Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.8 CVE-2026-24765 PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involvi… Debian Linux 8.5.52 / 9.6.33+ Fix from $1,9502026-01-27 HIGH 7.8 CVE-2025-64512 Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107… Debian Linux 2025-11-07+ Fix from $1,9502025-11-10 HIGH 8.8 CVE-2025-49113 KEVEPSS 98% Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n… Debian Linux 1.5.10 / 1.6.11+ Fix from $1,9502025-06-02 MEDIUM 5.9 CVE-2024-20926 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup… Debian Linux Patch available Fix from $1,6002024-01-16 CRITICAL 9.8 CVE-2023-27372EPSS 100% SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… Debian Linux 3.2.18 / 4.0.10+ Fix from $2,3002023-02-28 HIGH 8.1 CVE-2020-10650 A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via igni… Debian Linux 2.9.10.4+ Fix from $1,9502022-12-26 HIGH 7.5 CVE-2022-42003 In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value d… Debian Linux 2.12.7.1 / 2.13.3+ Fix from $1,9502022-10-02 HIGH 7.5 CVE-2022-42004 In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to … Debian Linux 2.12.7.1 / 2.13.0+ Fix from $1,9502022-10-02 HIGH 8.0 CVE-2022-30287EPSS 71% Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This th… Debian Linux after 5.2.22 Fix from $1,9502022-07-28 HIGH 7.5 CVE-2022-25647EPSS 12% The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal clas… Debian Linux 2.8.9+ Fix from $1,9502022-05-01 MEDIUM 5.3 CVE-2022-21341 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that … Debian Linux after 15.0.5 Fix from $1,6002022-01-19 CRITICAL 9.8 CVE-2021-42392EPSS 63% The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attack… Debian Linux after 2.0.204 Fix from $2,3002022-01-10 MEDIUM 6.3 CVE-2021-39140EPSS 6% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca… Debian Linux 1.4.18+ Fix from $1,6002021-08-23 HIGH 8.5 CVE-2021-39141EPSS 16% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39144 KEVEPSS 98% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39145 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2021-39139 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2021-29505EPSS 77% XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack… Debian Linux 1.4.17+ Fix from $1,9502021-05-28 HIGH 8.1 CVE-2020-36183 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36179EPSS 21% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common… Debian Linux Patch available Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36180EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux Patch available Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36182EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-07 HIGH 8.1 CVE-2020-36184EPSS 10% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux Patch available Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36185EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36186EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36187EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36188EPSS 11% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36189 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.dep… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-36181EPSS 5% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp… Debian Linux Patch available Fix from $1,9502021-01-06 HIGH 8.1 CVE-2020-35728EPSS 13% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.… Debian Linux 2.6.7.5 / 2.9.10.8+ Fix from $1,9502020-12-27