Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-17531EPSS 5%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …
Debian Linux
2.6.7.3 / 2.8.11.5+
CRITICAL 9.8
CVE-2019-17267
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactio…
Active Iq Unified Manager
2.8.11.5 / 2.9.10+
CRITICAL 9.8
CVE-2019-17206
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute…
Redis Wrapper
0.3.0+
CRITICAL 9.8
CVE-2019-16891EPSS 46%
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Liferay Portal
after 6.0.6
CRITICAL 9.8
CVE-2019-12630EPSS 66%
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitr…
Security Manager
4.18+
HIGH 7.8
CVE-2019-17080EPSS 8%
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpick…
Mintinstall
No fix yet
CRITICAL 9.8
CVE-2019-16942EPSS 6%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …
Debian Linux
2.6.7.3 / 2.8.11.5+
CRITICAL 9.8
CVE-2019-16943
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …
Debian Linux
2.6.7.3 / 2.8.11.5+
CRITICAL 9.8
CVE-2019-10202EPSS 5%
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2019-9365
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional…
Android
Mitigation only
MEDIUM 5.5
CVE-2019-9373
In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of servic…
Android
Mitigation only
CRITICAL 9.8
CVE-2019-16755
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-au…
Myit Digital Workplace
18.08.00+
CRITICAL 9.8
CVE-2019-16894
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
Inoerp
No fix yet
HIGH 8.8
CVE-2019-11666
Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51…
Service Manager
after 9.62
CRITICAL 9.8
CVE-2019-0195EPSS 15%
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou…
Tapestry
after 5.4.3
CRITICAL 9.8
CVE-2019-14540EPSS 11%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
Fedora
2.6.7.3 / 2.8.11.5+
CRITICAL 9.8
CVE-2019-16335
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a…
Fedora
2.6.7.3 / 2.8.11.5+
HIGH 8.8
CVE-2019-16317
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because…
Pimcore
5.7.1+
CRITICAL 9.8
CVE-2019-0189EPSS 24%
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and …
Ofbiz
16.11.06+
CRITICAL 9.8
CVE-2017-18605
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
Gravitate Qa Tracker
after 1.2.1
HIGH 7.5
CVE-2017-18604
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
Sitebuilder Dynamic Components
after 1.0
HIGH 7.2
CVE-2019-14224EPSS 5%
An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit…
Alfresco
No fix yet
HIGH 8.8
CVE-2019-5069
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially r…
Efront Lms
after 5.2.12
CRITICAL 9.8
CVE-2018-11569
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.
Eventum
3.5.2+
CRITICAL 9.8
CVE-2019-15780
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Formidable Form Builder
4.02.01+
CRITICAL 9.8
CVE-2019-15521
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
Spoon Library
1.4.1+
CRITICAL 9.8
CVE-2018-20987
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
Newsletters
4.6.8.6+
CRITICAL 9.8
CVE-2019-11030
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in S…
Mirasys Vms
7.6.1 / 8.3.2+
CRITICAL 9.8
CVE-2019-15319
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
Optiontree
2.7.0+
CRITICAL 9.8
CVE-2019-15320
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
Optiontree
2.7.3+