Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-18375
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
Ampache
No fix yet
HIGH 8.1
CVE-2016-10750
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a list…
Hazelcast
3.11+
CRITICAL 9.8
CVE-2019-12240
The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.
Virim
No fix yet
CRITICAL 9.8
CVE-2019-12241
The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.
Carts Guru
No fix yet
HIGH 7.5
CVE-2019-12086EPSS 22%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a sp…
Debian Linux
2.6.7.3 / 2.7.9.6+
CRITICAL 9.8
CVE-2019-4279EPSS 80%
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence …
Websphere Application Server
after 9.0.0.11
HIGH 7.1
CVE-2019-10912
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user inp…
Symfony
2.8.50 / 3.4.26+
HIGH 7.8
CVE-2019-10924
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.3). The vulnerability could allow an attacker to execute arbitrary code …
Logo\! Soft Comfort
8.3+
CRITICAL 9.8
CVE-2019-11831EPSS 6%
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which a…
Pharstreamwrapper
2.1.1 / 3.1.1+
CRITICAL 9.8
CVE-2019-11830
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar st…
Pharstreamwrapper
2.1.1 / 3.1.1+
HIGH 7.5
CVE-2019-11458
An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwr…
Cakephp
Patch available
CRITICAL 9.8
CVE-2019-5434EPSS 57%
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in …
Revive Adserver
4.2.0+
CRITICAL 9.8
CVE-2019-7214EPSS 85%
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the serve…
Smartermail
16.3.6985+
HIGH 8.8
CVE-2019-9056
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersMa…
Cms Made Simple
Mitigation only
HIGH 7.8
CVE-2019-7361
An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autod…
Advance Steel
Mitigation only
HIGH 8.8
CVE-2019-10867EPSS 69%
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will …
Pimcore
5.7.1+
HIGH 7.5
CVE-2018-12680
The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a denial of service in applicat…
Coapthon
No fix yet
HIGH 7.5
CVE-2018-12679
The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of service in applications that use …
Coapthon3
No fix yet
CRITICAL 9.8
CVE-2017-18365EPSS 21%
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute ar…
GitHub
2.8.7+
CRITICAL 9.8
CVE-2019-10068 KEVEPSS 96%
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validat…
Xperience
10.0.52 / 11.0.48+
HIGH 8.8
CVE-2019-9055EPSS 12%
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.…
Cms Made Simple
after 2.2.8
HIGH 8.8
CVE-2019-9057
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, …
Cms Made Simple
after 2.2.8
HIGH 8.8
CVE-2019-9061
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unse…
Cms Made Simple
after 2.2.8
HIGH 8.8
CVE-2019-7539
A code injection issue was discovered in ipycache through 2016-05-31.
Ipycache
after 2016-05-31
HIGH 8.8
CVE-2018-20221EPSS 10%
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input…
Ajera
after 9.10.16
CRITICAL 9.8
CVE-2018-19276EPSS 99%
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary comman…
Openmrs
1.12.1 / 2.0.8+
HIGH 7.5
CVE-2018-12022EPSS 7%
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…
Debian Linux
Patch available
HIGH 7.5
CVE-2018-12023EPSS 9%
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2019-0192EPSS 78%
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it…
Solr
after 6.6.5
CRITICAL 9.8
CVE-2019-0187
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a…
Jmeter
Mitigation only