Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux HIGH 7.8
CVE-2026-24765

PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involvi…

Fix: 8.5.52 / 9.6.33+
Fix from $1,950 2026-01-27
Debian Linux HIGH 7.8
CVE-2025-64512

Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107…

Fix: 2025-11-07+
Fix from $1,950 2025-11-10
Debian Linux HIGH 8.8
CVE-2025-49113 KEVEPSS 98%

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…

Fix: 1.5.10 / 1.6.11+
Fix from $1,950 2025-06-02
Debian Linux MEDIUM 5.9
CVE-2024-20926

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup…

Patch available
Fix from $1,600 2024-01-16
Debian Linux CRITICAL 9.8
CVE-2023-27372EPSS 100%

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Fix: 3.2.18 / 4.0.10+
Fix from $2,300 2023-02-28
Debian Linux HIGH 8.1
CVE-2020-10650

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via igni…

Fix: 2.9.10.4+
Fix from $1,950 2022-12-26
Debian Linux HIGH 7.5
CVE-2022-42003

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value d…

Fix: 2.12.7.1 / 2.13.3+
Fix from $1,950 2022-10-02
Debian Linux HIGH 7.5
CVE-2022-42004

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to …

Fix: 2.12.7.1 / 2.13.0+
Fix from $1,950 2022-10-02
Debian Linux HIGH 8.0
CVE-2022-30287EPSS 71%

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This th…

Fix: after 5.2.22
Fix from $1,950 2022-07-28
Debian Linux HIGH 7.5
CVE-2022-25647EPSS 12%

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal clas…

Fix: 2.8.9+
Fix from $1,950 2022-05-01
Debian Linux MEDIUM 5.3
CVE-2022-21341

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux CRITICAL 9.8
CVE-2021-42392EPSS 63%

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack…

Fix: after 2.0.204
Fix from $2,300 2022-01-10
Debian Linux MEDIUM 6.3
CVE-2021-39140EPSS 6%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca…

Fix: 1.4.18+
Fix from $1,600 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39141EPSS 16%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39145

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.8
CVE-2021-39139

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.8
CVE-2021-29505EPSS 77%

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack…

Fix: 1.4.17+
Fix from $1,950 2021-05-28
Debian Linux HIGH 8.1
CVE-2020-36183

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36179EPSS 21%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common…

Patch available
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36180EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Patch available
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36182EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-07
Debian Linux HIGH 8.1
CVE-2020-36184EPSS 10%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Patch available
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36185EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36186EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36187EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36188EPSS 11%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36189

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-36181EPSS 5%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…

Patch available
Fix from $1,950 2021-01-06
Debian Linux HIGH 8.1
CVE-2020-35728EPSS 13%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.…

Fix: 2.6.7.5 / 2.9.10.8+
Fix from $1,950 2020-12-27