Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-502 Clear
ID Title
CVE-2020-35728 Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
CVE-2020-35490 Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
CVE-2020-35491 Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
CVE-2020-24750 Unsafe Deserialization in fasterxml (CVE-2020-24750)
vulnerability in fasterxml (CVE-2020-24750). Successful exploitation can lead to full system takeover.
CVE-2020-24616 Unsafe Deserialization in fasterxml (CVE-2020-24616)
vulnerability in fasterxml (CVE-2020-24616). Successful exploitation can lead to full system takeover.
CVE-2020-14195 Unsafe Deserialization in fasterxml (CVE-2020-14195)
vulnerability in fasterxml (CVE-2020-14195). Successful exploitation can lead to full system takeover.
CVE-2020-14060 Unsafe Deserialization in apache (CVE-2020-14060)
vulnerability in apache (CVE-2020-14060). Successful exploitation can lead to full system takeover.
CVE-2020-14061 Unsafe Deserialization in fasterxml (CVE-2020-14061)
vulnerability in fasterxml (CVE-2020-14061). Successful exploitation can lead to full system takeover.
CVE-2020-14062 Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
CVE-2020-9484 Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
CVE-2020-11619 Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-10673 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2020-9548 Unsafe Deserialization in fasterxml (CVE-2020-9548)
vulnerability in fasterxml (CVE-2020-9548). Successful exploitation can lead to full system takeover.
CVE-2020-9546 Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
CVE-2019-17571 Unsafe Deserialization in log4j:log4j (CVE-2019-17571)
vulnerability in log4j:log4j (CVE-2019-17571). Successful exploitation can lead to full system takeover.
CVE-2019-10086 Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
CVE-2014-9515 Unsafe Deserialization in dozer-project (CVE-2014-9515)
vulnerability in dozer-project (CVE-2014-9515). Successful exploitation can lead to full system takeover.
CVE-2017-5641 Unsafe Deserialization in apache (CVE-2017-5641)
vulnerability in apache (CVE-2017-5641). Successful exploitation can lead to full system takeover.
CVE-2017-17672 Unsafe Deserialization in deserialization (CVE-2017-17672)
vulnerability in deserialization (CVE-2017-17672). Successful exploitation can lead to full system takeover.
CVE-2017-11283 Unsafe Deserialization in deserialization (CVE-2017-11283)
vulnerability in deserialization (CVE-2017-11283). Successful exploitation can lead to full system takeover.
CVE-2017-11284 Unsafe Deserialization in deserialization (CVE-2017-11284)
vulnerability in deserialization (CVE-2017-11284). Successful exploitation can lead to full system takeover.
CVE-2017-1000207 Unsafe Deserialization in swagger (CVE-2017-1000207)
vulnerability in swagger (CVE-2017-1000207). Successful exploitation can lead to full system takeover.
CVE-2017-4995 Unsafe Deserialization in deserialization (CVE-2017-4995)
vulnerability in deserialization (CVE-2017-4995). Successful exploitation can lead to full system takeover.
CVE-2017-8045 Unsafe Deserialization in pivotal-software (CVE-2017-8045)
vulnerability in pivotal-software (CVE-2017-8045). Successful exploitation can lead to full system takeover.
CVE-2017-1000248 Redis-store
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
CVE-2017-1000208 Unsafe Deserialization in swagger (CVE-2017-1000208)
vulnerability in swagger (CVE-2017-1000208). Successful exploitation can lead to full system takeover.
CVE-2017-1000195 Unsafe Deserialization in octobercms (CVE-2017-1000195)
vulnerability in octobercms (CVE-2017-1000195). Data can be tampered with by attackers.
CVE-2017-12633 Unsafe Deserialization in apache (CVE-2017-12633)
vulnerability in apache (CVE-2017-12633). Successful exploitation can lead to full system takeover.
CVE-2017-12634 Unsafe Deserialization in apache (CVE-2017-12634)
vulnerability in apache (CVE-2017-12634). Successful exploitation can lead to full system takeover.
CVE-2015-7501 Unsafe Deserialization in apache (CVE-2015-7501)
vulnerability in apache (CVE-2015-7501). Successful exploitation can lead to full system takeover.
CVE-2017-1000148 Unsafe Deserialization in mahara (CVE-2017-1000148)
vulnerability in mahara (CVE-2017-1000148). Successful exploitation can lead to full system takeover.
CVE-2016-5003 Unsafe Deserialization in apache (CVE-2016-5003)
vulnerability in apache (CVE-2016-5003). Successful exploitation can lead to full system takeover.
CVE-2017-12796 Unsafe Deserialization in openmrs (CVE-2017-12796)
vulnerability in openmrs (CVE-2017-12796). Successful exploitation can lead to full system takeover.
CVE-2017-12628 Unsafe Deserialization in apache (CVE-2017-12628)
vulnerability in apache (CVE-2017-12628). Successful exploitation can lead to full system takeover.
CVE-2015-5164 Unsafe Deserialization in pulpproject (CVE-2015-5164)
vulnerability in pulpproject (CVE-2015-5164). Successful exploitation can lead to full system takeover.
CVE-2016-8736 Unsafe Deserialization in apache (CVE-2016-8736)
vulnerability in apache (CVE-2016-8736). Successful exploitation can lead to full system takeover.
CVE-2017-0903 Unsafe Deserialization in deserialization (CVE-2017-0903)
vulnerability in deserialization (CVE-2017-0903). Successful exploitation can lead to full system takeover.
CVE-2017-0806 Unsafe Deserialization in google (CVE-2017-0806)
vulnerability in google (CVE-2017-0806). Successful exploitation can lead to full system takeover.
CVE-2017-14702 Unsafe Deserialization in deserialization (CVE-2017-14702)
vulnerability in deserialization (CVE-2017-14702). Successful exploitation can lead to full system takeover.
CVE-2017-10932 Unsafe Deserialization in c (CVE-2017-10932)
vulnerability in c (CVE-2017-10932). Successful exploitation can lead to full system takeover.
CVE-2017-14141 Unsafe Deserialization in kaltura (CVE-2017-14141)
vulnerability in kaltura (CVE-2017-14141). Successful exploitation can lead to full system takeover.
CVE-2016-8744 Unsafe Deserialization in apache (CVE-2016-8744)
vulnerability in apache (CVE-2016-8744). Successful exploitation can lead to full system takeover.
CVE-2017-12612 Unsafe Deserialization in apache (CVE-2017-12612)
vulnerability in apache (CVE-2017-12612). Successful exploitation can lead to full system takeover.
CVE-2017-14035 CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →