Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2019-06-21 CVE-2019-11011 Deserialization of Untrusted Data vulnerability in Akamai Cloudtest
Akamai CloudTest before 58.30 allows remote code execution.
network
low complexity
akamai CWE-502
critical
9.8
2019-06-20 CVE-2018-15890 Deserialization of Untrusted Data vulnerability in Ethereum Ethereumj 1.8.2
An issue was discovered in EthereumJ 1.8.2.
network
low complexity
ethereum CWE-502
critical
9.8
2019-06-19 CVE-2019-12814 Deserialization of Untrusted Data vulnerability in multiple products
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9.
network
high complexity
fasterxml debian CWE-502
5.9
2019-06-18 CVE-2019-12868 Deserialization of Untrusted Data vulnerability in Misp 2.4.109
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
network
low complexity
misp CWE-502
7.2
2019-06-13 CVE-2019-12799 Deserialization of Untrusted Data vulnerability in Shopware
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated.
network
low complexity
shopware CWE-502
8.8
2019-06-12 CVE-2019-7840 Deserialization of Untrusted Data vulnerability in Adobe Coldfusion 11.0/2016/2018
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability.
network
low complexity
adobe CWE-502
critical
9.8
2019-06-06 CVE-2019-12760 Deserialization of Untrusted Data vulnerability in Parso Project Parso
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache.
network
high complexity
parso-project CWE-502
7.5
2019-06-06 CVE-2019-11080 Deserialization of Untrusted Data vulnerability in Sitecore Experience Platform
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.
network
low complexity
sitecore CWE-502
8.8
2019-06-05 CVE-2019-11956 Deserialization of Untrusted Data vulnerability in HP Intelligent Management Center
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-502
8.8
2019-06-05 CVE-2019-11950 Deserialization of Untrusted Data vulnerability in HP Intelligent Management Center
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-502
8.8