Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2021-21243EPSS 54% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted da… Onedev 4.0.3+ Fix from $2,3002021-01-15 CRITICAL 9.8 CVE-2020-24639EPSS 7% There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airw… Airwave Glass 1.3.3+ Fix from $2,3002021-01-15 CRITICAL 9.8 CVE-2020-23653 An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/con… Thinkadmin after 6.0 Fix from $2,3002021-01-13 HIGH 8.0 CVE-2021-21604 Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content … Jenkins after 2.274 Fix from $1,9502021-01-13 HIGH 8.8 CVE-2020-26118 In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vu… Collaborator after 13.3.13302 Fix from $1,9502021-01-11 CRITICAL 9.8 CVE-2020-11995EPSS 6% A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use H… Dubbo after 2.7.7 Fix from $2,3002021-01-11 HIGH 8.1 CVE-2020-36183 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36179EPSS 21% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common… Debian Linux Patch available Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36180EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux Patch available Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36182EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36184EPSS 10% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux Patch available Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36185EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36186EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36187EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36188EPSS 11% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36189 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36181EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux Patch available Fix from $1,9502021-01-06 CRITICAL 9.8 CVE-2020-10655 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri… Insider Threat Management Server 7.9.1+ Fix from $2,3002021-01-06 CRITICAL 9.8 CVE-2020-10656 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri… Insider Threat Management Server 7.9.1+ Fix from $2,3002021-01-06 HIGH 7.2 CVE-2020-10657 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAler… Insider Threat Management Server 7.9.1+ Fix from $1,9502021-01-06 CRITICAL 9.8 CVE-2020-10658 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri… Insider Threat Management Server 7.9.1+ Fix from $2,3002021-01-06 HIGH 8.8 CVE-2020-8884 rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to e… Insider Threat Management 7.4.2 / 7.5.3+ Fix from $1,9502021-01-06 HIGH 8.8 CVE-2019-4728 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute… Sterling B2b Integrator after 6.0.3.2 Fix from $1,9502021-01-05 HIGH 7.5 CVE-2020-35488EPSS 8% The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a… Nxlog 3.0.2272+ Fix from $1,9502021-01-05 CRITICAL 9.8 CVE-2021-3007EPSS 75% Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if t… Laminas Http 2.14.2+ Fix from $2,3002021-01-04 HIGH 8.8 CVE-2020-35932 Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as s… Newsletter 6.8.2+ Fix from $1,9502021-01-01 HIGH 8.8 CVE-2020-35938 PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP… Post Grid 1.22.16 / 2.0.73+ Fix from $1,9502021-01-01 HIGH 8.8 CVE-2020-35939 PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrar… Post Grid 1.22.16 / 2.0.73+ Fix from $1,9502021-01-01 HIGH 8.8 CVE-2020-26165 qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php beca… Qdpm after 9.1 Fix from $1,9502020-12-31 CRITICAL 9.8 CVE-2019-7725 includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization forma… Nukeviet 4.3.04+ Fix from $2,3002020-12-31