Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2022-32521 A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deseriali… Data Center Expert 7.9.0+ Fix from $1,9502023-01-30 HIGH 7.5 CVE-2022-31710 vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrust… Vrealize Log Insight 8.10.2+ Fix from $1,9502023-01-26 HIGH 8.8 CVE-2022-45923 An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker … Opentext Extended Ecm after 22.4 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21839 KEVEPSS 100% Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3… Weblogic Server Patch available Fix from $1,9502023-01-18 CRITICAL 9.8 CVE-2022-4890 A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file … Predictapp 2022-03-20+ Fix from $2,3002023-01-16 HIGH 8.8 CVE-2023-22850 Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call. Tiki 24.1+ Fix from $1,9502023-01-14 CRITICAL 9.8 CVE-2022-46478 The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary comma… Datax Web after 2.1.2 Fix from $2,3002023-01-13 HIGH 8.8 CVE-2022-41778 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect servic… Infrasuite Device Master after 00.00.01a Fix from $1,9502023-01-13 HIGH 7.8 CVE-2023-21779 Visual Studio Code Remote Code Execution Vulnerability Visual Studio Code 1.74.3+ Fix from $1,9502023-01-10 HIGH 8.0 CVE-2023-21745 Microsoft Exchange Server Spoofing Vulnerability Exchange Server No fix yet Fix from $1,9502023-01-10 HIGH 8.0 CVE-2023-21762 Microsoft Exchange Server Spoofing Vulnerability Exchange Server No fix yet Fix from $1,9502023-01-10 HIGH 8.8 CVE-2023-21744 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Foundation No fix yet Fix from $1,9502023-01-10 HIGH 7.5 CVE-2023-21538 .NET Denial of Service Vulnerability Fedora No fix yet Fix from $1,9502023-01-10 HIGH 8.8 CVE-2022-47083EPSS 18% A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via… Spitfire No fix yet Fix from $1,9502023-01-10 MEDIUM 6.1 CVE-2021-32828 The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vu… Nuxeo after 11.5.109 Fix from $1,6002023-01-05 CRITICAL 9.8 CVE-2021-32824 Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb… Dubbo 2.6.10 / 2.7.10+ Fix from $2,3002023-01-03 HIGH 7.5 CVE-2022-41966EPSS 9% XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack… Xstream 1.4.20+ Fix from $1,9502022-12-28 HIGH 8.1 CVE-2020-10650 A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via igni… Debian Linux 2.9.10.4+ Fix from $1,9502022-12-26 HIGH 7.5 CVE-2022-41596 The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of … Harmonyos 2.1+ Fix from $1,9502022-12-20 CRITICAL 9.8 CVE-2021-38241 Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework. Ruoyi 4.6.1+ Fix from $2,3002022-12-16 CRITICAL 9.8 CVE-2021-33420 A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable functio… Replicator 1.0.4+ Fix from $2,3002022-12-15 CRITICAL 9.8 CVE-2022-44351 Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php. Skycaiji No fix yet Fix from $2,3002022-12-07 CRITICAL 9.8 CVE-2022-44371 hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE). Hope Boot No fix yet Fix from $2,3002022-12-07 CRITICAL 9.8 CVE-2022-32224 A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 whic… Activerecord 5.2.8.1 / 6.0.5.1+ Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-46366 Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1… Tapestry 4.0.0+ Fix from $2,3002022-12-02 CRITICAL 9.8 CVE-2022-1471EPSS 100% SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an a… Snakeyaml 2.0+ Fix from $2,3002022-12-01 HIGH 8.8 CVE-2022-36964EPSS 17% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar… Orion Platform 2020.2.6+ Fix from $1,9502022-11-29 HIGH 7.8 CVE-2022-41958 super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. A… Super Xray 0.7+ Fix from $1,9502022-11-25 CRITICAL 9.8 CVE-2022-41875 A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads.… Optica 0.10.2+ Fix from $2,3002022-11-23 CRITICAL 9.8 CVE-2022-41922 `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. T… Yii 1.1.27+ Fix from $2,3002022-11-23