Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2021-44677 An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th… Enterprise Vault after 14.1.2 Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-44678 An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th… Enterprise Vault after 14.1.2 Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-44679 An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th… Enterprise Vault after 14.1.2 Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-36564 ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapte… Thinkphp No fix yet Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-36567 ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache. Thinkphp No fix yet Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-23758EPSS 89% All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET cla… Ajaxpro.2 21.10.30.1+ Fix from $2,3002021-12-03 HIGH 8.8 CVE-2021-43360 Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authen… Ehrd Mitigation only Fix from $1,9502021-12-01 MEDIUM 6.5 CVE-2021-22095 In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object … Spring Advanced Message Queuing Protocol 2.2.19 / 2.3.11+ Fix from $1,6002021-11-30 HIGH 8.8 CVE-2021-34992 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required t… C1 Cms Patch available Fix from $1,9502021-11-15 HIGH 7.5 CVE-2021-26558 Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa… Shardingsphere Ui 5.0.0+ Fix from $1,9502021-11-11 HIGH 7.8 CVE-2021-42698 Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the origin… Daqfactory after 18.1 Fix from $1,9502021-11-05 CRITICAL 9.8 CVE-2021-42237 KEVEPSS 98% Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot… Experience Platform Mitigation only Fix from $2,3002021-11-05 MEDIUM 6.5 CVE-2021-22097 In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a me… Spring Advanced Message Queuing Protocol after 2.3.10 Fix from $1,6002021-10-28 CRITICAL 10.0 CVE-2019-19810 Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attac… Call Recording Mitigation only Fix from $2,3002021-10-28 HIGH 7.8 CVE-2021-41078 Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file. Nameko after 2.13.0 Fix from $1,9502021-10-26 CRITICAL 9.8 CVE-2021-40865EPSS 66% An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 CRITICAL 9.8 CVE-2021-40719 Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation wh… Connect after 11.2.3 Fix from $2,3002021-10-21 HIGH 8.8 CVE-2021-39321 Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action… Sassy Social Share Patch available Fix from $1,9502021-10-21 HIGH 7.8 CVE-2021-35227 The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available. Access Rights Manager after 2020.2.6 Fix from $1,9502021-10-21 CRITICAL 9.8 CVE-2021-40720EPSS 10% Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the che… Ops Cli 2.0.5+ Fix from $2,3002021-10-15 HIGH 7.3 CVE-2021-40843 Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the… Insider Threat Management Server 7.11.2+ Fix from $1,9502021-10-13 HIGH 7.2 CVE-2021-33728 A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deser… Sinec Nms 1.0+ Fix from $1,9502021-10-12 MEDIUM 6.7 CVE-2021-25738 Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. Java 11.0.1+ Fix from $1,6002021-10-11 CRITICAL 9.8 CVE-2021-42090 An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled. Zammad 4.1.1+ Fix from $2,3002021-10-07 HIGH 8.1 CVE-2021-41129 Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati… Panel 1.6.2+ Fix from $1,9502021-10-06 HIGH 7.8 CVE-2021-0685 In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This c… Android Patch available Fix from $1,9502021-10-06 CRITICAL 9.8 CVE-2021-41110 cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted D… Cwlviewer 1.3.1+ Fix from $2,3002021-10-01 CRITICAL 9.8 CVE-2021-41616 Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR… Ddlutils Mitigation only Fix from $2,3002021-09-30 CRITICAL 9.1 CVE-2021-40102 An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection ass… Concrete Cms after 8.5.5 Fix from $2,3002021-09-24 HIGH 8.1 CVE-2021-41588 In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr… Gradle 2021.1.3+ Fix from $1,9502021-09-24