Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-24289
Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur…
Cayenne
4.2+
HIGH 8.8
CVE-2022-22005EPSS 17%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Enterprise Server
No fix yet
HIGH 7.5
CVE-2022-0538
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vuln…
Jenkins
2.319.3 / 2.334+
HIGH 8.1
CVE-2021-42631EPSS 6%
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
Virtual Appliance
19.1.1.13+
CRITICAL 9.8
CVE-2021-45899
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
Suitecrm
7.12.3 / 8.0.2+
HIGH 8.1
CVE-2021-41766
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…
Karaf
4.3.6+
MEDIUM 5.3
CVE-2022-21341
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that …
Debian Linux
after 15.0.5
HIGH 8.8
CVE-2022-23302EPSS 64%
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration…
Log4j
1.2.18.1+
HIGH 8.8
CVE-2022-23307EPSS 54%
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j…
Chainsaw
1.2.18.1 / 2.0+
HIGH 8.8
CVE-2021-45394
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <lin…
Html2pdf
5.2.4+
CRITICAL 9.8
CVE-2021-43297EPSS 17%
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…
Dubbo
2.6.12 / 2.7.15+
CRITICAL 9.8
CVE-2021-42392EPSS 63%
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack…
Debian Linux
after 2.0.204
HIGH 7.2
CVE-2022-21663
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm…
WordPress
5.8.3+
CRITICAL 9.8
CVE-2022-21647EPSS 38%
CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remo…
Codeigniter
4.1.6+
HIGH 7.2
CVE-2021-20318
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary …
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.8
CVE-2021-4118
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
Pytorch Lightning
1.6.0+
MEDIUM 5.4
CVE-2021-43853
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript …
Ajax.net Professional
21.12.22.1+
CRITICAL 9.8
CVE-2021-44029
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserializa…
Kace Desktop Authority
11.2+
CRITICAL 9.8
CVE-2021-36336
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code o…
Wyse Management Suite
after 3.3.1
MEDIUM 6.6
CVE-2021-42550
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat…
Satellite
1.0.3+
HIGH 7.8
CVE-2021-0970
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalat…
Android
Patch available
HIGH 7.5
CVE-2021-4104EPSS 81%
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack…
Log4j
Patch available
CRITICAL 9.8
CVE-2021-24857
The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object inje…
Totop Link
after 1.7.1
CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…
Log4j
2.1.0 / 2.3.1+
HIGH 8.8
CVE-2021-42125EPSS 82%
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dan…
Avalanche
6.3.3+
CRITICAL 9.8
CVE-2021-42127EPSS 66%
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via …
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42130EPSS 62%
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to p…
Avalanche
6.3.3+
CRITICAL 9.8
CVE-2021-44680
An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…
Enterprise Vault
after 14.1.2
CRITICAL 9.8
CVE-2021-44681
An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…
Enterprise Vault
after 14.1.2
CRITICAL 9.8
CVE-2021-44682
An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…
Enterprise Vault
after 14.1.2