Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2020-25258 An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and … Onbase after 20.3.10.1000 Fix from $2,3002020-09-11 CRITICAL 9.8 CVE-2020-25259 An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and … Onbase after 20.3.10.1000 Fix from $2,3002020-09-11 CRITICAL 9.8 CVE-2020-25260 An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and … Onbase after 20.3.10.1000 Fix from $2,3002020-09-11 HIGH 8.8 CVE-2020-17405 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication … Symphony Mitigation only Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-24034 Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege es… F\@st 5280 Router Firmware No fix yet Fix from $1,9502020-09-01 HIGH 7.8 CVE-2020-15777 An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Jav… Maven 1.6+ Fix from $1,9502020-08-25 HIGH 8.1 CVE-2020-24616EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An… Active Iq Unified Manager 2.9.10.6+ Fix from $1,9502020-08-25 HIGH 8.8 CVE-2020-10289 Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whene… Robot Operating System Patch available Fix from $1,9502020-08-20 CRITICAL 9.8 CVE-2020-4589EPSS 8% IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafte… Websphere Application Server after 9.0.5.4 Fix from $2,3002020-08-13 CRITICAL 9.8 CVE-2020-5413 Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default o… Spring Integration after 19.0 Fix from $2,3002020-07-31 CRITICAL 9.1 CVE-2019-11286 VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2… Gemfire 1.8.2 / 1.9.2+ Fix from $2,3002020-07-31 CRITICAL 9.8 CVE-2020-15086 In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification… Mediace 7.6.5+ Fix from $2,3002020-07-29 HIGH 8.8 CVE-2020-15098 In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th… TYPO3 9.5.20 / 10.4.6+ Fix from $1,9502020-07-29 CRITICAL 9.8 CVE-2020-10917EPSS 6% This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not requ… Esmpro Manager Mitigation only Fix from $2,3002020-07-22 HIGH 8.1 CVE-2020-15842 Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle atta… Digital Experience Platform 7.3.0+ Fix from $1,9502020-07-20 HIGH 8.8 CVE-2020-4464EPSS 13% IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specia… Websphere Application Server after 9.0.5.4 Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-11982EPSS 7% An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) … Airflow after 1.10.10 Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-12007 A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a de… Mc Works after 10.95.208.31 Fix from $2,3002020-07-16 HIGH 7.5 CVE-2020-12015 A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This… Mc Works after 10.95.208.31 Fix from $1,9502020-07-16 HIGH 7.5 CVE-2020-12009 A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability… Mc Works after 10.95.208.31 Fix from $1,9502020-07-16 CRITICAL 9.8 CVE-2020-14000 MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certa… Scratch Vm 0.2.0-prerelease.20200714185213+ Fix from $2,3002020-07-16 MEDIUM 6.1 CVE-2020-9496EPSS 99% XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 Ofbiz No fix yet Fix from $1,6002020-07-15 HIGH 8.8 CVE-2020-1439EPSS 20% A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of… Sharepoint Enterprise Server Patch available Fix from $1,9502020-07-14 CRITICAL 9.8 CVE-2020-1948EPSS 16% This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or met… Dubbo after 2.7.6 Fix from $2,3002020-07-14 HIGH 8.8 CVE-2020-4305 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deseriali… Infosphere Information Server after 11.7.1.1 Fix from $1,9502020-07-09 CRITICAL 9.8 CVE-2020-14172 This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. Th… Jira 7.13.0 / 8.5.0+ Fix from $2,3002020-07-03 HIGH 8.8 CVE-2020-2211 Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types… Kubernetes Ci after 1.3 Fix from $1,9502020-07-02 MEDIUM 6.8 CVE-2013-7489 The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution. Beaker after 1.11.0 Fix from $1,6002020-06-26 HIGH 7.5 CVE-2020-10740 A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application… Wildfly 20.0.0+ Fix from $1,9502020-06-22 CRITICAL 9.8 CVE-2020-14942 Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py. Tendenci Mitigation only Fix from $2,3002020-06-21