Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2019-20330EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. Debian Linux 2.7.9.7 / 2.8.11.5+ Fix from $2,3002020-01-03 CRITICAL 9.8 CVE-2016-1000027EPSS 32% Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data… Spring Framework 6.0.0+ Fix from $2,3002020-01-02 MEDIUM 6.5 CVE-2019-14466 The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per… Debian Linux Patch available Fix from $1,6002019-12-31 HIGH 7.8 CVE-2019-19470 Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affect… Tinywall 2.1.13+ Fix from $1,9502019-12-30 HIGH 8.8 CVE-2019-18211 An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of … C1 Cms after 6.6 Fix from $1,9502019-12-23 CRITICAL 9.8 CVE-2019-17571EPSS 69% Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi… Log4j 4.14.3+ Fix from $2,3002019-12-20 HIGH 8.8 CVE-2019-19909 An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injectio… Open Journal System 3.1.2-2+ Fix from $1,9502019-12-19 CRITICAL 9.8 CVE-2019-8662EPSS 10% This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able… Iphone Os 5.3 / 10.14.6+ Fix from $2,3002019-12-18 HIGH 8.8 CVE-2019-19849 An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and… TYPO3 8.7.30 / 9.5.12+ Fix from $1,9502019-12-17 CRITICAL 9.8 CVE-2019-18956EPSS 6% Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2,… Dv2eemvc 1.0.30 / 1.1.2+ Fix from $2,3002019-12-17 CRITICAL 9.8 CVE-2019-19826 The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.in… Views Dynamic Field after 6.x-1.4 Fix from $2,3002019-12-16 CRITICAL 9.8 CVE-2014-3699 eDeploy has RCE via cPickle deserialization of untrusted data Edeploy No fix yet Fix from $2,3002019-12-15 CRITICAL 9.8 CVE-2019-16774 In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. Phpfastcache 5.0.13+ Fix from $2,3002019-12-12 CRITICAL 9.8 CVE-2019-18316 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the A… Sppa T3000 Application Server Mitigation only Fix from $2,3002019-12-12 CRITICAL 9.8 CVE-2019-18283EPSS 5% A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without au… Sppa T3000 Application Server No fix yet Fix from $2,3002019-12-12 HIGH 8.1 CVE-2019-17358 Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An auth… Debian Linux after 1.2.7 Fix from $1,9502019-12-12 HIGH 7.5 CVE-2019-19373 An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where … Matrix 5.5.0.3 / 5.5.1.8+ Fix from $1,9502019-12-11 CRITICAL 9.8 CVE-2019-18935 KEVEPSS 100% Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploi… Ui For Asp.net Ajax after 2020.1.114 Fix from $2,3002019-12-11 CRITICAL 9.8 CVE-2019-19230 An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacke… Nolio Patch available Fix from $2,3002019-12-09 CRITICAL 9.8 CVE-2019-17556 Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being … Olingo after 4.6.0 Fix from $2,3002019-12-04 CRITICAL 10.0 CVE-2019-18580 Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated… Emc Storage Monitoring And Reporting Mitigation only Fix from $2,3002019-11-26 HIGH 8.8 CVE-2019-15271 KEVEPSS 6% A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker… Rv016 Multi Wan Vpn Firmware 4.2.3.10+ Fix from $1,9502019-11-26 HIGH 8.8 CVE-2019-4561 IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted… Security Identity Manager Mitigation only Fix from $1,9502019-11-20 CRITICAL 9.8 CVE-2019-1373EPSS 18% A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Re… Exchange Server Patch available Fix from $2,3002019-11-12 HIGH 7.2 CVE-2019-8141 A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticate… Magento 2.1.19 / 2.2.10+ Fix from $1,9502019-11-06 HIGH 7.8 CVE-2019-18631 The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and… Authentication Service Patch available Fix from $1,9502019-11-05 CRITICAL 9.8 CVE-2019-18364 In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. Teamcity 2019.1.4+ Fix from $2,3002019-10-31 HIGH 7.5 CVE-2019-18601 OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series o… Openafs 1.6.24 / 1.8.5+ Fix from $1,9502019-10-29 CRITICAL 9.8 CVE-2019-12017 A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login a… Mapr 5.2.2+ Fix from $2,3002019-10-24 CRITICAL 9.8 CVE-2019-13116EPSS 5% The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, rela… Mule Runtime 3.8.0+ Fix from $2,3002019-10-16