Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.6 CVE-2021-21371 Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the … Jira Cloud 1.1.21+ Fix from $1,9502021-03-10 MEDIUM 6.5 CVE-2021-21488 Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w… Netweaver Knowledge Management Mitigation only Fix from $1,6002021-03-09 CRITICAL 9.8 CVE-2020-24914EPSS 5% A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileDa… Qcubed after 3.1.1 Fix from $2,3002021-03-04 HIGH 8.8 CVE-2020-24036 PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code. Fork Cms 5.8.3+ Fix from $1,9502021-03-04 CRITICAL 9.8 CVE-2020-29047EPSS 16% The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the… Wp Hotel Booking after 1.10.2 Fix from $2,3002021-03-03 HIGH 8.8 CVE-2021-20076 Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged u… Tenable.sc after 5.17.0 Fix from $1,9502021-03-03 HIGH 7.8 CVE-2021-26857 KEVEPSS 96% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502021-03-03 HIGH 8.8 CVE-2021-24066EPSS 6% Microsoft SharePoint Remote Code Execution Vulnerability Sharepoint Enterprise Server Patch available Fix from $1,9502021-02-25 CRITICAL 9.8 CVE-2021-27335 KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections… Kollect 4.8.16c+ Fix from $2,3002021-02-18 CRITICAL 9.8 CVE-2021-22855 The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized object… Hr Portal Mitigation only Fix from $2,3002021-02-17 HIGH 7.2 CVE-2021-23338 This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function. Qlib Patch available Fix from $1,9502021-02-15 CRITICAL 9.8 CVE-2021-27213 config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used. Pystemon 2021-02-13+ Fix from $2,3002021-02-14 CRITICAL 9.8 CVE-2020-27868EPSS 81% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not r… Ocularis Mitigation only Fix from $2,3002021-02-12 HIGH 8.1 CVE-2021-26912EPSS 41% NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des… Netmotion Mobility 11.73 / 12.02+ Fix from $1,9502021-02-08 HIGH 8.1 CVE-2021-26913EPSS 13% NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des… Netmotion Mobility 11.73 / 12.02+ Fix from $1,9502021-02-08 HIGH 8.1 CVE-2021-26914EPSS 78% NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des… Netmotion Mobility 11.73 / 12.02+ Fix from $1,9502021-02-08 HIGH 8.1 CVE-2021-26915EPSS 42% NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java des… Netmotion Mobility 11.73 / 12.02+ Fix from $1,9502021-02-08 CRITICAL 9.8 CVE-2021-25274EPSS 36% The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que… Orion Platform 2020.2.4+ Fix from $2,3002021-02-03 HIGH 7.8 CVE-2021-25758 In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution. Intellij Idea 2020.3+ Fix from $1,9502021-02-03 CRITICAL 9.8 CVE-2021-3160 Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to i… Assuweb Mitigation only Fix from $2,3002021-01-28 CRITICAL 9.8 CVE-2020-4682EPSS 8% IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa… Mq Patch available Fix from $2,3002021-01-28 HIGH 8.8 CVE-2020-4888EPSS 62% IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused b… Qradar Security Information And Event Manager Patch available Fix from $1,9502021-01-28 CRITICAL 9.8 CVE-2020-27583 IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to exec… Infosphere Information Server No fix yet Fix from $2,3002021-01-26 HIGH 8.8 CVE-2020-17532 When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The… Java Chassis 2.1.5+ Fix from $1,9502021-01-25 HIGH 7.8 CVE-2020-12525 M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data … Rosemount Transmitter Interface Software 3.5 / 4.5+ Fix from $1,9502021-01-22 HIGH 8.1 CVE-2021-20190EPSS 7% A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest thre… Active Iq Unified Manager 2.6.7.5 / 2.9.10.7+ Fix from $1,9502021-01-19 CRITICAL 9.8 CVE-2021-25294EPSS 11% OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php … Opencats after 0.9.5-3 Fix from $2,3002021-01-18 CRITICAL 9.8 CVE-2021-21242EPSS 74% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exe… Onedev 4.0.3+ Fix from $2,3002021-01-15 HIGH 8.8 CVE-2021-21247 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj… Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 8.8 CVE-2021-21249 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote … Onedev 4.0.3+ Fix from $1,9502021-01-15