Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
MEDIUM 5.7 CVE-2023-36777EPSS 81% Microsoft Exchange Server Information Disclosure Vulnerability Exchange Server Patch available Fix from $1,6002023-09-12 HIGH 8.0 CVE-2023-36757EPSS 69% Microsoft Exchange Server Spoofing Vulnerability Exchange Server Patch available Fix from $1,9502023-09-12 HIGH 8.0 CVE-2023-36744EPSS 82% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-09-12 HIGH 8.0 CVE-2023-36745EPSS 81% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-09-12 HIGH 8.0 CVE-2023-36756EPSS 75% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-09-12 HIGH 8.8 CVE-2022-1415 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a… Decision Manager Mitigation only Fix from $1,9502023-09-11 HIGH 7.8 CVE-2023-35669 In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deseriali… Android Patch available Fix from $1,9502023-09-11 CRITICAL 9.8 CVE-2020-19559 An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() p… Agilis Xfs For Opteva No fix yet Fix from $2,3002023-09-11 HIGH 7.2 CVE-2023-4528EPSS 27% Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (in… Jscape Mft 2023.1.9+ Fix from $1,9502023-09-07 CRITICAL 9.8 CVE-2023-41330 knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerabili… Snappy 1.4.3+ Fix from $2,3002023-09-06 CRITICAL 9.8 CVE-2023-0925 Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 b… Webmethods Mitigation only Fix from $2,3002023-09-06 MEDIUM 6.6 CVE-2023-37941EPSS 29% If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to … Superset after 2.1.0 Fix from $1,6002023-09-06 HIGH 7.8 CVE-2023-28072 Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious user could po… Alienware Command Center 5.5.51.0+ Fix from $1,9502023-09-04 HIGH 8.8 CVE-2023-40595 In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serial… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 HIGH 8.8 CVE-2023-40195 Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo… Airflow Spark Provider 4.1.3+ Fix from $1,9502023-08-28 CRITICAL 9.8 CVE-2023-40571 weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a… Weblogic Framework 0.2.4+ Fix from $2,3002023-08-25 HIGH 7.8 CVE-2023-24621 An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class … Yamlbeans after 1.15 Fix from $1,9502023-08-25 HIGH 7.8 CVE-2023-34040 In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual c… Spring For Apache Kafka after 3.0.9 Fix from $1,9502023-08-24 HIGH 8.8 CVE-2023-39106 An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() c… Nacos Spring Project after 1.1.1 Fix from $1,9502023-08-21 CRITICAL 9.8 CVE-2023-3259 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address fiel… Iboot Pdu4a C10 Firmware 1.44.0804202+ Fix from $2,3002023-08-14 HIGH 7.5 CVE-2023-39396 Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,9502023-08-13 HIGH 8.8 CVE-2023-38181EPSS 11% Microsoft Exchange Server Spoofing Vulnerability Exchange Server Patch available Fix from $1,9502023-08-08 HIGH 8.0 CVE-2023-38182EPSS 6% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-08-08 HIGH 8.0 CVE-2023-35388EPSS 7% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-08-08 CRITICAL 9.8 CVE-2023-38689 Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `ObjectInputStream#readObject` on un… Logisticspipes 0.10.0.71+ Fix from $2,3002023-08-04 CRITICAL 9.8 CVE-2023-36480 The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, … Aerospike Java Client 4.5.0 / 5.2.0+ Fix from $2,3002023-08-04 CRITICAL 9.8 CVE-2022-40609 IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe dese… Sdk 7.1.5.19 / 8.0.8.5+ Fix from $2,3002023-08-02 HIGH 7.8 CVE-2021-31680 Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file. Yolov5 No fix yet Fix from $1,9502023-07-31 HIGH 7.8 CVE-2021-31681 Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file. Yolov3 No fix yet Fix from $1,9502023-07-31 MEDIUM 6.5 CVE-2023-24971 IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to t… B2b Advanced Communications 1.0.0.8+ Fix from $1,6002023-07-31