Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2020-2189 Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a… Source Code Management Filter Jervis after 0.2.1 Fix from $1,9502020-05-06 MEDIUM 6.5 CVE-2020-12469 admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value wi… Subrion after 4.2.1 Fix from $1,6002020-04-29 CRITICAL 9.8 CVE-2020-12471 MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserial… Monox after 5.1.40.5152 Fix from $2,3002020-04-29 CRITICAL 9.8 CVE-2020-12133EPSS 10% The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java d… Electric Consciousmap after 2.8.1 Fix from $2,3002020-04-27 CRITICAL 9.8 CVE-2020-10915EPSS 87% This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r… One No fix yet Fix from $2,3002020-04-22 CRITICAL 9.8 CVE-2020-10914EPSS 47% This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r… One No fix yet Fix from $2,3002020-04-22 HIGH 7.8 CVE-2020-0082 In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead … Android Mitigation only Fix from $1,9502020-04-17 CRITICAL 9.8 CVE-2020-1964 It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to … Heron Mitigation only Fix from $2,3002020-04-16 HIGH 8.8 CVE-2020-2179 Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote … Yaml Axis after 0.2.0 Fix from $1,9502020-04-16 HIGH 8.8 CVE-2020-2180 Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co… Amazon Web Services Serverless Application Model after 1.2.2 Fix from $1,9502020-04-16 MEDIUM 6.3 CVE-2020-4271 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged… Qradar Security Information And Event Manager 7.3.3+ Fix from $1,6002020-04-15 HIGH 8.8 CVE-2020-4272 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request … Qradar Security Information And Event Manager 7.3.3+ Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-6219 SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allo… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502020-04-14 CRITICAL 9.8 CVE-2020-11630 An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent bet… Ejbca 6.15.2.6 / 7.3.1.2+ Fix from $2,3002020-04-08 HIGH 8.1 CVE-2020-11619 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.ao… Debian Linux 2.9.10.4+ Fix from $1,9502020-04-07 HIGH 8.1 CVE-2020-11620EPSS 6% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jel… Debian Linux 2.9.10.4+ Fix from $1,9502020-04-07 CRITICAL 9.8 CVE-2019-17564EPSS 37% Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in… Dubbo after 2.7.4 Fix from $2,3002020-04-01 HIGH 7.2 CVE-2020-11467 An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style… Deskpro 2019.8.0+ Fix from $1,9502020-04-01 MEDIUM 5.4 CVE-2019-2391 Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour includi… Js Bson 1.1.4+ Fix from $1,6002020-03-31 HIGH 8.8 CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* … Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-11113EPSS 6% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 CRITICAL 9.8 CVE-2020-7610 All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsot… Bson 1.1.4+ Fix from $2,3002020-03-30 HIGH 8.8 CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPan… Debian Linux 2.7.9.7 / 2.8.11.6+ Fix from $1,9502020-03-26 HIGH 8.8 CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.pro… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-26 CRITICAL 9.8 CVE-2020-6967EPSS 5% In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics ex… Factorytalk Services Platform Mitigation only Fix from $2,3002020-03-23 CRITICAL 9.8 CVE-2020-7961 KEVEPSS 100% Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JS… Liferay Portal 7.2.1+ Fix from $2,3002020-03-20 HIGH 8.8 CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.trans… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-18 HIGH 8.8 CVE-2020-10673EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.type… Debian Linux 2.6.7.4 / 2.9.10.4+ Fix from $1,9502020-03-18 HIGH 8.8 CVE-2019-20452 A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/s… Pydio 8.2.4+ Fix from $1,9502020-03-17