Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2017-1000248 Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis Redis Store after 1.3.0 Fix from $2,3002017-11-17 HIGH 8.8 CVE-2017-1000208 A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafte… Swagger Codegen after 2.2.2 Fix from $1,9502017-11-17 HIGH 7.5 CVE-2017-1000195 October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissi… October after 1.0.412 Fix from $1,9502017-11-17 CRITICAL 9.8 CVE-2017-12633EPSS 7% The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D… Camel 2.19.4 / 2.20.1+ Fix from $2,3002017-11-15 CRITICAL 9.8 CVE-2017-12634EPSS 7% The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De… Camel 2.19.4+ Fix from $2,3002017-11-15 CRITICAL 9.8 CVE-2015-7501EPSS 86% Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl… Data Grid Mitigation only Fix from $2,3002017-11-09 HIGH 8.8 CVE-2017-1000148 Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of t… Mahara Patch available Fix from $1,9502017-11-03 CRITICAL 9.8 CVE-2016-5003EPSS 15% The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ… Ws Xmlrpc No fix yet Fix from $2,3002017-10-27 CRITICAL 9.8 CVE-2017-12796 The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate user… Openmrs 2.6.1+ Fix from $2,3002017-10-23 HIGH 7.8 CVE-2017-12628 The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex… James Server after 3.0.0 Fix from $1,9502017-10-20 HIGH 7.2 CVE-2015-5164 The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access o… Qpid Mitigation only Fix from $1,9502017-10-18 CRITICAL 9.8 CVE-2016-8736 Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. Openmeetings 3.1.2+ Fix from $2,3002017-10-12 CRITICAL 9.8 CVE-2017-0903EPSS 16% RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specificatio… Debian Linux Patch available Fix from $2,3002017-10-11 CRITICAL 9.8 CVE-2017-12149 KEVEPSS 91% In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-10-04 HIGH 7.8 CVE-2017-0806 An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0… Android Patch available Fix from $1,9502017-10-04 CRITICAL 9.8 CVE-2017-14702EPSS 8% ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserializ… Ers Data System No fix yet Fix from $2,3002017-09-30 CRITICAL 9.8 CVE-2017-10932 All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the a… Nr8120 Firmware 12.17.20+ Fix from $2,3002017-09-28 HIGH 7.2 CVE-2017-14141 The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection … Kaltura Server 13.2.0+ Fix from $1,9502017-09-19 HIGH 8.1 CVE-2017-9805 KEVEPSS 99% The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des… Struts 2.3.34 / 2.5.13+ Fix from $1,9502017-09-15 HIGH 8.8 CVE-2016-8744 Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal… Brooklyn after 0.9.0 Fix from $1,9502017-09-13 HIGH 7.8 CVE-2017-12612 In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched … Spark Mitigation only Fix from $1,9502017-09-13 CRITICAL 9.8 CVE-2017-14035 CrushFTP 8.x before 8.2.0 has a serialization vulnerability. Crushftp No fix yet Fix from $2,3002017-08-30 CRITICAL 9.8 CVE-2017-11153EPSS 12% Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain a… Photo Station after 6.7.2-3429 Fix from $2,3002017-08-08 CRITICAL 9.8 CVE-2017-9785 Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie. Nancy after 1.4.3 Fix from $2,3002017-07-20 HIGH 8.1 CVE-2017-1000034EPSS 6% Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the… Akka after 2.4.16 Fix from $1,9502017-07-17 HIGH 8.1 CVE-2017-1000053 Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session. Plug 1.0.4 / 1.1.7+ Fix from $1,9502017-07-17 CRITICAL 9.1 CVE-2016-6793EPSS 8% The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop… Wicket 1.5.17 / 6.25.0+ Fix from $2,3002017-07-17 HIGH 7.5 CVE-2017-9844EPSS 6% SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java… Netweaver Mitigation only Fix from $1,9502017-07-12 CRITICAL 9.8 CVE-2016-4000EPSS 6% Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. Debian Linux Patch available Fix from $2,3002017-07-06 HIGH 8.2 CVE-2017-2295 Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. … Debian Linux after 4.10.0 Fix from $1,9502017-07-05