Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.2 CVE-2022-38108EPSS 69% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform 2020.2.6+ Fix from $1,9502022-10-20 HIGH 7.2 CVE-2022-36957EPSS 13% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform 2020.2.6+ Fix from $1,9502022-10-20 HIGH 8.8 CVE-2022-36958EPSS 83% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar… Orion Platform 2020.2.6+ Fix from $1,9502022-10-20 CRITICAL 9.8 CVE-2022-43019 OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality. Opencats No fix yet Fix from $2,3002022-10-19 HIGH 8.8 CVE-2022-23734 A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on … Enterprise Server 3.2.16 / 3.3.11+ Fix from $1,9502022-10-19 CRITICAL 9.8 CVE-2022-39198 A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss… Dubbo after 3.0.11 Fix from $2,3002022-10-18 CRITICAL 9.8 CVE-2022-40889 Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php. Phpok No fix yet Fix from $2,3002022-10-18 CRITICAL 9.8 CVE-2022-22241 An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data w… Junos 19.1+ Fix from $2,3002022-10-18 MEDIUM 6.5 CVE-2022-3291 Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can lea… GitLab 15.2.5 / 15.3.4+ Fix from $1,6002022-10-17 HIGH 8.8 CVE-2022-39311 GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go… Gocd 21.1.0+ Fix from $1,9502022-10-14 CRITICAL 9.8 CVE-2022-39297 MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools. Attackers ca… Meliscms 5.0.1+ Fix from $2,3002022-10-12 CRITICAL 9.8 CVE-2022-39298 MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewritting, search optimization an… Meliscms 5.0.1+ Fix from $2,3002022-10-12 CRITICAL 9.8 CVE-2018-18446 dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2). Paint.net 4.1.2+ Fix from $2,3002022-10-12 CRITICAL 9.8 CVE-2018-18447 dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2). Paint.net 4.1.2+ Fix from $2,3002022-10-12 CRITICAL 9.1 CVE-2022-31680EPSS 33% The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on… Vcenter Server 6.5+ Fix from $2,3002022-10-07 HIGH 7.8 CVE-2022-26471 In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no a… Android Mitigation only Fix from $1,9502022-10-07 HIGH 7.8 CVE-2022-26472 In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additio… Android Mitigation only Fix from $1,9502022-10-07 HIGH 8.0 CVE-2022-41082 KEVEPSS 100% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502022-10-03 HIGH 7.5 CVE-2022-42003 In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value d… Debian Linux 2.12.7.1 / 2.13.3+ Fix from $1,9502022-10-02 HIGH 7.5 CVE-2022-42004 In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to … Debian Linux 2.12.7.1 / 2.13.0+ Fix from $1,9502022-10-02 CRITICAL 9.8 CVE-2022-40314 A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified. Moodle 3.9.17 / 3.11.10+ Fix from $2,3002022-09-30 HIGH 8.0 CVE-2022-39256 Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrar… C1 Cms 6.13+ Fix from $1,9502022-09-27 HIGH 7.2 CVE-2022-2903 The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections i… Ninja Forms 3.6.13+ Fix from $1,9502022-09-26 CRITICAL 9.8 CVE-2022-36944EPSS 9% Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction … Fedora 2.9.0 / 2.13.9+ Fix from $2,3002022-09-23 CRITICAL 9.8 CVE-2022-41237 Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co… Dotci after 2.40.00 Fix from $2,3002022-09-21 HIGH 8.8 CVE-2022-40955 In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi… Inlong 1.3.0+ Fix from $1,9502022-09-20 CRITICAL 9.1 CVE-2022-39008 The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to … Emui Mitigation only Fix from $2,3002022-09-16 CRITICAL 9.8 CVE-2022-38352EPSS 20% ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerab… Thinkphp No fix yet Fix from $2,3002022-09-15 HIGH 7.8 CVE-2022-36038 CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in… Circuitverse Patch available Fix from $1,9502022-09-06 HIGH 7.5 CVE-2022-2433 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export… Ajax Load More 5.5.4+ Fix from $1,9502022-09-06