Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2017-18375 Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php. Ampache No fix yet Fix from $1,9502019-05-24 HIGH 8.1 CVE-2016-10750 In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a list… Hazelcast 3.11+ Fix from $1,9502019-05-22 CRITICAL 9.8 CVE-2019-12240 The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. Virim No fix yet Fix from $2,3002019-05-20 CRITICAL 9.8 CVE-2019-12241 The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php. Carts Guru No fix yet Fix from $2,3002019-05-20 HIGH 7.5 CVE-2019-12086EPSS 22% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a sp… Debian Linux 2.6.7.3 / 2.7.9.6+ Fix from $1,9502019-05-17 CRITICAL 9.8 CVE-2019-4279EPSS 80% IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence … Websphere Application Server after 9.0.0.11 Fix from $2,3002019-05-17 HIGH 7.1 CVE-2019-10912 In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user inp… Symfony 2.8.50 / 3.4.26+ Fix from $1,9502019-05-16 HIGH 7.8 CVE-2019-10924 A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.3). The vulnerability could allow an attacker to execute arbitrary code … Logo\! Soft Comfort 8.3+ Fix from $1,9502019-05-14 CRITICAL 9.8 CVE-2019-11831EPSS 6% The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which a… Pharstreamwrapper 2.1.1 / 3.1.1+ Fix from $2,3002019-05-09 CRITICAL 9.8 CVE-2019-11830 PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar st… Pharstreamwrapper 2.1.1 / 3.1.1+ Fix from $2,3002019-05-09 HIGH 7.5 CVE-2019-11458 An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwr… Cakephp Patch available Fix from $1,9502019-05-08 CRITICAL 9.8 CVE-2019-5434EPSS 57% An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in … Revive Adserver 4.2.0+ Fix from $2,3002019-05-06 CRITICAL 9.8 CVE-2019-7214EPSS 85% SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the serve… Smartermail 16.3.6985+ Fix from $2,3002019-04-24 HIGH 8.8 CVE-2019-9056 An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersMa… Cms Made Simple Mitigation only Fix from $1,9502019-04-11 HIGH 7.8 CVE-2019-7361 An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autod… Advance Steel Mitigation only Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-10867EPSS 69% An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will … Pimcore 5.7.1+ Fix from $1,9502019-04-04 HIGH 7.5 CVE-2018-12680 The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a denial of service in applicat… Coapthon No fix yet Fix from $1,9502019-04-02 HIGH 7.5 CVE-2018-12679 The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of service in applications that use … Coapthon3 No fix yet Fix from $1,9502019-04-02 CRITICAL 9.8 CVE-2017-18365EPSS 21% The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute ar… GitHub 2.8.7+ Fix from $2,3002019-03-28 CRITICAL 9.8 CVE-2019-10068 KEVEPSS 96% An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validat… Xperience 10.0.52 / 11.0.48+ Fix from $2,3002019-03-26 HIGH 8.8 CVE-2019-9055EPSS 12% An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.… Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 HIGH 8.8 CVE-2019-9057 An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, … Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 HIGH 8.8 CVE-2019-9061 An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unse… Cms Made Simple after 2.2.8 Fix from $1,9502019-03-26 HIGH 8.8 CVE-2019-7539 A code injection issue was discovered in ipycache through 2016-05-31. Ipycache after 2016-05-31 Fix from $1,9502019-03-21 HIGH 8.8 CVE-2018-20221EPSS 10% Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input… Ajera after 9.10.16 Fix from $1,9502019-03-21 CRITICAL 9.8 CVE-2018-19276EPSS 99% OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary comman… Openmrs 1.12.1 / 2.0.8+ Fix from $2,3002019-03-21 HIGH 7.5 CVE-2018-12022EPSS 7% An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a… Debian Linux Patch available Fix from $1,9502019-03-21 HIGH 7.5 CVE-2018-12023EPSS 9% An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a… Debian Linux Patch available Fix from $1,9502019-03-21 CRITICAL 9.8 CVE-2019-0192EPSS 78% In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it… Solr after 6.6.5 Fix from $2,3002019-03-07 CRITICAL 9.8 CVE-2019-0187 Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a… Jmeter Mitigation only Fix from $2,3002019-03-06