Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-32521
A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deseriali…
Data Center Expert
7.9.0+
HIGH 7.5
CVE-2022-31710
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrust…
Vrealize Log Insight
8.10.2+
HIGH 8.8
CVE-2022-45923
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker …
Opentext Extended Ecm
after 22.4
HIGH 7.5
CVE-2023-21839 KEVEPSS 100%
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…
Weblogic Server
Patch available
CRITICAL 9.8
CVE-2022-4890
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file …
Predictapp
2022-03-20+
HIGH 8.8
CVE-2023-22850
Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.
Tiki
24.1+
CRITICAL 9.8
CVE-2022-46478
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary comma…
Datax Web
after 2.1.2
HIGH 8.8
CVE-2022-41778
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect servic…
Infrasuite Device Master
after 00.00.01a
HIGH 7.8
CVE-2023-21779
Visual Studio Code Remote Code Execution Vulnerability
Visual Studio Code
1.74.3+
HIGH 8.0
CVE-2023-21745
Microsoft Exchange Server Spoofing Vulnerability
Exchange Server
No fix yet
HIGH 8.0
CVE-2023-21762
Microsoft Exchange Server Spoofing Vulnerability
Exchange Server
No fix yet
HIGH 8.8
CVE-2023-21744
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Foundation
No fix yet
HIGH 7.5
CVE-2023-21538
.NET Denial of Service Vulnerability
Fedora
No fix yet
HIGH 8.8
CVE-2022-47083EPSS 18%
A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via…
Spitfire
No fix yet
MEDIUM 6.1
CVE-2021-32828
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vu…
Nuxeo
after 11.5.109
CRITICAL 9.8
CVE-2021-32824
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…
Dubbo
2.6.10 / 2.7.10+
HIGH 7.5
CVE-2022-41966EPSS 9%
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack…
Xstream
1.4.20+
HIGH 8.1
CVE-2020-10650
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via igni…
Debian Linux
2.9.10.4+
HIGH 7.5
CVE-2022-41596
The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of …
Harmonyos
2.1+
CRITICAL 9.8
CVE-2021-38241
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
Ruoyi
4.6.1+
CRITICAL 9.8
CVE-2021-33420
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable functio…
Replicator
1.0.4+
CRITICAL 9.8
CVE-2022-44351
Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.
Skycaiji
No fix yet
CRITICAL 9.8
CVE-2022-44371
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
Hope Boot
No fix yet
CRITICAL 9.8
CVE-2022-32224
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 whic…
Activerecord
5.2.8.1 / 6.0.5.1+
CRITICAL 9.8
CVE-2022-46366
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…
Tapestry
4.0.0+
CRITICAL 9.8
CVE-2022-1471EPSS 100%
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an a…
Snakeyaml
2.0+
HIGH 8.8
CVE-2022-36964EPSS 17%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…
Orion Platform
2020.2.6+
HIGH 7.8
CVE-2022-41958
super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. A…
Super Xray
0.7+
CRITICAL 9.8
CVE-2022-41875
A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads.…
Optica
0.10.2+
CRITICAL 9.8
CVE-2022-41922
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. T…
Yii
1.1.27+