Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

3,057 CVEs tagged with CWE-5021,172 Critical, 1,471 High, 341 Medium, 72 Low, 1 Unrated.

CVE-2018-19274

Published Nov 17, 2018

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15381

Published Nov 8, 2018

A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the ro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-8021

Published Nov 7, 2018

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was release…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1851

Published Oct 31, 2018

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a spe…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18013

Published Oct 24, 2018

* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18628

Published Oct 23, 2018

An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18589

Published Oct 23, 2018

A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerabilit…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15616

Published Oct 17, 2018

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-3245

Published Oct 17, 2018

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18240

Published Oct 11, 2018

Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechani…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15425

Published Oct 5, 2018

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the un…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3972

Published Sep 26, 2018

An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15965

Published Sep 25, 2018

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15959

Published Sep 25, 2018

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15958

Published Sep 25, 2018

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15957

Published Sep 25, 2018

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9045

Published Sep 17, 2018

A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0750

Published Sep 11, 2018

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by inject…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1567

Published Sep 7, 2018

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrus…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15514

Published Sep 1, 2018

HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,851-2,875 of 3,057 CVEsPage 115 of 123