Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2022-37936 Unauthenticated Java deserialization vulnerability in Serviceguard Manager Serviceguard For Linux Mitigation only Fix from $2,3002023-03-01 CRITICAL 9.8 CVE-2023-27372EPSS 100% SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… Debian Linux 3.2.18 / 4.0.10+ Fix from $2,3002023-02-28 HIGH 7.8 CVE-2023-20944 In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esca… Android Patch available Fix from $1,9502023-02-28 CRITICAL 9.8 CVE-2022-23535 LiteDB is a small, fast and lightweight .NET NoSQL embedded database. Versions prior to 5.0.13 are subject to Deserialization of Untrusted Data. Lite… Litedb 5.0.13+ Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-26326 The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated at… Buddyforms 2.7.8+ Fix from $2,3002023-02-23 CRITICAL 9.8 CVE-2023-0960 A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config… Seacms No fix yet Fix from $2,3002023-02-22 HIGH 7.2 CVE-2022-48282 Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which … C\# Driver 2.19.0+ Fix from $1,9502023-02-21 CRITICAL 9.8 CVE-2023-26234 JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance. Jd Gui Patch available Fix from $2,3002023-02-21 CRITICAL 9.8 CVE-2022-47986 KEVEPSS 100% IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializa… Aspera Faspex after 4.4.1 Fix from $2,3002023-02-17 HIGH 7.2 CVE-2023-23836EPSS 80% SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-47507EPSS 7% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-38111EPSS 85% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-47503EPSS 24% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-47504EPSS 25% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2023-21710EPSS 8% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-21713 Microsoft SQL Server Remote Code Execution Vulnerability Sql Server Patch available Fix from $1,9502023-02-14 HIGH 7.2 CVE-2023-21703 Azure Data Box Gateway Remote Code Execution Vulnerability Azure Data Box Gateway Patch available Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-21706 Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-21707EPSS 82% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-21529 KEVEPSS 62% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502023-02-14 HIGH 7.3 CVE-2023-21568 Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability Sql Server 2019 Integration Services Patch available Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-25558 DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The… Datahub 0.9.5+ Fix from $1,9502023-02-11 HIGH 8.8 CVE-2022-3568 The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and i… Imagemagick Engine 1.7.6+ Fix from $1,9502023-02-10 CRITICAL 9.8 CVE-2022-45982 thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a c… Thinkphp after 6.0.13 Fix from $2,3002023-02-08 HIGH 8.8 CVE-2023-25194EPSS 96% A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to… Kafka Connect after 3.3.2 Fix from $1,9502023-02-07 HIGH 7.2 CVE-2023-0669 KEVEPSS 100% Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due t… Goanywhere Managed File Transfer 7.1.2+ Fix from $1,9502023-02-06 CRITICAL 9.8 CVE-2023-25135EPSS 24% vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializati… Vbulletin No fix yet Fix from $2,3002023-02-03 CRITICAL 9.8 CVE-2023-24997 Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.… Inlong after 1.5.0 Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2023-24162 Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter. Hutool No fix yet Fix from $2,3002023-01-31 HIGH 8.8 CVE-2022-44645 In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when… Linkis after 1.3.0 Fix from $1,9502023-01-31