Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-20330EPSS 9%
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Debian Linux
2.7.9.7 / 2.8.11.5+
CRITICAL 9.8
CVE-2016-1000027EPSS 32%
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data…
Spring Framework
6.0.0+
MEDIUM 6.5
CVE-2019-14466
The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per…
Debian Linux
Patch available
HIGH 7.8
CVE-2019-19470
Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affect…
Tinywall
2.1.13+
HIGH 8.8
CVE-2019-18211
An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of …
C1 Cms
after 6.6
CRITICAL 9.8
CVE-2019-17571EPSS 69%
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi…
Log4j
4.14.3+
HIGH 8.8
CVE-2019-19909
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injectio…
Open Journal System
3.1.2-2+
CRITICAL 9.8
CVE-2019-8662EPSS 10%
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able…
Iphone Os
5.3 / 10.14.6+
HIGH 8.8
CVE-2019-19849
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and…
TYPO3
8.7.30 / 9.5.12+
CRITICAL 9.8
CVE-2019-18956EPSS 6%
Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2,…
Dv2eemvc
1.0.30 / 1.1.2+
CRITICAL 9.8
CVE-2019-19826
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.in…
Views Dynamic Field
after 6.x-1.4
CRITICAL 9.8
CVE-2014-3699
eDeploy has RCE via cPickle deserialization of untrusted data
Edeploy
No fix yet
CRITICAL 9.8
CVE-2019-16774
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
Phpfastcache
5.0.13+
CRITICAL 9.8
CVE-2019-18316
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A…
Sppa T3000 Application Server
Mitigation only
CRITICAL 9.8
CVE-2019-18283EPSS 5%
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without au…
Sppa T3000 Application Server
No fix yet
HIGH 8.1
CVE-2019-17358
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An auth…
Debian Linux
after 1.2.7
HIGH 7.5
CVE-2019-19373
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where …
Matrix
5.5.0.3 / 5.5.1.8+
CRITICAL 9.8
CVE-2019-18935 KEVEPSS 100%
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploi…
Ui For Asp.net Ajax
after 2020.1.114
CRITICAL 9.8
CVE-2019-19230
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacke…
Nolio
Patch available
CRITICAL 9.8
CVE-2019-17556
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being …
Olingo
after 4.6.0
CRITICAL 10.0
CVE-2019-18580
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated…
Emc Storage Monitoring And Reporting
Mitigation only
HIGH 8.8
CVE-2019-15271 KEVEPSS 6%
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker…
Rv016 Multi Wan Vpn Firmware
4.2.3.10+
HIGH 8.8
CVE-2019-4561
IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted…
Security Identity Manager
Mitigation only
CRITICAL 9.8
CVE-2019-1373EPSS 18%
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Re…
Exchange Server
Patch available
HIGH 7.2
CVE-2019-8141
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticate…
Magento
2.1.19 / 2.2.10+
HIGH 7.8
CVE-2019-18631
The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and…
Authentication Service
Patch available
CRITICAL 9.8
CVE-2019-18364
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
Teamcity
2019.1.4+
HIGH 7.5
CVE-2019-18601
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series o…
Openafs
1.6.24 / 1.8.5+
CRITICAL 9.8
CVE-2019-12017
A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login a…
Mapr
5.2.2+
CRITICAL 9.8
CVE-2019-13116EPSS 5%
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, rela…
Mule Runtime
3.8.0+