Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-44677
An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…
Enterprise Vault
after 14.1.2
CRITICAL 9.8
CVE-2021-44678
An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…
Enterprise Vault
after 14.1.2
CRITICAL 9.8
CVE-2021-44679
An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…
Enterprise Vault
after 14.1.2
CRITICAL 9.8
CVE-2021-36564
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapte…
Thinkphp
No fix yet
CRITICAL 9.8
CVE-2021-36567
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
Thinkphp
No fix yet
CRITICAL 9.8
CVE-2021-23758EPSS 89%
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET cla…
Ajaxpro.2
21.10.30.1+
HIGH 8.8
CVE-2021-43360
Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authen…
Ehrd
Mitigation only
MEDIUM 6.5
CVE-2021-22095
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object …
Spring Advanced Message Queuing Protocol
2.2.19 / 2.3.11+
HIGH 8.8
CVE-2021-34992
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required t…
C1 Cms
Patch available
HIGH 7.5
CVE-2021-26558
Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa…
Shardingsphere Ui
5.0.0+
HIGH 7.8
CVE-2021-42698
Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the origin…
Daqfactory
after 18.1
CRITICAL 9.8
CVE-2021-42237 KEVEPSS 98%
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot…
Experience Platform
Mitigation only
MEDIUM 6.5
CVE-2021-22097
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a me…
Spring Advanced Message Queuing Protocol
after 2.3.10
CRITICAL 10.0
CVE-2019-19810
Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attac…
Call Recording
Mitigation only
HIGH 7.8
CVE-2021-41078
Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.
Nameko
after 2.13.0
CRITICAL 9.8
CVE-2021-40865EPSS 66%
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (…
Storm
1.2.4 / 2.1.1+
CRITICAL 9.8
CVE-2021-40719
Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation wh…
Connect
after 11.2.3
HIGH 8.8
CVE-2021-39321
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action…
Sassy Social Share
Patch available
HIGH 7.8
CVE-2021-35227
The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.
Access Rights Manager
after 2020.2.6
CRITICAL 9.8
CVE-2021-40720EPSS 10%
Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the che…
Ops Cli
2.0.5+
HIGH 7.3
CVE-2021-40843
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the…
Insider Threat Management Server
7.11.2+
HIGH 7.2
CVE-2021-33728
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deser…
Sinec Nms
1.0+
MEDIUM 6.7
CVE-2021-25738
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
Java
11.0.1+
CRITICAL 9.8
CVE-2021-42090
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
Zammad
4.1.1+
HIGH 8.1
CVE-2021-41129
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati…
Panel
1.6.2+
HIGH 7.8
CVE-2021-0685
In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This c…
Android
Patch available
CRITICAL 9.8
CVE-2021-41110
cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted D…
Cwlviewer
1.3.1+
CRITICAL 9.8
CVE-2021-41616
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…
Ddlutils
Mitigation only
CRITICAL 9.1
CVE-2021-40102
An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection ass…
Concrete Cms
after 8.5.5
HIGH 8.1
CVE-2021-41588
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…
Gradle
2021.1.3+