Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.6
CVE-2021-21371
Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the …
Jira Cloud
1.1.21+
MEDIUM 6.5
CVE-2021-21488
Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w…
Netweaver Knowledge Management
Mitigation only
CRITICAL 9.8
CVE-2020-24914EPSS 5%
A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileDa…
Qcubed
after 3.1.1
HIGH 8.8
CVE-2020-24036
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
Fork Cms
5.8.3+
CRITICAL 9.8
CVE-2020-29047EPSS 16%
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the…
Wp Hotel Booking
after 1.10.2
HIGH 8.8
CVE-2021-20076
Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged u…
Tenable.sc
after 5.17.0
HIGH 7.8
CVE-2021-26857 KEVEPSS 96%
Microsoft Exchange Server Remote Code Execution Vulnerability
Exchange Server
Patch available
HIGH 8.8
CVE-2021-24066EPSS 6%
Microsoft SharePoint Remote Code Execution Vulnerability
Sharepoint Enterprise Server
Patch available
CRITICAL 9.8
CVE-2021-27335
KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections…
Kollect
4.8.16c+
CRITICAL 9.8
CVE-2021-22855
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized object…
Hr Portal
Mitigation only
HIGH 7.2
CVE-2021-23338
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
Qlib
Patch available
CRITICAL 9.8
CVE-2021-27213
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.
Pystemon
2021-02-13+
CRITICAL 9.8
CVE-2020-27868EPSS 81%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not r…
Ocularis
Mitigation only
HIGH 8.1
CVE-2021-26912EPSS 41%
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…
Netmotion Mobility
11.73 / 12.02+
HIGH 8.1
CVE-2021-26913EPSS 13%
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…
Netmotion Mobility
11.73 / 12.02+
HIGH 8.1
CVE-2021-26914EPSS 78%
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…
Netmotion Mobility
11.73 / 12.02+
HIGH 8.1
CVE-2021-26915EPSS 42%
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des…
Netmotion Mobility
11.73 / 12.02+
CRITICAL 9.8
CVE-2021-25274EPSS 36%
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…
Orion Platform
2020.2.4+
HIGH 7.8
CVE-2021-25758
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
Intellij Idea
2020.3+
CRITICAL 9.8
CVE-2021-3160
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to i…
Assuweb
Mitigation only
CRITICAL 9.8
CVE-2020-4682EPSS 8%
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…
Mq
Patch available
HIGH 8.8
CVE-2020-4888EPSS 62%
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused b…
Qradar Security Information And Event Manager
Patch available
CRITICAL 9.8
CVE-2020-27583
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec…
Infosphere Information Server
No fix yet
HIGH 8.8
CVE-2020-17532
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The…
Java Chassis
2.1.5+
HIGH 7.8
CVE-2020-12525
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data …
Rosemount Transmitter Interface Software
3.5 / 4.5+
HIGH 8.1
CVE-2021-20190EPSS 7%
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest thre…
Active Iq Unified Manager
2.6.7.5 / 2.9.10.7+
CRITICAL 9.8
CVE-2021-25294EPSS 11%
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php …
Opencats
after 0.9.5-3
CRITICAL 9.8
CVE-2021-21242EPSS 74%
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exe…
Onedev
4.0.3+
HIGH 8.8
CVE-2021-21247
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj…
Onedev
4.0.3+
HIGH 8.8
CVE-2021-21249
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote …
Onedev
4.0.3+