Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.5 CVE-2021-39145 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39146EPSS 14% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39147 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39148 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39149 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39151 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2021-39139 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 7.8 CVE-2021-21867 An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Develo… Codesys Patch available Fix from $1,9502021-08-18 HIGH 7.8 CVE-2021-21868 An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Developme… Codesys Patch available Fix from $1,9502021-08-18 HIGH 8.8 CVE-2021-37678 TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary … Tensorflow 2.3.4 / 2.4.3+ Fix from $1,9502021-08-12 HIGH 7.2 CVE-2021-38585 The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585). Cpanel 98.0.1+ Fix from $1,9502021-08-11 CRITICAL 9.8 CVE-2021-23420 This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run… Codeception 3.1.3 / 4.1.22+ Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2021-37544 In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. Teamcity 2020.2.4+ Fix from $2,3002021-08-06 HIGH 8.1 CVE-2021-37632 SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn642's Config Lib between 1.0.4… Config Lib 1.0.9+ Fix from $1,9502021-08-05 CRITICAL 9.8 CVE-2021-34371EPSS 13% Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVaria… Neo4j after 3.4.18 Fix from $2,3002021-08-05 HIGH 7.8 CVE-2021-21863 A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.1… Development System Patch available Fix from $1,9502021-08-05 HIGH 8.8 CVE-2021-36483 DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization. Devexpress after 21.1 Fix from $1,9502021-08-04 HIGH 7.8 CVE-2021-21866 A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Develo… Development System Patch available Fix from $1,9502021-08-02 HIGH 7.8 CVE-2021-21864 A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Dev… Development System Patch available Fix from $1,9502021-08-02 HIGH 7.8 CVE-2021-21865 A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Developm… Development System Patch available Fix from $1,9502021-08-02 HIGH 7.2 CVE-2021-36766 Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/l… Concrete Cms 8.5.6+ Fix from $1,9502021-07-30 CRITICAL 9.8 CVE-2021-29781 IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. B… Partner Engagement Manager Patch available Fix from $2,3002021-07-30 CRITICAL 9.8 CVE-2021-37578 Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo… Juddi 3.3.10+ Fix from $2,3002021-07-29 CRITICAL 9.8 CVE-2020-5341 Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data… Emc Avamar Server Patch available Fix from $2,3002021-07-28 CRITICAL 9.8 CVE-2021-35464 KEVEPSS 100% ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does no… Access Management 6.5.4 / 14.6.3+ Fix from $2,3002021-07-22 HIGH 7.8 CVE-2021-22777 A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file. Sosafe Configurable 1.8.1+ Fix from $1,9502021-07-21 HIGH 8.1 CVE-2021-34520 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Foundation Patch available Fix from $1,9502021-07-14 CRITICAL 9.1 CVE-2021-32742 Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens up the potential for exposing… Vapor 4.47.2+ Fix from $2,3002021-07-09 HIGH 7.2 CVE-2021-29150 A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba … Clearpass Policy Manager 6.8.9 / 6.9.6+ Fix from $1,9502021-07-08 CRITICAL 9.8 CVE-2021-24384 The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unse… Joomsport 5.1.8+ Fix from $2,3002021-07-06