Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

3,025 CVEs tagged with CWE-5021,168 Critical, 1,450 High, 335 Medium, 72 Low, 0 Unrated.

CVE-2019-19849

Published Dec 17, 2019

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to i…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19826

Published Dec 16, 2019

The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP obje…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18316

Published Dec 12, 2019

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain r…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18283

Published Dec 12, 2019

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Applicatio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19373

Published Dec 11, 2019

An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18935

Published Dec 11, 2019

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys…

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
68.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-17556

Published Dec 4, 2019

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18580

Published Nov 26, 2019

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially expl…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15271

Published Nov 26, 2019

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands…

CVSS 8.8 · High
evidence mentions
3
Buzz score
45.4
KEV listed

CVE-2019-4561

Published Nov 20, 2019

IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1373

Published Nov 12, 2019

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerabil…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-8141

Published Nov 6, 2019

A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative pri…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18364

Published Oct 31, 2019

In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18601

Published Oct 29, 2019

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to cras…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12017

Published Oct 24, 2019

A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login and ticket issuance. An attacke…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13116

Published Oct 16, 2019

The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collecti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,676-2,700 of 3,025 CVEsPage 108 of 121