Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-20453
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http…
Pydio
8.2.4+
CRITICAL 9.8
CVE-2020-1947EPSS 34%
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load …
Shardingsphere
Mitigation only
CRITICAL 9.8
CVE-2017-10992EPSS 10%
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker…
Storage Essentials
No fix yet
HIGH 8.8
CVE-2016-1487
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deseriali…
Markvision Enterprise
2.3.0+
HIGH 8.8
CVE-2020-2158
Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod…
Literate
after 1.0
CRITICAL 9.8
CVE-2020-5327
Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is expo…
Security Management Server
10.2.10+
CRITICAL 9.8
CVE-2020-10189 KEVEPSS 100%
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the F…
Manageengine Desktop Central
10.0.479+
CRITICAL 9.8
CVE-2019-14893
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of ma…
Jackson Databind
2.8.11.5 / 2.9.10+
CRITICAL 9.8
CVE-2019-14892EPSS 6%
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…
Decision Manager
2.6.7.3 / 2.8.11.5+
CRITICAL 9.8
CVE-2020-9547EPSS 18%
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engi…
Active Iq Unified Manager
2.7.9.7 / 2.8.11.6+
CRITICAL 9.8
CVE-2020-9548EPSS 18%
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An…
Active Iq Unified Manager
2.7.9.7 / 2.8.11.6+
CRITICAL 9.8
CVE-2020-9546
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shad…
Active Iq Unified Manager
2.7.9.7 / 2.8.11.6+
HIGH 7.2
CVE-2019-5326
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP pla…
Airwave
8.2.10.1+
CRITICAL 9.8
CVE-2020-8441
JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinue…
Jyaml
after 1.3
CRITICAL 9.8
CVE-2019-20477EPSS 5%
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a …
Fedora
after 5.1.2
CRITICAL 9.8
CVE-2020-9006EPSS 9%
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via…
Popup Builder
after 2.6.7.6
HIGH 7.2
CVE-2020-8801
SuiteCRM through 7.11.11 allows PHAR Deserialization.
Suitecrm
after 7.11.11
HIGH 8.8
CVE-2020-2123
Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod…
Radargun
after 1.7
HIGH 8.8
CVE-2020-0618 KEVEPSS 99%
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL…
Sql Server
Patch available
CRITICAL 9.8
CVE-2020-8840EPSS 27%
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC…
Debian Linux
2.7.9.7 / 2.8.11.5+
CRITICAL 9.8
CVE-2020-6770
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on …
Bosch Video Management System Mobile Video Service
after 10.0.0.1225
CRITICAL 9.8
CVE-2013-4521
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods c…
Nuxeo
Patch available
CRITICAL 9.8
CVE-2020-3716EPSS 14%
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulner…
Magento
after 2.3.3
CRITICAL 9.8
CVE-2019-17570EPSS 49%
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) librar…
Xml Rpc
Patch available
CRITICAL 9.8
CVE-2020-6959
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Buil…
Maxpro Nvr Xe Firmware
after 5.6
HIGH 7.8
CVE-2019-17635
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by…
Memory Analyzer
after 1.9.1
HIGH 8.1
CVE-2020-2604
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE…
Enterprise Linux
after 13.0.1
CRITICAL 9.8
CVE-2020-2555 KEVEPSS 97%
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are aff…
Access Manager
after 11.3.2
CRITICAL 9.8
CVE-2019-17076
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial…
Jamf
after 10.15.0
CRITICAL 9.8
CVE-2014-1860
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
Contao Cms
after 3.2.4