Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2021-35971 Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remo… Veeam Backup \& Replication 10.0.1.4854 / 11.0.0.837+ Fix from $2,3002021-06-30 HIGH 8.1 CVE-2021-22439 There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability.… Anyoffice Mitigation only Fix from $1,9502021-06-29 HIGH 8.8 CVE-2021-29485 Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a ma… Ratpack 1.9.0+ Fix from $1,9502021-06-29 CRITICAL 9.8 CVE-2021-31649 In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute Jfinal after 4.9.08 Fix from $2,3002021-06-24 MEDIUM 6.7 CVE-2021-34394 Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker… Jetson Linux 32.5.1+ Fix from $1,6002021-06-22 HIGH 7.8 CVE-2021-35196 Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is in… Manuskript after 0.12.0 Fix from $1,9502021-06-21 CRITICAL 9.8 CVE-2020-9493 A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. Chainsaw 1.2.18.1 / 2.0+ Fix from $2,3002021-06-16 HIGH 7.2 CVE-2021-3040 An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform f… Bridgecrew Checkov 2.0.139+ Fix from $1,9502021-06-10 HIGH 7.5 CVE-2021-33175 EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of … Emq X Broker 4.2.8+ Fix from $1,9502021-06-08 HIGH 7.5 CVE-2021-33176 VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the hand… Vernemq 1.12.0+ Fix from $1,9502021-06-08 HIGH 8.1 CVE-2021-33898 In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to… Invoice Ninja 4.4.0+ Fix from $1,9502021-06-06 CRITICAL 9.8 CVE-2021-33806 The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObj… Bdlib 1.16.1.7+ Fix from $2,3002021-06-03 HIGH 8.0 CVE-2021-23895 Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a… Database Security 4.8.2+ Fix from $1,9502021-06-02 HIGH 8.8 CVE-2021-23894 Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create… Database Security 4.8.2+ Fix from $1,9502021-06-02 CRITICAL 9.8 CVE-2021-25641EPSS 21% Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before… Dubbo 2.6.9 / 2.7.8+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-30179 Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha… Dubbo 2.6.9 / 2.7.10+ Fix from $2,3002021-06-01 CRITICAL 9.8 CVE-2021-33790 The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of re… Reborncore 3.19.5 / 4.2.10+ Fix from $2,3002021-05-31 HIGH 8.8 CVE-2021-29505EPSS 77% XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack… Debian Linux 1.4.17+ Fix from $1,9502021-05-28 CRITICAL 9.8 CVE-2021-27852 KEVEPSS 32% Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary … Survey 7.0+ Fix from $2,3002021-05-27 CRITICAL 9.8 CVE-2021-32075 Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization. Terraria 1.4.2.3+ Fix from $2,3002021-05-24 HIGH 8.8 CVE-2021-24307EPSS 53% The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_setti… All In One Seo 4.1.0.2+ Fix from $1,9502021-05-24 HIGH 7.2 CVE-2021-32634 Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated… Emissary Patch available Fix from $1,9502021-05-21 CRITICAL 9.8 CVE-2021-31474EPSS 94% This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Au… Network Performance Monitor 2020.2.5+ Fix from $2,3002021-05-21 HIGH 8.8 CVE-2021-24280 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJ… Redirection For Contact Form 7 2.3.4+ Fix from $1,9502021-05-14 CRITICAL 9.8 CVE-2021-33026EPSS 7% The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege e… Flask Caching after 1.10.1 Fix from $2,3002021-05-13 CRITICAL 9.1 CVE-2021-29508 Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on t… Wire No fix yet Fix from $2,3002021-05-11 CRITICAL 9.8 CVE-2021-32098 Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization. Pandora Fms No fix yet Fix from $2,3002021-05-07 HIGH 7.2 CVE-2021-25152 A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released … Airwave 8.2.12.1+ Fix from $1,9502021-04-28 HIGH 8.8 CVE-2021-25151EPSS 12% A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released … Airwave 8.2.12.1+ Fix from $1,9502021-04-28 CRITICAL 9.8 CVE-2020-36326 PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV… WordPress 3.7.36 / 3.8.36+ Fix from $2,3002021-04-28