Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2018-19296 PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. Debian Linux 5.2.27 / 6.0.6+ Fix from $1,9502018-11-16 CRITICAL 9.8 CVE-2018-15381EPSS 87% A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands… Unity Express 9.0.6+ Fix from $2,3002018-11-08 CRITICAL 9.8 CVE-2018-8021EPSS 53% Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. … Superset 0.23+ Fix from $2,3002018-11-07 CRITICAL 9.8 CVE-2018-1851 IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper des… Websphere Application Server 18.0.0.3+ Fix from $2,3002018-10-31 HIGH 7.8 CVE-2018-15686 A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be… Ubuntu Linux after 239 Fix from $1,9502018-10-26 HIGH 7.8 CVE-2018-18013 * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supp… Xenmobile Server after 10.8.0 Fix from $1,9502018-10-24 CRITICAL 9.8 CVE-2018-18628EPSS 5% An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize… Pippo Patch available Fix from $2,3002018-10-23 HIGH 8.8 CVE-2018-18589 A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9… Real User Monitoring Mitigation only Fix from $1,9502018-10-23 CRITICAL 9.8 CVE-2018-15616 A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserializatio… Avaya Aura System Platform after 6.4.2 Fix from $2,3002018-10-17 CRITICAL 9.8 CVE-2018-3245EPSS 94% Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are af… Weblogic Server Patch available Fix from $2,3002018-10-17 CRITICAL 9.8 CVE-2018-18240 Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream'… Pippo after 1.11.0 Fix from $2,3002018-10-11 HIGH 8.1 CVE-2018-16364EPSS 18% A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload … Manageengine Applications Manager No fix yet Fix from $1,9502018-09-26 CRITICAL 9.8 CVE-2018-3972 An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (… Monero No fix yet Fix from $2,3002018-09-26 CRITICAL 9.8 CVE-2018-15965EPSS 26% Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Coldfusion Mitigation only Fix from $2,3002018-09-25 CRITICAL 9.8 CVE-2018-15957EPSS 28% Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Coldfusion Mitigation only Fix from $2,3002018-09-25 CRITICAL 9.8 CVE-2018-15958EPSS 26% Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Coldfusion Mitigation only Fix from $2,3002018-09-25 CRITICAL 9.8 CVE-2018-15959EPSS 26% Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Coldfusion Mitigation only Fix from $2,3002018-09-25 HIGH 8.8 CVE-2016-9045 A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserializa… Processmaker No fix yet Fix from $1,9502018-09-17 CRITICAL 9.8 CVE-2018-17057EPSS 26% An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. Tcpdf 3.16.0 / 6.2.22+ Fix from $2,3002018-09-14 HIGH 8.8 CVE-2016-0750 The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user cou… Infinispan 9.1.0+ Fix from $1,9502018-09-11 CRITICAL 9.8 CVE-2018-1567 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a… Websphere Application Server after 9.0.0.9 Fix from $2,3002018-09-07 HIGH 7.5 CVE-2018-10911 A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read… Virtualization Host 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 HIGH 8.8 CVE-2018-15514 HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\p… Docker No fix yet Fix from $1,9502018-09-01 HIGH 7.8 CVE-2018-10513 A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker … Antivirus \+ Security after 12.0 Fix from $1,9502018-08-30 CRITICAL 9.8 CVE-2018-15691EPSS 17% Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute … Release Automation 6.3.0.9945 / 6.4.0.10119+ Fix from $2,3002018-08-30 HIGH 7.8 CVE-2018-14572 In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as dem… Conference Scheduler Cli after 0.10.1 Fix from $1,9502018-08-28 HIGH 8.1 CVE-2018-15576EPSS 10% An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in… Easylogin Pro after 1.3.0 Fix from $1,9502018-08-24 MEDIUM 5.3 CVE-2018-1999042 A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name… Jenkins after 2.137 Fix from $1,6002018-08-23 CRITICAL 9.8 CVE-2018-1000641 YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that ca… Yeswiki Patch available Fix from $2,3002018-08-20 HIGH 7.5 CVE-2018-15503 The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object… Swoole Patch available Fix from $1,9502018-08-18