Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-2042
A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functional…
Datagear
after 4.5.1
HIGH 7.8
CVE-2023-1552
ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social…
Toolboxst
7.10+
HIGH 8.8
CVE-2023-1381
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR d…
Wp Meta Seo
4.5.5+
CRITICAL 9.8
CVE-2023-29215
In Apache Linkis <=1.3.1, due to the lack of effective filtering
of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi…
Linkis
after 1.3.1
CRITICAL 9.8
CVE-2023-29216
In Apache Linkis <=1.3.1, because the parameters are not
effectively filtered, the attacker uses the MySQL data source and malicious parameters to
co…
Linkis
after 1.3.1
CRITICAL 9.8
CVE-2023-28500
A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operati…
Livecycle Es4
11.0.1+
HIGH 8.8
CVE-2023-20102
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbi…
Secure Network Analytics
after 7.4.1
HIGH 8.8
CVE-2023-29006
The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an aut…
Order
2.7.7+
CRITICAL 9.8
CVE-2020-29312
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be…
Zend Framework
after 3.1.3
CRITICAL 9.8
CVE-2023-28462
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (C…
Payara Server
after 5.0.0
CRITICAL 9.8
CVE-2022-36974EPSS 84%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…
Avalanche
6.3.4+
CRITICAL 9.8
CVE-2022-36977EPSS 7%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…
Avalanche
6.3.4+
CRITICAL 9.8
CVE-2022-36978EPSS 7%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…
Avalanche
6.3.4+
HIGH 7.8
CVE-2022-2561
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is requi…
Quickopc
5.63.246+
HIGH 7.8
CVE-2022-28685EPSS 17%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U…
Aveva Edge
2020.2.00.40+
HIGH 8.8
CVE-2022-36971EPSS 15%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…
Avalanche
6.3.4+
HIGH 7.8
CVE-2023-26547
The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privile…
Emui
No fix yet
HIGH 7.5
CVE-2023-26548
The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.
Emui
No fix yet
CRITICAL 9.8
CVE-2023-1399
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges i…
N6854a Firmware
after 2.4.2
HIGH 7.8
CVE-2023-1145
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect s…
Infrasuite Device Master
1.0.5+
HIGH 8.8
CVE-2023-27296
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.
It could be triggered by authenticated users of InLong,…
Inlong
after 1.5.0
CRITICAL 9.8
CVE-2023-1133EPSS 50%
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ …
Infrasuite Device Master
1.0.5+
HIGH 8.8
CVE-2023-1139
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway servi…
Infrasuite Device Master
1.0.5+
CRITICAL 9.8
CVE-2023-26359 KEVEPSS 18%
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabil…
Coldfusion
Patch available
CRITICAL 9.8
CVE-2023-28667
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of …
Lead Generated
1.25+
HIGH 7.8
CVE-2023-27978EPSS 6%
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload dat…
Custom Reports
after 16.0.0.23040
CRITICAL 9.8
CVE-2023-28115
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHA…
Snappy
1.4.2+
HIGH 7.5
CVE-2023-26464
** UNSUPPORTED WHEN ASSIGNED **
When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t…
Log4j
2.0+
CRITICAL 9.8
CVE-2023-23638
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution.
This issue affects Apache Dubbo 2.…
Dubbo
after 3.1.5
CRITICAL 9.8
CVE-2023-26779
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).
Yf Exam
No fix yet