Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-35728 |
|
Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35490 |
|
Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35491 |
|
Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
|
| CVE-2020-24750 |
|
Unsafe Deserialization in fasterxml (CVE-2020-24750)
vulnerability in fasterxml (CVE-2020-24750). Successful exploitation can lead to full system takeover.
|
| CVE-2020-24616 |
|
Unsafe Deserialization in fasterxml (CVE-2020-24616)
vulnerability in fasterxml (CVE-2020-24616). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14195 |
|
Unsafe Deserialization in fasterxml (CVE-2020-14195)
vulnerability in fasterxml (CVE-2020-14195). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14060 |
|
Unsafe Deserialization in apache (CVE-2020-14060)
vulnerability in apache (CVE-2020-14060). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14061 |
|
Unsafe Deserialization in fasterxml (CVE-2020-14061)
vulnerability in fasterxml (CVE-2020-14061). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14062 |
|
Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9484 |
|
Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
|
| CVE-2020-11619 |
|
Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11111 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
| CVE-2020-11112 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10968 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2020-9548 |
|
Unsafe Deserialization in fasterxml (CVE-2020-9548)
vulnerability in fasterxml (CVE-2020-9548). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9546 |
|
Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
|
| CVE-2019-17571 |
|
Unsafe Deserialization in log4j:log4j (CVE-2019-17571)
vulnerability in log4j:log4j (CVE-2019-17571). Successful exploitation can lead to full system takeover.
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-9515 |
|
Unsafe Deserialization in dozer-project (CVE-2014-9515)
vulnerability in dozer-project (CVE-2014-9515). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5641 |
|
Unsafe Deserialization in apache (CVE-2017-5641)
vulnerability in apache (CVE-2017-5641). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17672 |
|
Unsafe Deserialization in deserialization (CVE-2017-17672)
vulnerability in deserialization (CVE-2017-17672). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11283 |
|
Unsafe Deserialization in deserialization (CVE-2017-11283)
vulnerability in deserialization (CVE-2017-11283). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11284 |
|
Unsafe Deserialization in deserialization (CVE-2017-11284)
vulnerability in deserialization (CVE-2017-11284). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000207 |
|
Unsafe Deserialization in swagger (CVE-2017-1000207)
vulnerability in swagger (CVE-2017-1000207). Successful exploitation can lead to full system takeover.
|
| CVE-2017-4995 |
|
Unsafe Deserialization in deserialization (CVE-2017-4995)
vulnerability in deserialization (CVE-2017-4995). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8045 |
|
Unsafe Deserialization in pivotal-software (CVE-2017-8045)
vulnerability in pivotal-software (CVE-2017-8045). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000248 |
|
Redis-store
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
|
| CVE-2017-1000208 |
|
Unsafe Deserialization in swagger (CVE-2017-1000208)
vulnerability in swagger (CVE-2017-1000208). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000195 |
|
Unsafe Deserialization in octobercms (CVE-2017-1000195)
vulnerability in octobercms (CVE-2017-1000195). Data can be tampered with by attackers.
|
| CVE-2017-12633 |
|
Unsafe Deserialization in apache (CVE-2017-12633)
vulnerability in apache (CVE-2017-12633). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12634 |
|
Unsafe Deserialization in apache (CVE-2017-12634)
vulnerability in apache (CVE-2017-12634). Successful exploitation can lead to full system takeover.
|
| CVE-2015-7501 |
|
Unsafe Deserialization in apache (CVE-2015-7501)
vulnerability in apache (CVE-2015-7501). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000148 |
|
Unsafe Deserialization in mahara (CVE-2017-1000148)
vulnerability in mahara (CVE-2017-1000148). Successful exploitation can lead to full system takeover.
|
| CVE-2016-5003 |
|
Unsafe Deserialization in apache (CVE-2016-5003)
vulnerability in apache (CVE-2016-5003). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12796 |
|
Unsafe Deserialization in openmrs (CVE-2017-12796)
vulnerability in openmrs (CVE-2017-12796). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12628 |
|
Unsafe Deserialization in apache (CVE-2017-12628)
vulnerability in apache (CVE-2017-12628). Successful exploitation can lead to full system takeover.
|
| CVE-2015-5164 |
|
Unsafe Deserialization in pulpproject (CVE-2015-5164)
vulnerability in pulpproject (CVE-2015-5164). Successful exploitation can lead to full system takeover.
|
| CVE-2016-8736 |
|
Unsafe Deserialization in apache (CVE-2016-8736)
vulnerability in apache (CVE-2016-8736). Successful exploitation can lead to full system takeover.
|
| CVE-2017-0903 |
|
Unsafe Deserialization in deserialization (CVE-2017-0903)
vulnerability in deserialization (CVE-2017-0903). Successful exploitation can lead to full system takeover.
|
| CVE-2017-0806 |
|
Unsafe Deserialization in google (CVE-2017-0806)
vulnerability in google (CVE-2017-0806). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14702 |
|
Unsafe Deserialization in deserialization (CVE-2017-14702)
vulnerability in deserialization (CVE-2017-14702). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10932 |
|
Unsafe Deserialization in c (CVE-2017-10932)
vulnerability in c (CVE-2017-10932). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14141 |
|
Unsafe Deserialization in kaltura (CVE-2017-14141)
vulnerability in kaltura (CVE-2017-14141). Successful exploitation can lead to full system takeover.
|
| CVE-2016-8744 |
|
Unsafe Deserialization in apache (CVE-2016-8744)
vulnerability in apache (CVE-2016-8744). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12612 |
|
Unsafe Deserialization in apache (CVE-2017-12612)
vulnerability in apache (CVE-2017-12612). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14035 |
|
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
|