Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-2189
Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a…
Source Code Management Filter Jervis
after 0.2.1
MEDIUM 6.5
CVE-2020-12469
admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value wi…
Subrion
after 4.2.1
CRITICAL 9.8
CVE-2020-12471
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserial…
Monox
after 5.1.40.5152
CRITICAL 9.8
CVE-2020-12133EPSS 10%
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java d…
Electric Consciousmap
after 2.8.1
CRITICAL 9.8
CVE-2020-10915EPSS 87%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r…
One
No fix yet
CRITICAL 9.8
CVE-2020-10914EPSS 47%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r…
One
No fix yet
HIGH 7.8
CVE-2020-0082
In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead …
Android
Mitigation only
CRITICAL 9.8
CVE-2020-1964
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to …
Heron
Mitigation only
HIGH 8.8
CVE-2020-2179
Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote …
Yaml Axis
after 0.2.0
HIGH 8.8
CVE-2020-2180
Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co…
Amazon Web Services Serverless Application Model
after 1.2.2
MEDIUM 6.3
CVE-2020-4271
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged…
Qradar Security Information And Event Manager
7.3.3+
HIGH 8.8
CVE-2020-4272
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request …
Qradar Security Information And Event Manager
7.3.3+
HIGH 8.8
CVE-2020-6219
SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allo…
Businessobjects Business Intelligence Platform
Mitigation only
CRITICAL 9.8
CVE-2020-11630
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent bet…
Ejbca
6.15.2.6 / 7.3.1.2+
HIGH 8.1
CVE-2020-11619
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.ao…
Debian Linux
2.9.10.4+
HIGH 8.1
CVE-2020-11620EPSS 6%
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jel…
Debian Linux
2.9.10.4+
CRITICAL 9.8
CVE-2019-17564EPSS 37%
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in…
Dubbo
after 2.7.4
HIGH 7.2
CVE-2020-11467
An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style…
Deskpro
2019.8.0+
MEDIUM 5.4
CVE-2019-2391
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour includi…
Js Bson
1.1.4+
HIGH 8.8
CVE-2020-11111
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* …
Debian Linux
2.9.10.4+
HIGH 8.8
CVE-2020-11112
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro…
Debian Linux
2.9.10.4+
HIGH 8.8
CVE-2020-11113EPSS 6%
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.…
Debian Linux
2.9.10.4+
CRITICAL 9.8
CVE-2020-7610
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsot…
Bson
1.1.4+
HIGH 8.8
CVE-2020-10969
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPan…
Debian Linux
2.7.9.7 / 2.8.11.6+
HIGH 8.8
CVE-2020-10968
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.pro…
Debian Linux
2.9.10.4+
CRITICAL 9.8
CVE-2020-6967EPSS 5%
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics ex…
Factorytalk Services Platform
Mitigation only
CRITICAL 9.8
CVE-2020-7961 KEVEPSS 100%
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JS…
Liferay Portal
7.2.1+
HIGH 8.8
CVE-2020-10672
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.trans…
Debian Linux
2.9.10.4+
HIGH 8.8
CVE-2020-10673EPSS 8%
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.type…
Debian Linux
2.6.7.4 / 2.9.10.4+
HIGH 8.8
CVE-2019-20452
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/s…
Pydio
8.2.4+