Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2023-38647 An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S… Helix 1.3.0+ Fix from $2,3002023-07-26 CRITICAL 9.8 CVE-2023-37895 Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in… Jackrabbit 2.20.11 / 2.21.18+ Fix from $2,3002023-07-25 HIGH 7.5 CVE-2023-34434 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.… Inlong after 1.7.0 Fix from $1,9502023-07-25 HIGH 7.5 CVE-2023-3324 A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul… Zenon after 11.0.0 Fix from $1,9502023-07-24 CRITICAL 9.8 CVE-2023-38203 KEVEPSS 97% Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vu… Coldfusion Patch available Fix from $2,3002023-07-20 HIGH 8.8 CVE-2023-28754 Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a sp… Shardingsphere 5.4.0+ Fix from $1,9502023-07-19 CRITICAL 9.8 CVE-2023-26512 CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac… Eventmesh Connector Rabbitmq after 1.8.0 Fix from $2,3002023-07-17 HIGH 7.8 CVE-2023-3513 Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access… Razer Central after 7.11.0.558 Fix from $1,9502023-07-14 HIGH 7.5 CVE-2023-25770 Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notific… C300 Firmware after 520.2tcu2 Fix from $1,9502023-07-13 HIGH 8.8 CVE-2023-3343 The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untru… User Registration after 3.0.1 Fix from $1,9502023-07-13 CRITICAL 9.8 CVE-2023-29300 KEVEPSS 100% Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untruste… Coldfusion Mitigation only Fix from $2,3002023-07-12 CRITICAL 9.8 CVE-2023-36825 Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability prese… Platform 14.5.0+ Fix from $2,3002023-07-11 HIGH 7.8 CVE-2023-35317 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Windows Server 2012 Patch available Fix from $1,9502023-07-11 HIGH 8.8 CVE-2023-33160 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502023-07-11 HIGH 8.8 CVE-2023-33134 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502023-07-11 CRITICAL 9.8 CVE-2023-34347 ​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remo… Infrasuite Device Master 1.0.7+ Fix from $2,3002023-07-10 MEDIUM 5.3 CVE-2023-33008 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input tha… Johnzon 1.2.21+ Fix from $1,6002023-07-07 CRITICAL 9.8 CVE-2023-28323 A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit… Endpoint Manager 2022+ Fix from $2,3002023-07-01 HIGH 8.8 CVE-2023-31222EPSS 28% Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an… Paceart Optima 1.12+ Fix from $1,9502023-06-29 MEDIUM 5.5 CVE-2023-21205 In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local inform… Android Mitigation only Fix from $1,6002023-06-28 MEDIUM 6.7 CVE-2023-21209 In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of … Android Mitigation only Fix from $1,6002023-06-28 CRITICAL 9.8 CVE-2023-33299EPSS 24% A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to exe… Fortinac after 9.2.7 Fix from $2,3002023-06-23 HIGH 8.8 CVE-2023-26436 Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserializa… Open Xchange Appsuite Backend 7.10.6+ Fix from $1,9502023-06-20 CRITICAL 9.8 CVE-2023-35839 A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload. Solon 2.3.3+ Fix from $2,3002023-06-19 HIGH 8.8 CVE-2023-3308 A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template … Icefrog No fix yet Fix from $1,9502023-06-18 HIGH 7.8 CVE-2023-21124 In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege… Android Patch available Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-32031EPSS 81% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-06-14 HIGH 8.0 CVE-2023-28310EPSS 25% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-06-14 HIGH 7.8 CVE-2023-3001EPSS 32% A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload dat… Igss Dashboard 16.0.0.23131+ Fix from $1,9502023-06-14 CRITICAL 9.8 CVE-2023-3234 A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_im… Crmeb after 4.6.0 Fix from $2,3002023-06-14