Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-15321
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
Optiontree
2.7.3+
CRITICAL 9.8
CVE-2018-20984
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
Patreon Wordpress
1.2.2+
HIGH 7.3
CVE-2019-10086EPSS 30%
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the clas…
Commons Beanutils
after 1.9.3
CRITICAL 9.8
CVE-2019-0344 KEVEPSS 7%
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex…
Commerce Cloud
Mitigation only
HIGH 7.5
CVE-2019-14439EPSS 11%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either global…
Debian Linux
2.6.7.3 / 2.7.9.6+
CRITICAL 9.8
CVE-2018-11779
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…
Storm
after 1.2.2
CRITICAL 9.8
CVE-2019-10173EPSS 95%
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has…
Xstream
after 8.2.2
CRITICAL 9.8
CVE-2019-1010306
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted reque…
Slanger
Patch available
HIGH 7.2
CVE-2019-10135
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed t…
Osbs Client
0.56.1+
CRITICAL 9.8
CVE-2018-11307EPSS 6%
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…
Openshift Container Platform
2.6.7.3 / 2.7.9.4+
HIGH 8.8
CVE-2019-12747
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
TYPO3
after 9.5.7
MEDIUM 5.9
CVE-2019-12384EPSS 45%
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core clas…
Debian Linux
2.6.7.3 / 2.7.9.6+
CRITICAL 9.8
CVE-2019-11011
Akamai CloudTest before 58.30 allows remote code execution.
Cloudtest
58.30+
CRITICAL 9.8
CVE-2018-15890
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/EC…
Ethereumj
No fix yet
MEDIUM 5.9
CVE-2019-12814EPSS 11%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a s…
Debian Linux
2.6.7.3 / 2.7.9.6+
HIGH 7.2
CVE-2019-12868EPSS 6%
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-…
Misp
Patch available
HIGH 8.8
CVE-2019-12799EPSS 55%
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can …
Shopware
after 5.6.0
CRITICAL 9.8
CVE-2019-7840EPSS 17%
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Su…
Coldfusion
Mitigation only
HIGH 8.8
CVE-2019-11080EPSS 14%
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user …
Experience Platform
9.1.1+
HIGH 8.8
CVE-2019-11950EPSS 6%
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
HIGH 8.8
CVE-2019-11956EPSS 6%
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
HIGH 8.8
CVE-2019-5350EPSS 6%
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
CRITICAL 9.8
CVE-2019-11944EPSS 13%
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
CRITICAL 9.8
CVE-2019-11945EPSS 79%
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Intelligent Management Center
7.3+
CRITICAL 9.8
CVE-2019-10069
In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
Godot
2.1+
CRITICAL 9.8
CVE-2019-9874 KEVEPSS 84%
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo…
Cms
after 8.2
HIGH 8.8
CVE-2019-9875 KEVEPSS 14%
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi…
Cms
after 9.1
CRITICAL 9.8
CVE-2019-6980
Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.
Zimbra Collaboration Suite
8.7.11 / 8.8.9+
CRITICAL 9.8
CVE-2019-7091EPSS 26%
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Suc…
Coldfusion
Mitigation only
HIGH 8.8
CVE-2016-10753
e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
E107
No fix yet