Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-12557EPSS 80%
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
Intelligent Management Center
after 7.3
CRITICAL 9.8
CVE-2016-8511EPSS 15%
A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v1…
Network Automation
Mitigation only
CRITICAL 9.8
CVE-2016-8519EPSS 28%
A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.
Operations Orchestration
10.70+
HIGH 8.8
CVE-2017-15089
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authentica…
Infinispan
after 9.1.6
HIGH 8.8
CVE-2018-1000058
Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to J…
Pipeline Supporting Apis
after 2.17
CRITICAL 9.8
CVE-2018-1000059
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute …
Validform Builder
Mitigation only
HIGH 7.8
CVE-2018-1000045
NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This …
Singledop
Patch available
HIGH 7.8
CVE-2018-1000046
NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack…
Pyblock
after 1.3
HIGH 8.8
CVE-2018-1000047
NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This…
Kodiak
Mitigation only
HIGH 8.8
CVE-2018-1000048
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in r…
Rtretrievalframework
Mitigation only
CRITICAL 9.8
CVE-2016-3957
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which migh…
Web2py
2.14.2+
CRITICAL 9.8
CVE-2017-15095EPSS 8%
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo…
Debian Linux
2.6.7.2 / 2.7.9.2+
CRITICAL 9.8
CVE-2017-7525EPSS 38%
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user …
Debian Linux
2.6.7.1 / 2.7.9.1+
CRITICAL 9.8
CVE-2017-1000353 KEVEPSS 100%
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated re…
Jenkins
after 2.56
MEDIUM 6.5
CVE-2017-1000355
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.
Jenkins
after 2.56
CRITICAL 9.8
CVE-2017-4947EPSS 9%
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Succes…
Vrealize Automation
1.3.0+
MEDIUM 5.0
CVE-2017-15703
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den…
Nifi
after 1.4.0
HIGH 8.1
CVE-2018-1051
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…
Resteasy
Mitigation only
CRITICAL 9.8
CVE-2017-17406
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not…
Enterprise Manager
7.2.766+
HIGH 8.1
CVE-2018-5968EPSS 7%
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…
Debian Linux
2.6.7.3 / 2.7.9.2+
CRITICAL 9.8
CVE-2016-6814EPSS 17%
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se…
Groovy
after 2.4.7
CRITICAL 9.8
CVE-2017-17485EPSS 50%
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C…
Debian Linux
2.6.7.3 / 2.7.9.2+
CRITICAL 9.8
CVE-2014-9515EPSS 6%
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted seri…
Dozer
after 5.5.1
CRITICAL 9.8
CVE-2017-5641EPSS 21%
Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. …
Flex Blazeds
8.5.3-00+
CRITICAL 9.8
CVE-2017-17672EPSS 15%
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circum…
Vbulletin
after 5.3.3
CRITICAL 9.8
CVE-2017-11283EPSS 43%
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 a…
Coldfusion
Patch available
CRITICAL 9.8
CVE-2017-11284EPSS 43%
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 a…
Coldfusion
Patch available
HIGH 8.8
CVE-2017-1000207
A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being…
Swagger Codegen
after 2.2.2
HIGH 8.1
CVE-2017-4995
An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable defau…
Spring Security
Mitigation only
CRITICAL 9.8
CVE-2017-8045
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being c…
Spring Advanced Message Queuing Protocol
Mitigation only