Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-21243EPSS 54%
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted da…
Onedev
4.0.3+
CRITICAL 9.8
CVE-2020-24639EPSS 7%
There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airw…
Airwave Glass
1.3.3+
CRITICAL 9.8
CVE-2020-23653
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/con…
Thinkadmin
after 6.0
HIGH 8.0
CVE-2021-21604
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content …
Jenkins
after 2.274
HIGH 8.8
CVE-2020-26118
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vu…
Collaborator
after 13.3.13302
CRITICAL 9.8
CVE-2020-11995EPSS 6%
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H…
Dubbo
after 2.7.7
HIGH 8.1
CVE-2020-36183
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.…
Debian Linux
2.6.7.5 / 2.9.10.8+
HIGH 8.1
CVE-2020-36179EPSS 21%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common…
Debian Linux
Patch available
HIGH 8.1
CVE-2020-36180EPSS 5%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…
Debian Linux
Patch available
HIGH 8.1
CVE-2020-36182EPSS 5%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…
Debian Linux
2.6.7.5 / 2.9.10.8+
HIGH 8.1
CVE-2020-36184EPSS 10%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…
Debian Linux
Patch available
HIGH 8.1
CVE-2020-36185EPSS 5%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…
Debian Linux
2.6.7.5 / 2.9.10.8+
HIGH 8.1
CVE-2020-36186EPSS 5%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…
Debian Linux
2.6.7.5 / 2.9.10.8+
HIGH 8.1
CVE-2020-36187EPSS 5%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…
Debian Linux
2.6.7.5 / 2.9.10.8+
HIGH 8.1
CVE-2020-36188EPSS 11%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…
Debian Linux
2.6.7.5 / 2.9.10.8+
HIGH 8.1
CVE-2020-36189
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…
Debian Linux
2.6.7.5 / 2.9.10.8+
HIGH 8.1
CVE-2020-36181EPSS 5%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2020-10655
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…
Insider Threat Management Server
7.9.1+
CRITICAL 9.8
CVE-2020-10656
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…
Insider Threat Management Server
7.9.1+
HIGH 7.2
CVE-2020-10657
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAler…
Insider Threat Management Server
7.9.1+
CRITICAL 9.8
CVE-2020-10658
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…
Insider Threat Management Server
7.9.1+
HIGH 8.8
CVE-2020-8884
rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to e…
Insider Threat Management
7.4.2 / 7.5.3+
HIGH 8.8
CVE-2019-4728
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute…
Sterling B2b Integrator
after 6.0.3.2
HIGH 7.5
CVE-2020-35488EPSS 8%
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a…
Nxlog
3.0.2272+
CRITICAL 9.8
CVE-2021-3007EPSS 75%
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if t…
Laminas Http
2.14.2+
HIGH 8.8
CVE-2020-35932
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as s…
Newsletter
6.8.2+
HIGH 8.8
CVE-2020-35938
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP…
Post Grid
1.22.16 / 2.0.73+
HIGH 8.8
CVE-2020-35939
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrar…
Post Grid
1.22.16 / 2.0.73+
HIGH 8.8
CVE-2020-26165
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php beca…
Qdpm
after 9.1
CRITICAL 9.8
CVE-2019-7725
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization forma…
Nukeviet
4.3.04+