Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-36182 |
|
Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36179 |
|
Unsafe Deserialization in apache (CVE-2020-36179)
vulnerability in apache (CVE-2020-36179). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36180 |
|
Unsafe Deserialization in apache (CVE-2020-36180)
vulnerability in apache (CVE-2020-36180). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36184 |
|
Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36185 |
|
Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36186 |
|
Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36187 |
|
Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36181 |
|
Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35728 |
|
Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35490 |
|
Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35491 |
|
Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
|
| CVE-2020-17103 |
|
, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID...
, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID...
|
| CVE-2020-25649 |
|
XXE (XML External Entity) in fasterxml (CVE-2020-25649)
vulnerability in fasterxml (CVE-2020-25649). Data can be tampered with by attackers.
|
| CVE-2020-7564 |
|
Vulnerability in schneider-electric (CVE-2020-7564)
vulnerability in schneider-electric (CVE-2020-7564). Successful exploitation can lead to full system takeover.
|
| CVE-2020-15670 |
|
Vulnerability in mozilla (CVE-2020-15670)
vulnerability in mozilla (CVE-2020-15670). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14060 |
|
Unsafe Deserialization in apache (CVE-2020-14060)
vulnerability in apache (CVE-2020-14060). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14062 |
|
Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1102 |
|
Unrestricted File Upload in microsoft (CVE-2020-1102)
vulnerability in microsoft (CVE-2020-1102). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1093 |
|
Buffer Overflow in microsoft (CVE-2020-1093)
vulnerability in microsoft (CVE-2020-1093). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1108 |
|
Vulnerability in csharp (CVE-2020-1108)
vulnerability in csharp (CVE-2020-1108). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-1092 |
|
Buffer Overflow in microsoft (CVE-2020-1092)
vulnerability in microsoft (CVE-2020-1092). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1069 |
|
Buffer Overflow in csharp (CVE-2020-1069)
vulnerability in csharp (CVE-2020-1069). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1058 |
|
Buffer Overflow in microsoft (CVE-2020-1058)
vulnerability in microsoft (CVE-2020-1058). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1060 |
|
Buffer Overflow in microsoft (CVE-2020-1060)
vulnerability in microsoft (CVE-2020-1060). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1062 |
|
Buffer Overflow in microsoft (CVE-2020-1062)
vulnerability in microsoft (CVE-2020-1062). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1064 |
|
Vulnerability in microsoft (CVE-2020-1064)
vulnerability in microsoft (CVE-2020-1064). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1066 |
|
Privilege Escalation in csharp (CVE-2020-1066)
vulnerability in csharp (CVE-2020-1066). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1023 |
|
Unrestricted File Upload in microsoft (CVE-2020-1023)
vulnerability in microsoft (CVE-2020-1023). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1024 |
|
Unrestricted File Upload in microsoft (CVE-2020-1024)
vulnerability in microsoft (CVE-2020-1024). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1035 |
|
Buffer Overflow in microsoft (CVE-2020-1035)
vulnerability in microsoft (CVE-2020-1035). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9484 |
|
Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
|
| CVE-2020-11619 |
|
Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11111 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
| CVE-2020-11112 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10968 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2019-13721 |
|
Use-After-Free in google (CVE-2019-13721)
vulnerability in google (CVE-2019-13721). Successful exploitation can lead to full system takeover.
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-1068 KEV |
|
[KEV] Vulnerability in Microsoft sql-server (CVE-2019-1068)
vulnerability in Microsoft sql-server (CVE-2019-1068). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-15756 |
|
Vulnerability in spring (CVE-2018-15756)
vulnerability in spring (CVE-2018-15756). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-1258 |
|
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
|
| CVE-2018-1259 |
|
XXE (XML External Entity) in broadcom (CVE-2018-1259)
vulnerability in broadcom (CVE-2018-1259). Confidential information can be exposed externally.
|
| CVE-2018-1274 |
|
Vulnerability in dos (CVE-2018-1274)
vulnerability in dos (CVE-2018-1274). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12174 |
|
Vulnerability in apache (CVE-2017-12174)
vulnerability in apache (CVE-2017-12174). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-6926 |
|
OS Command Injection in misp-project (CVE-2018-6926)
OS command injection in misp-project (CVE-2018-6926). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12626 |
|
Vulnerability in org.apache.poi:poi (CVE-2017-12626)
vulnerability in org.apache.poi:poi (CVE-2017-12626). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.17` or later.
|
| CVE-2017-17983 |
|
SQL Injection in sqli (CVE-2017-17983)
SQL injection in sqli (CVE-2017-17983). Successful exploitation can lead to full system takeover.
|