Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2020-35728EPSS 13% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502020-12-27 HIGH 8.1 CVE-2020-35490EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux 2.9.10.8+ Fix from $1,9502020-12-17 HIGH 8.1 CVE-2020-35491EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux 2.9.10.8+ Fix from $1,9502020-12-17 CRITICAL 9.8 CVE-2020-22083EPSS 6% jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been … Jsonpickle after 1.4.1 Fix from $2,3002020-12-17 CRITICAL 9.8 CVE-2020-20136 QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNam… Lean after 2.4.0.1 Fix from $2,3002020-12-14 HIGH 8.8 CVE-2020-9301 Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. T… Spinnaker 1.21.5 / 1.22.4+ Fix from $1,9502020-12-11 HIGH 8.4 CVE-2020-17144 KEVEPSS 37% Microsoft Exchange Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502020-12-10 CRITICAL 9.8 CVE-2020-17531EPSS 10% A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok… Tapestry 5.0.1+ Fix from $2,3002020-12-08 HIGH 7.8 CVE-2020-28948EPSS 47% Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. Archive Tar 1.4.11 / 7.75+ Fix from $1,9502020-11-19 CRITICAL 9.8 CVE-2020-27131EPSS 88% Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker … Security Manager after 4.22 Fix from $2,3002020-11-17 CRITICAL 9.8 CVE-2020-5664 Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors. Xoonips after 3.49 Fix from $2,3002020-11-16 HIGH 8.8 CVE-2020-28339 The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not … Welcart E Commerce 1.9.36+ Fix from $1,9502020-11-07 HIGH 8.0 CVE-2020-26207 DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschem… Dbschemareader 2.7.4.3+ Fix from $1,9502020-11-04 CRITICAL 9.8 CVE-2020-28032EPSS 16% WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. WordPress 5.5.2+ Fix from $2,3002020-11-02 HIGH 7.8 CVE-2020-10721 A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur… Fabric8 Maven after 4.4.1 Fix from $1,9502020-10-22 HIGH 7.2 CVE-2020-15244 In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to… Magento 20.0.4+ Fix from $1,9502020-10-21 CRITICAL 9.8 CVE-2020-24648EPSS 11% A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Cente… Intelligent Management Center 7.3+ Fix from $2,3002020-10-19 HIGH 7.8 CVE-2020-7811 Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine … Update after 3.0.32.0 Fix from $1,9502020-10-12 CRITICAL 9.8 CVE-2020-26867 ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely e… Pcvue 12.0.17+ Fix from $2,3002020-10-12 HIGH 8.1 CVE-2020-26945 MyBatis before 3.5.6 mishandles deserialization of object streams. Mybatis 3.5.6+ Fix from $1,9502020-10-10 HIGH 8.8 CVE-2020-4280EPSS 73% IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-sup… Qradar Security Information And Event Manager after 7.4.1 Fix from $1,9502020-10-08 HIGH 7.2 CVE-2020-14030 An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (an… Ozeki Ng Sms Gateway after 4.17.6 Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2020-15188EPSS 5% SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code w… Soy Cms 3.0.2.328+ Fix from $2,3002020-09-18 HIGH 8.1 CVE-2020-24750EPSS 7% FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcompon… Debian Linux 2.6.7.5 / 2.9.10.6+ Fix from $1,9502020-09-17 HIGH 7.8 CVE-2020-7528 A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary co… Scadapack 7x Remote Connect after 3.6.3.574 Fix from $1,9502020-09-16 HIGH 7.8 CVE-2020-7532 A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitra… Scadapack X70 Security Administrator after 1.2.0 Fix from $1,9502020-09-16 HIGH 8.8 CVE-2020-15172 The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Discord users can use specially … Fluffycogs 2.0.38+ Fix from $1,9502020-09-15 CRITICAL 10.0 CVE-2020-15148EPSS 79% Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. T… Yii 2.0.38+ Fix from $2,3002020-09-15 HIGH 8.8 CVE-2020-4521EPSS 6% IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe … Maximo Asset Management 7.6.0.10 / 7.6.1.2+ Fix from $1,9502020-09-15 HIGH 7.8 CVE-2020-24164 A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payloa… Nippy 2.14.2+ Fix from $1,9502020-09-11