Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2020-14932 compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.… Squirrelmail Mitigation only Fix from $2,3002020-06-20 HIGH 8.8 CVE-2020-14933 compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor dispute… Squirrelmail Mitigation only Fix from $1,9502020-06-20 CRITICAL 9.8 CVE-2020-8165EPSS 46% A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided… Rails 5.2.4.3 / 6.0.3.1+ Fix from $2,3002020-06-19 HIGH 7.5 CVE-2020-8164 A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be… Rails 5.2.4.3 / 6.0.3.1+ Fix from $1,9502020-06-19 HIGH 8.1 CVE-2020-14195 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jn… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-16 HIGH 8.1 CVE-2020-14060EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-14 HIGH 8.1 CVE-2020-14061 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueC… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-14 HIGH 8.1 CVE-2020-14062EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xal… Active Iq Unified Manager 2.9.10.5+ Fix from $1,9502020-06-14 HIGH 8.1 CVE-2020-5411 When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixe… Spring Batch after 4.2.2 Fix from $1,9502020-06-11 MEDIUM 5.5 CVE-2020-0132 In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local … Android Patch available Fix from $1,6002020-06-11 CRITICAL 9.8 CVE-2020-4043 phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to a… Phpmussel 1.6.0+ Fix from $2,3002020-06-10 HIGH 7.5 CVE-2020-10644EPSS 20% The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (… Ignition Gateway 7.9.14 / 8.0.10+ Fix from $1,9502020-06-09 HIGH 7.5 CVE-2020-12000 The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, wh… Ignition Gateway 7.9.14 / 8.0.10+ Fix from $1,9502020-06-09 CRITICAL 9.8 CVE-2020-4448EPSS 12% IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with… Websphere Application Server 8.5.5.18 / 9.0.5.4+ Fix from $2,3002020-06-05 HIGH 7.5 CVE-2020-4449 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-cr… Websphere Application Server after 9.0.5.4 Fix from $1,9502020-06-05 CRITICAL 9.8 CVE-2020-4450EPSS 34% IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-craft… Websphere Application Server 8.5.5.18 / 9.0.5.5+ Fix from $2,3002020-06-05 HIGH 8.1 CVE-2020-7660 serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js". Serialize Javascript 3.1.0+ Fix from $1,9502020-06-01 CRITICAL 9.8 CVE-2020-12390 Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76. Firefox 76.0+ Fix from $2,3002020-05-26 CRITICAL 9.8 CVE-2020-3280EPSS 7% A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote … Unified Contact Center Express 12.0+ Fix from $2,3002020-05-22 CRITICAL 9.8 CVE-2018-21234EPSS 8% Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. Hive 5.0.4+ Fix from $2,3002020-05-21 HIGH 7.0 CVE-2020-9484EPSS 57% When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to contr… Tomcat 7.0.108 / 8.5.63+ Fix from $1,9502020-05-20 CRITICAL 9.8 CVE-2020-12835EPSS 13% An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attack… Readyapi No fix yet Fix from $2,3002020-05-20 CRITICAL 9.8 CVE-2020-13091 pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an… Pandas after 1.0.3 Fix from $2,3002020-05-15 CRITICAL 9.8 CVE-2020-13092 scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, i… Scikit Learn after 0.23.0 Fix from $2,3002020-05-15 CRITICAL 9.8 CVE-2020-11972EPSS 6% Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users… Camel after 8.2.2 Fix from $2,3002020-05-14 CRITICAL 9.8 CVE-2020-11973EPSS 7% Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sh… Camel after 8.5.0 Fix from $2,3002020-05-14 HIGH 8.8 CVE-2020-11067 In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to in… TYPO3 after 10.4.1 Fix from $1,9502020-05-14 HIGH 8.8 CVE-2019-16112EPSS 11% TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceMana… Eagle No fix yet Fix from $1,9502020-05-13 HIGH 8.8 CVE-2020-12760 An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration … Opennms Horizon 26.1.0 / 2018.1.19+ Fix from $1,9502020-05-11 HIGH 7.2 CVE-2020-5741 KEVEPSS 73% Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. Media Server 1.19.3+ Fix from $1,9502020-05-08