Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
MEDIUM 5.3 CVE-2022-21549 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are … Fedora Patch available Fix from $1,6002022-07-19 HIGH 7.8 CVE-2022-27579 A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.… Flexi Soft Designer 1.9.4+ Fix from $1,9502022-07-19 HIGH 7.8 CVE-2022-27580 A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 al… Safety Designer after 1.11.0 Fix from $1,9502022-07-19 HIGH 7.8 CVE-2022-1984 This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 ma… Workforce Access 7.3.0+ Fix from $1,9502022-07-19 CRITICAL 9.8 CVE-2022-24082EPSS 12% If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no… Infinity 8.7.3+ Fix from $2,3002022-07-19 CRITICAL 9.8 CVE-2022-35405 KEVEPSS 100% Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect… Manageengine Access Manager Plus 4.3 / 5.5+ Fix from $2,3002022-07-19 CRITICAL 9.8 CVE-2022-2437 The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' … Feed Them Social 2.9.8.6+ Fix from $2,3002022-07-18 HIGH 8.8 CVE-2022-2444 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data… Visualizer 3.7.10+ Fix from $1,9502022-07-18 CRITICAL 9.8 CVE-2021-41419EPSS 9% QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. Dvr Firmware 2021-12-13+ Fix from $2,3002022-07-18 HIGH 8.8 CVE-2022-30981 An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence … Gentics Cms 5.43.1+ Fix from $1,9502022-07-17 HIGH 7.8 CVE-2021-36665 An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon. Insync Client 7.0.0+ Fix from $1,9502022-07-12 CRITICAL 9.8 CVE-2022-31604 NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and … Nvflare 2.1.2+ Fix from $2,3002022-07-01 CRITICAL 9.8 CVE-2022-31605 NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load… Nvflare 2.1.2+ Fix from $2,3002022-07-01 HIGH 8.8 CVE-2022-31115 opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used inst… Opensearch 2.0.2+ Fix from $1,9502022-06-30 CRITICAL 9.8 CVE-2022-33107EPSS 23% ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Abstr… Thinkphp No fix yet Fix from $2,3002022-06-29 MEDIUM 5.0 CVE-2022-20195 In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial o… Android Mitigation only Fix from $1,6002022-06-15 HIGH 7.0 CVE-2021-35095 Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same… Ar8035 Firmware Patch available Fix from $1,9502022-06-14 CRITICAL 9.8 CVE-2022-25845EPSS 19% The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restric… Fastjson 1.2.83+ Fix from $2,3002022-06-10 CRITICAL 9.8 CVE-2022-25863 The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input thro… Gatsby 2.14.1 / 3.15.2+ Fix from $2,3002022-06-10 CRITICAL 9.8 CVE-2022-1660EPSS 17% The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker… N6854a Firmware 2.4.0+ Fix from $2,3002022-06-02 CRITICAL 9.8 CVE-2022-29875 A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA… Biograph Horizon Pet\/ct Systems Firmware Mitigation only Fix from $2,3002022-06-01 CRITICAL 9.8 CVE-2021-32935 The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker… In Sight Opc Server after 5.7.4_ Fix from $2,3002022-05-23 HIGH 7.5 CVE-2022-28948 An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input. Yaml Patch available Fix from $1,9502022-05-19 HIGH 7.8 CVE-2022-1118EPSS 11% Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and pr… Connected Component Workbench after 13.00.00 Fix from $1,9502022-05-17 CRITICAL 9.8 CVE-2022-24108EPSS 33% The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potenti… So Listing Tabs No fix yet Fix from $2,3002022-05-17 HIGH 8.8 CVE-2022-0573 JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation … Artifactory 6.23.41 / 7.17.16+ Fix from $1,9502022-05-16 CRITICAL 9.8 CVE-2022-29363 Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows atta… Phpok No fix yet Fix from $2,3002022-05-12 HIGH 8.8 CVE-2022-1463 The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and includ… Booking Calendar after 9.1 Fix from $1,9502022-05-10 CRITICAL 9.8 CVE-2021-23592 The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver cla… Thinkphp 6.0.12+ Fix from $2,3002022-05-06 CRITICAL 9.8 CVE-2020-23620 The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of us… Orlansoft Erp Mitigation only Fix from $2,3002022-05-02