Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2022-24289 Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur… Cayenne 4.2+ Fix from $1,9502022-02-11 HIGH 8.8 CVE-2022-22005EPSS 17% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Enterprise Server No fix yet Fix from $1,9502022-02-09 HIGH 7.5 CVE-2022-0538 Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vuln… Jenkins 2.319.3 / 2.334+ Fix from $1,9502022-02-09 HIGH 8.1 CVE-2021-42631EPSS 6% PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution. Virtual Appliance 19.1.1.13+ Fix from $1,9502022-01-31 CRITICAL 9.8 CVE-2021-45899 SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. Suitecrm 7.12.3 / 8.0.2+ Fix from $2,3002022-01-28 HIGH 8.1 CVE-2021-41766 Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology… Karaf 4.3.6+ Fix from $1,9502022-01-26 MEDIUM 5.3 CVE-2022-21341 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that … Debian Linux after 15.0.5 Fix from $1,6002022-01-19 HIGH 8.8 CVE-2022-23302EPSS 64% JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration… Log4j 1.2.18.1+ Fix from $1,9502022-01-18 HIGH 8.8 CVE-2022-23307EPSS 54% CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j… Chainsaw 1.2.18.1 / 2.0+ Fix from $1,9502022-01-18 HIGH 8.8 CVE-2021-45394 An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <lin… Html2pdf 5.2.4+ Fix from $1,9502022-01-18 CRITICAL 9.8 CVE-2021-43297EPSS 17% A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub… Dubbo 2.6.12 / 2.7.15+ Fix from $2,3002022-01-10 CRITICAL 9.8 CVE-2021-42392EPSS 63% The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack… Debian Linux after 2.0.204 Fix from $2,3002022-01-10 HIGH 7.2 CVE-2022-21663 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm… WordPress 5.8.3+ Fix from $1,9502022-01-06 CRITICAL 9.8 CVE-2022-21647EPSS 38% CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remo… Codeigniter 4.1.6+ Fix from $2,3002022-01-04 HIGH 7.2 CVE-2021-20318 The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502021-12-23 HIGH 7.8 CVE-2021-4118 pytorch-lightning is vulnerable to Deserialization of Untrusted Data Pytorch Lightning 1.6.0+ Fix from $1,9502021-12-23 MEDIUM 5.4 CVE-2021-43853 Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript … Ajax.net Professional 21.12.22.1+ Fix from $1,6002021-12-22 CRITICAL 9.8 CVE-2021-44029 An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserializa… Kace Desktop Authority 11.2+ Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2021-36336 Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code o… Wyse Management Suite after 3.3.1 Fix from $2,3002021-12-21 MEDIUM 6.6 CVE-2021-42550 In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat… Satellite 1.0.3+ Fix from $1,6002021-12-16 HIGH 7.8 CVE-2021-0970 In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalat… Android Patch available Fix from $1,9502021-12-15 HIGH 7.5 CVE-2021-4104EPSS 81% JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack… Log4j Patch available Fix from $1,9502021-12-14 CRITICAL 9.8 CVE-2021-24857 The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object inje… Totop Link after 1.7.1 Fix from $2,3002021-12-13 CRITICAL 10.0 CVE-2021-44228 KEVEPSS 100% Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… Log4j 2.1.0 / 2.3.1+ Fix from $2,3002021-12-10 HIGH 8.8 CVE-2021-42125EPSS 82% An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dan… Avalanche 6.3.3+ Fix from $1,9502021-12-07 CRITICAL 9.8 CVE-2021-42127EPSS 66% A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via … Avalanche 6.3.3+ Fix from $2,3002021-12-07 HIGH 8.8 CVE-2021-42130EPSS 62% A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to p… Avalanche 6.3.3+ Fix from $1,9502021-12-07 CRITICAL 9.8 CVE-2021-44680 An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th… Enterprise Vault after 14.1.2 Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-44681 An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th… Enterprise Vault after 14.1.2 Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-44682 An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th… Enterprise Vault after 14.1.2 Fix from $2,3002021-12-06