Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2020-23621 The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserializ… Svi Ms Management System Mitigation only Fix from $2,3002022-05-02 HIGH 7.5 CVE-2022-25647EPSS 12% The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal clas… Debian Linux 2.8.9+ Fix from $1,9502022-05-01 CRITICAL 9.8 CVE-2022-25767 All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, caus… Ureport2 No fix yet Fix from $2,3002022-05-01 HIGH 8.8 CVE-2022-29936 USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-f… Oracle Optimization No fix yet Fix from $1,9502022-04-29 CRITICAL 9.8 CVE-2022-29528 An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur. Misp 2.4.158+ Fix from $2,3002022-04-20 CRITICAL 9.8 CVE-2022-26133EPSS 70% SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 … Bitbucket Data Center 7.6.14 / 7.17.6+ Fix from $2,3002022-04-20 CRITICAL 9.8 CVE-2022-21445 KEVEPSS 62% Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t… Application Development Framework Mitigation only Fix from $2,3002022-04-19 CRITICAL 9.8 CVE-2022-27158 pearweb < 1.32 suffers from Deserialization of Untrusted Data. Pearweb 1.32.0+ Fix from $2,3002022-04-15 HIGH 7.2 CVE-2022-24846 GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn ca… Geowebcache 1.19.3 / 1.20.2+ Fix from $1,9502022-04-14 HIGH 7.8 CVE-2021-21956 A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead… Imunify360 No fix yet Fix from $1,9502022-04-14 HIGH 7.2 CVE-2022-22957EPSS 23% VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22… Cloud Foundation 5.0 / 9.0+ Fix from $1,9502022-04-13 HIGH 7.2 CVE-2022-22958 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22… Cloud Foundation 5.0 / 9.0+ Fix from $1,9502022-04-13 HIGH 7.8 CVE-2019-6834 A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with… Software Update after 2.3.0 Fix from $1,9502022-04-13 CRITICAL 9.8 CVE-2022-23450EPSS 36% A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 U… Simatic Energy Manager Basic 7.3+ Fix from $2,3002022-04-12 HIGH 8.8 CVE-2022-20763 A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java … Webex Meetings Online Mitigation only Fix from $1,9502022-04-06 CRITICAL 9.8 CVE-2020-19229 Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an at… Jeesite No fix yet Fix from $2,3002022-04-05 CRITICAL 9.8 CVE-2021-33207 The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code. Mashzone Nextgen after 10.7 Fix from $2,3002022-04-05 HIGH 7.2 CVE-2022-1032 Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. Crater 6.0.6+ Fix from $1,9502022-03-29 HIGH 8.6 CVE-2021-27475 Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows… Connected Components Workbench after 12.00.00 Fix from $1,9502022-03-23 CRITICAL 9.8 CVE-2021-27460 Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without suf… Factorytalk Assetcentre after 10.00 Fix from $2,3002022-03-23 CRITICAL 9.8 CVE-2021-27462 A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s… Factorytalk Assetcentre after 10.00 Fix from $2,3002022-03-23 CRITICAL 9.8 CVE-2021-27466 A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifi… Factorytalk Assetcentre after 10.00 Fix from $2,3002022-03-23 CRITICAL 9.8 CVE-2021-27470 A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s… Factorytalk Assetcentre after 10.00 Fix from $2,3002022-03-23 HIGH 7.8 CVE-2022-26503 Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local s… Veeam 4.0.2.2208 / 5.0.3.4708+ Fix from $1,9502022-03-17 CRITICAL 9.8 CVE-2022-0749 This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the user-controllable input afte… Singoocms.utility No fix yet Fix from $2,3002022-03-17 HIGH 8.8 CVE-2022-23940EPSS 53% SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achie… Suitecrm 7.12.5 / 8.0.4+ Fix from $1,9502022-03-10 HIGH 7.2 CVE-2022-24282 A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions)… Sinec Network Management System Mitigation only Fix from $1,9502022-03-08 HIGH 7.2 CVE-2022-21828 A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified … Incapptic Connect No fix yet Fix from $1,9502022-03-04 HIGH 7.5 CVE-2022-0138 MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has … Mimosa Management Platform 1.0.3 / 2.5.4.1+ Fix from $1,9502022-02-18 HIGH 7.8 CVE-2021-46364 A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file. Magnolia Cms 6.2.4+ Fix from $1,9502022-02-11