Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-35971
Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remo…
Veeam Backup \& Replication
10.0.1.4854 / 11.0.0.837+
HIGH 8.1
CVE-2021-22439
There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability.…
Anyoffice
Mitigation only
HIGH 8.8
CVE-2021-29485
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a ma…
Ratpack
1.9.0+
CRITICAL 9.8
CVE-2021-31649
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
Jfinal
after 4.9.08
MEDIUM 6.7
CVE-2021-34394
Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker…
Jetson Linux
32.5.1+
HIGH 7.8
CVE-2021-35196
Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is in…
Manuskript
after 0.12.0
CRITICAL 9.8
CVE-2020-9493
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.
Chainsaw
1.2.18.1 / 2.0+
HIGH 7.2
CVE-2021-3040
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform f…
Bridgecrew Checkov
2.0.139+
HIGH 7.5
CVE-2021-33175
EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of …
Emq X Broker
4.2.8+
HIGH 7.5
CVE-2021-33176
VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the hand…
Vernemq
1.12.0+
HIGH 8.1
CVE-2021-33898
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to…
Invoice Ninja
4.4.0+
CRITICAL 9.8
CVE-2021-33806
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObj…
Bdlib
1.16.1.7+
HIGH 8.0
CVE-2021-23895
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a…
Database Security
4.8.2+
HIGH 8.8
CVE-2021-23894
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create…
Database Security
4.8.2+
CRITICAL 9.8
CVE-2021-25641EPSS 21%
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before…
Dubbo
2.6.9 / 2.7.8+
CRITICAL 9.8
CVE-2021-30179
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha…
Dubbo
2.6.9 / 2.7.10+
CRITICAL 9.8
CVE-2021-33790
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of re…
Reborncore
3.19.5 / 4.2.10+
HIGH 8.8
CVE-2021-29505EPSS 77%
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack…
Debian Linux
1.4.17+
CRITICAL 9.8
CVE-2021-27852 KEVEPSS 32%
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary …
Survey
7.0+
CRITICAL 9.8
CVE-2021-32075
Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
Terraria
1.4.2.3+
HIGH 8.8
CVE-2021-24307EPSS 53%
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_setti…
All In One Seo
4.1.0.2+
HIGH 7.2
CVE-2021-32634
Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated…
Emissary
Patch available
CRITICAL 9.8
CVE-2021-31474EPSS 94%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Au…
Network Performance Monitor
2020.2.5+
HIGH 8.8
CVE-2021-24280
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJ…
Redirection For Contact Form 7
2.3.4+
CRITICAL 9.8
CVE-2021-33026EPSS 7%
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege e…
Flask Caching
after 1.10.1
CRITICAL 9.1
CVE-2021-29508
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on t…
Wire
No fix yet
CRITICAL 9.8
CVE-2021-32098
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
Pandora Fms
No fix yet
HIGH 7.2
CVE-2021-25152
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released …
Airwave
8.2.12.1+
HIGH 8.8
CVE-2021-25151EPSS 12%
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released …
Airwave
8.2.12.1+
CRITICAL 9.8
CVE-2020-36326
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV…
WordPress
3.7.36 / 3.8.36+