Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2022-21549
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …
Fedora
Patch available
HIGH 7.8
CVE-2022-27579
A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.…
Flexi Soft Designer
1.9.4+
HIGH 7.8
CVE-2022-27580
A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 al…
Safety Designer
after 1.11.0
HIGH 7.8
CVE-2022-1984
This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 ma…
Workforce Access
7.3.0+
CRITICAL 9.8
CVE-2022-24082EPSS 12%
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no…
Infinity
8.7.3+
CRITICAL 9.8
CVE-2022-35405 KEVEPSS 100%
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect…
Manageengine Access Manager Plus
4.3 / 5.5+
CRITICAL 9.8
CVE-2022-2437
The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' …
Feed Them Social
2.9.8.6+
HIGH 8.8
CVE-2022-2444
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data…
Visualizer
3.7.10+
CRITICAL 9.8
CVE-2021-41419EPSS 9%
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
Dvr Firmware
2021-12-13+
HIGH 8.8
CVE-2022-30981
An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence …
Gentics Cms
5.43.1+
HIGH 7.8
CVE-2021-36665
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
Insync Client
7.0.0+
CRITICAL 9.8
CVE-2022-31604
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and …
Nvflare
2.1.2+
CRITICAL 9.8
CVE-2022-31605
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load…
Nvflare
2.1.2+
HIGH 8.8
CVE-2022-31115
opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used inst…
Opensearch
2.0.2+
CRITICAL 9.8
CVE-2022-33107EPSS 23%
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Abstr…
Thinkphp
No fix yet
MEDIUM 5.0
CVE-2022-20195
In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial o…
Android
Mitigation only
HIGH 7.0
CVE-2021-35095
Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same…
Ar8035 Firmware
Patch available
CRITICAL 9.8
CVE-2022-25845EPSS 19%
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restric…
Fastjson
1.2.83+
CRITICAL 9.8
CVE-2022-25863
The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input thro…
Gatsby
2.14.1 / 3.15.2+
CRITICAL 9.8
CVE-2022-1660EPSS 17%
The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker…
N6854a Firmware
2.4.0+
CRITICAL 9.8
CVE-2022-29875
A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA…
Biograph Horizon Pet\/ct Systems Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-32935
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker…
In Sight Opc Server
after 5.7.4_
HIGH 7.5
CVE-2022-28948
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
Yaml
Patch available
HIGH 7.8
CVE-2022-1118EPSS 11%
Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and pr…
Connected Component Workbench
after 13.00.00
CRITICAL 9.8
CVE-2022-24108EPSS 33%
The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potenti…
So Listing Tabs
No fix yet
HIGH 8.8
CVE-2022-0573
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation …
Artifactory
6.23.41 / 7.17.16+
CRITICAL 9.8
CVE-2022-29363
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows atta…
Phpok
No fix yet
HIGH 8.8
CVE-2022-1463
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and includ…
Booking Calendar
after 9.1
CRITICAL 9.8
CVE-2021-23592
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver cla…
Thinkphp
6.0.12+
CRITICAL 9.8
CVE-2020-23620
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of us…
Orlansoft Erp
Mitigation only