Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2023-2042 A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functional… Datagear after 4.5.1 Fix from $1,9502023-04-14 HIGH 7.8 CVE-2023-1552 ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social… Toolboxst 7.10+ Fix from $1,9502023-04-11 HIGH 8.8 CVE-2023-1381 The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR d… Wp Meta Seo 4.5.5+ Fix from $1,9502023-04-10 CRITICAL 9.8 CVE-2023-29215 In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-29216 In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-28500 A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operati… Livecycle Es4 11.0.1+ Fix from $2,3002023-04-06 HIGH 8.8 CVE-2023-20102 A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbi… Secure Network Analytics after 7.4.1 Fix from $1,9502023-04-05 HIGH 8.8 CVE-2023-29006 The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an aut… Order 2.7.7+ Fix from $1,9502023-04-05 CRITICAL 9.8 CVE-2020-29312 An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be… Zend Framework after 3.1.3 Fix from $2,3002023-04-04 CRITICAL 9.8 CVE-2023-28462 A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (C… Payara Server after 5.0.0 Fix from $2,3002023-03-30 CRITICAL 9.8 CVE-2022-36974EPSS 84% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio… Avalanche 6.3.4+ Fix from $2,3002023-03-29 CRITICAL 9.8 CVE-2022-36977EPSS 7% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio… Avalanche 6.3.4+ Fix from $2,3002023-03-29 CRITICAL 9.8 CVE-2022-36978EPSS 7% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio… Avalanche 6.3.4+ Fix from $2,3002023-03-29 HIGH 7.8 CVE-2022-2561 This vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interaction is requi… Quickopc 5.63.246+ Fix from $1,9502023-03-29 HIGH 7.8 CVE-2022-28685EPSS 17% This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). U… Aveva Edge 2020.2.00.40+ Fix from $1,9502023-03-29 HIGH 8.8 CVE-2022-36971EPSS 15% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio… Avalanche 6.3.4+ Fix from $1,9502023-03-29 HIGH 7.8 CVE-2023-26547 The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privile… Emui No fix yet Fix from $1,9502023-03-27 HIGH 7.5 CVE-2023-26548 The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,9502023-03-27 CRITICAL 9.8 CVE-2023-1399 N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges i… N6854a Firmware after 2.4.2 Fix from $2,3002023-03-27 HIGH 7.8 CVE-2023-1145 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect s… Infrasuite Device Master 1.0.5+ Fix from $1,9502023-03-27 HIGH 8.8 CVE-2023-27296 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong,… Inlong after 1.5.0 Fix from $1,9502023-03-27 CRITICAL 9.8 CVE-2023-1133EPSS 50% Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ … Infrasuite Device Master 1.0.5+ Fix from $2,3002023-03-27 HIGH 8.8 CVE-2023-1139 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway servi… Infrasuite Device Master 1.0.5+ Fix from $1,9502023-03-27 CRITICAL 9.8 CVE-2023-26359 KEVEPSS 18% Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabil… Coldfusion Patch available Fix from $2,3002023-03-23 CRITICAL 9.8 CVE-2023-28667 The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of … Lead Generated 1.25+ Fix from $2,3002023-03-22 HIGH 7.8 CVE-2023-27978EPSS 6% A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload dat… Custom Reports after 16.0.0.23040 Fix from $1,9502023-03-21 CRITICAL 9.8 CVE-2023-28115 Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHA… Snappy 1.4.2+ Fix from $2,3002023-03-17 HIGH 7.5 CVE-2023-26464 ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t… Log4j 2.0+ Fix from $1,9502023-03-10 CRITICAL 9.8 CVE-2023-23638 A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.… Dubbo after 3.1.5 Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-26779 CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE). Yf Exam No fix yet Fix from $2,3002023-03-03