Vulnerability index

Browse CVEs

3,052 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2017-12557EPSS 80% A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. Intelligent Management Center after 7.3 Fix from $2,3002018-02-15 CRITICAL 9.8 CVE-2016-8511EPSS 15% A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v1… Network Automation Mitigation only Fix from $2,3002018-02-15 CRITICAL 9.8 CVE-2016-8519EPSS 28% A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found. Operations Orchestration 10.70+ Fix from $2,3002018-02-15 HIGH 8.8 CVE-2017-15089 It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authentica… Infinispan after 9.1.6 Fix from $1,9502018-02-15 HIGH 8.8 CVE-2018-1000058 Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to J… Pipeline Supporting Apis after 2.17 Fix from $1,9502018-02-09 CRITICAL 9.8 CVE-2018-1000059 ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute … Validform Builder Mitigation only Fix from $2,3002018-02-09 HIGH 7.8 CVE-2018-1000045 NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This … Singledop Patch available Fix from $1,9502018-02-09 HIGH 7.8 CVE-2018-1000046 NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack… Pyblock after 1.3 Fix from $1,9502018-02-09 HIGH 8.8 CVE-2018-1000047 NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This… Kodiak Mitigation only Fix from $1,9502018-02-09 HIGH 8.8 CVE-2018-1000048 NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in r… Rtretrievalframework Mitigation only Fix from $1,9502018-02-09 CRITICAL 9.8 CVE-2016-3957 The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which migh… Web2py 2.14.2+ Fix from $2,3002018-02-06 CRITICAL 9.8 CVE-2017-15095EPSS 8% A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfo… Debian Linux 2.6.7.2 / 2.7.9.2+ Fix from $2,3002018-02-06 CRITICAL 9.8 CVE-2017-7525EPSS 38% A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user … Debian Linux 2.6.7.1 / 2.7.9.1+ Fix from $2,3002018-02-06 CRITICAL 9.8 CVE-2017-1000353 KEVEPSS 100% Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated re… Jenkins after 2.56 Fix from $2,3002018-01-29 MEDIUM 6.5 CVE-2017-1000355 Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void. Jenkins after 2.56 Fix from $1,6002018-01-29 CRITICAL 9.8 CVE-2017-4947EPSS 9% VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Succes… Vrealize Automation 1.3.0+ Fix from $2,3002018-01-29 MEDIUM 5.0 CVE-2017-15703 Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den… Nifi after 1.4.0 Fix from $1,6002018-01-25 HIGH 8.1 CVE-2018-1051 It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam… Resteasy Mitigation only Fix from $1,9502018-01-25 CRITICAL 9.8 CVE-2017-17406 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not… Enterprise Manager 7.2.766+ Fix from $2,3002018-01-23 HIGH 8.1 CVE-2018-5968EPSS 7% FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C… Debian Linux 2.6.7.3 / 2.7.9.2+ Fix from $1,9502018-01-22 CRITICAL 9.8 CVE-2016-6814EPSS 17% When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se… Groovy after 2.4.7 Fix from $2,3002018-01-18 CRITICAL 9.8 CVE-2017-17485EPSS 50% FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the C… Debian Linux 2.6.7.3 / 2.7.9.2+ Fix from $2,3002018-01-10 CRITICAL 9.8 CVE-2014-9515EPSS 6% Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted seri… Dozer after 5.5.1 Fix from $2,3002017-12-29 CRITICAL 9.8 CVE-2017-5641EPSS 21% Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. … Flex Blazeds 8.5.3-00+ Fix from $2,3002017-12-28 CRITICAL 9.8 CVE-2017-17672EPSS 15% In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circum… Vbulletin after 5.3.3 Fix from $2,3002017-12-14 CRITICAL 9.8 CVE-2017-11283EPSS 43% Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 a… Coldfusion Patch available Fix from $2,3002017-12-01 CRITICAL 9.8 CVE-2017-11284EPSS 43% Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 a… Coldfusion Patch available Fix from $2,3002017-12-01 HIGH 8.8 CVE-2017-1000207 A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being… Swagger Codegen after 2.2.2 Fix from $1,9502017-11-27 HIGH 8.1 CVE-2017-4995 An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable defau… Spring Security Mitigation only Fix from $1,9502017-11-27 CRITICAL 9.8 CVE-2017-8045 In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being c… Spring Advanced Message Queuing Protocol Mitigation only Fix from $2,3002017-11-27