Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

3,025 CVEs tagged with CWE-5021,168 Critical, 1,451 High, 334 Medium, 72 Low, 0 Unrated.

CVE-2019-5326

Published Feb 27, 2020

An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8441

Published Feb 19, 2020

JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20477

Published Feb 19, 2020

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9006

Published Feb 17, 2020

The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-2123

Published Feb 12, 2020

Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0618

Published Feb 11, 2020

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Rem…

CVSS 8.8 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-8840

Published Feb 10, 2020

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

CVSS 9.8 · Critical

CVE-2013-4521

Published Feb 6, 2020

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows rem…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-3716

Published Jan 29, 2020

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitati…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2020-6959

Published Jan 22, 2020

The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MA…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2019-17635

Published Jan 17, 2020

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the h…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2555

Published Jan 15, 2020

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0,…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
49.1
KEV listed

CVE-2019-17076

Published Jan 8, 2020

An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1000027

Published Jan 2, 2020

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14466

Published Dec 31, 2019

The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19470

Published Dec 30, 2019

Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all ve…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18211

Published Dec 23, 2019

An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19909

Published Dec 19, 2019

An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,651-2,675 of 3,025 CVEsPage 107 of 121