Skip to main content

CWE archive

CWE-502 CVEs

Programmatic archive

2,961 CVEs tagged with CWE-5021,131 Critical, 1,426 High, 331 Medium, 73 Low, 0 Unrated.

CVE-2019-4279

Published May 17, 2019

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from unt…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10912

Published May 16, 2019

In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unseri…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10924

Published May 14, 2019

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.3). The vulnerability could allow an attacker to execute arbitrary code if the attacker tricks a legit…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11830

Published May 9, 2019

PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attac…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11458

Published May 8, 2019

An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5434

Published May 6, 2019

An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7214

Published Apr 24, 2019

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9056

Published Apr 11, 2019

An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7361

Published Apr 9, 2019

An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autode…

CVSS 7.8 · High

CVE-2019-10867

Published Apr 4, 2019

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12680

Published Apr 2, 2019

The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a denial of service in applications that use this library (e.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12679

Published Apr 2, 2019

The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of service in applications that use this library (e.g., the standa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18365

Published Mar 28, 2019

The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs beca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10068

Published Mar 26, 2019

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was pos…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-9061

Published Mar 26, 2019

An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9057

Published Mar 26, 2019

An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated obje…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9055

Published Mar 26, 2019

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20221

Published Mar 21, 2019

Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. T…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19276

Published Mar 21, 2019

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-12023

Published Mar 21, 2019

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the servi…

CVSS 7.5 · High

CVE-2018-12022

Published Mar 21, 2019

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the servi…

CVSS 7.5 · High

CVE-2019-0192

Published Mar 7, 2019

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2019-0187

Published Mar 6, 2019

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,701-2,725 of 2,961 CVEsPage 109 of 119