Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2019-17531EPSS 5% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for … Debian Linux 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-10-12 CRITICAL 9.8 CVE-2019-17267 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactio… Active Iq Unified Manager 2.8.11.5 / 2.9.10+ Fix from $2,3002019-10-07 CRITICAL 9.8 CVE-2019-17206 Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute… Redis Wrapper 0.3.0+ Fix from $2,3002019-10-05 CRITICAL 9.8 CVE-2019-16891EPSS 46% Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload. Liferay Portal after 6.0.6 Fix from $2,3002019-10-04 CRITICAL 9.8 CVE-2019-12630EPSS 66% A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitr… Security Manager 4.18+ Fix from $2,3002019-10-02 HIGH 7.8 CVE-2019-17080EPSS 8% mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpick… Mintinstall No fix yet Fix from $1,9502019-10-02 CRITICAL 9.8 CVE-2019-16942EPSS 6% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for … Debian Linux 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-10-01 CRITICAL 9.8 CVE-2019-16943 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for … Debian Linux 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-10-01 CRITICAL 9.8 CVE-2019-10202EPSS 5% A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002019-10-01 CRITICAL 9.8 CVE-2019-9365 In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional… Android Mitigation only Fix from $2,3002019-09-27 MEDIUM 5.5 CVE-2019-9373 In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of servic… Android Mitigation only Fix from $1,6002019-09-27 CRITICAL 9.8 CVE-2019-16755 BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-au… Myit Digital Workplace 18.08.00+ Fix from $2,3002019-09-26 CRITICAL 9.8 CVE-2019-16894 download.php in inoERP 4.15 allows SQL injection through insecure deserialization. Inoerp No fix yet Fix from $2,3002019-09-26 HIGH 8.8 CVE-2019-11666 Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51… Service Manager after 9.62 Fix from $1,9502019-09-17 CRITICAL 9.8 CVE-2019-0195EPSS 15% Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou… Tapestry after 5.4.3 Fix from $2,3002019-09-16 CRITICAL 9.8 CVE-2019-14540EPSS 11% A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. Fedora 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-09-15 CRITICAL 9.8 CVE-2019-16335 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a… Fedora 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-09-15 HIGH 8.8 CVE-2019-16317 In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because… Pimcore 5.7.1+ Fix from $1,9502019-09-14 CRITICAL 9.8 CVE-2019-0189EPSS 24% The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and … Ofbiz 16.11.06+ Fix from $2,3002019-09-11 CRITICAL 9.8 CVE-2017-18605 The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. Gravitate Qa Tracker after 1.2.1 Fix from $2,3002019-09-10 HIGH 7.5 CVE-2017-18604 The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. Sitebuilder Dynamic Components after 1.0 Fix from $1,9502019-09-10 HIGH 7.2 CVE-2019-14224EPSS 5% An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit… Alfresco No fix yet Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-5069 A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially r… Efront Lms after 5.2.12 Fix from $1,9502019-09-05 CRITICAL 9.8 CVE-2018-11569 Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2. Eventum 3.5.2+ Fix from $2,3002019-09-05 CRITICAL 9.8 CVE-2019-15780 The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. Formidable Form Builder 4.02.01+ Fix from $2,3002019-08-29 CRITICAL 9.8 CVE-2019-15521 Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object. Spoon Library 1.4.1+ Fix from $2,3002019-08-26 CRITICAL 9.8 CVE-2018-20987 The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. Newsletters 4.6.8.6+ Fix from $2,3002019-08-22 CRITICAL 9.8 CVE-2019-11030 Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in S… Mirasys Vms 7.6.1 / 8.3.2+ Fix from $2,3002019-08-22 CRITICAL 9.8 CVE-2019-15319 The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. Optiontree 2.7.0+ Fix from $2,3002019-08-22 CRITICAL 9.8 CVE-2019-15320 The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. Optiontree 2.7.3+ Fix from $2,3002019-08-22