

NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack…

Fix: after 1.3
Fix from $1,950 2018-02-09
Kodiak HIGH 8.8
CVE-2018-1000047

NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This…

Mitigation only
Fix from $1,950 2018-02-09
Rtretrievalframework HIGH 8.8
CVE-2018-1000048

NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in r…

Mitigation only
Fix from $1,950 2018-02-09
Web2py CRITICAL 9.8
CVE-2016-3957

The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which migh…

Fix: 2.14.2+
Fix from $2,300 2018-02-06
Debian Linux CRITICAL 9.8
CVE-2017-15095EPSS 8%

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo…

Fix: 2.6.7.2 / 2.7.9.2+
Fix from $2,300 2018-02-06
Debian Linux CRITICAL 9.8
CVE-2017-7525EPSS 38%

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user …

Fix: 2.6.7.1 / 2.7.9.1+
Fix from $2,300 2018-02-06
Jenkins CRITICAL 9.8
CVE-2017-1000353 KEVEPSS 100%

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated re…

Fix: after 2.56
Fix from $2,300 2018-01-29
Jenkins MEDIUM 6.5
CVE-2017-1000355

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.

Fix: after 2.56
Fix from $1,600 2018-01-29
Vrealize Automation CRITICAL 9.8
CVE-2017-4947EPSS 9%

VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Succes…

Fix: 1.3.0+
Fix from $2,300 2018-01-29
Nifi MEDIUM 5.0
CVE-2017-15703

Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den…

Fix: after 1.4.0
Fix from $1,600 2018-01-25
Resteasy HIGH 8.1
CVE-2018-1051

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…

Mitigation only
Fix from $1,950 2018-01-25
Enterprise Manager CRITICAL 9.8
CVE-2017-17406

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not…

Fix: 7.2.766+
Fix from $2,300 2018-01-23
Debian Linux HIGH 8.1
CVE-2018-5968EPSS 7%

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…

Fix: 2.6.7.3 / 2.7.9.2+
Fix from $1,950 2018-01-22
Groovy CRITICAL 9.8
CVE-2016-6814EPSS 17%

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se…

Fix: after 2.4.7
Fix from $2,300 2018-01-18
Debian Linux CRITICAL 9.8
CVE-2017-17485EPSS 50%

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…

Fix: 2.6.7.3 / 2.7.9.2+
Fix from $2,300 2018-01-10
Dozer CRITICAL 9.8
CVE-2014-9515EPSS 6%

Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted seri…

Fix: after 5.5.1
Fix from $2,300 2017-12-29
Flex Blazeds CRITICAL 9.8
CVE-2017-5641EPSS 21%

Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. …

Fix: 8.5.3-00+
Fix from $2,300 2017-12-28
Vbulletin CRITICAL 9.8
CVE-2017-17672EPSS 15%

In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circum…

Fix: after 5.3.3
Fix from $2,300 2017-12-14
Coldfusion CRITICAL 9.8
CVE-2017-11283EPSS 43%

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 a…

Patch available
Fix from $2,300 2017-12-01
Coldfusion CRITICAL 9.8
CVE-2017-11284EPSS 43%

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 a…

Patch available
Fix from $2,300 2017-12-01
Swagger Codegen HIGH 8.8
CVE-2017-1000207

A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being…

Fix: after 2.2.2
Fix from $1,950 2017-11-27
Spring Security HIGH 8.1
CVE-2017-4995

An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable defau…

Mitigation only
Fix from $1,950 2017-11-27
Spring Advanced Message Queuing Protocol CRITICAL 9.8
CVE-2017-8045

In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being c…

Mitigation only
Fix from $2,300 2017-11-27