• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-502

CVE-2021-36564

February 23, 2023 by

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendorleagueflysystem-cached-adaptersrcStorageAdapter.php.

CVE-2021-36567

February 23, 2023 by

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component LeagueFlysystemCachedStorageAbstractCache.

CVE-2021-36336

February 23, 2023 by

Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.

CVE-2021-36231

February 23, 2023 by

Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.

CVE-2021-36163

February 23, 2023 by

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and therefore without applying the dubbo properties for applying allowed or blocked type lists. In addition, the generic service is always exposed and therefore attackers do not need to figure out a valid service/method name pair. This is fixed in 2.7.13, 2.6.10.1

CVE-2021-35971

February 23, 2023 by

Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 78
  • Go to page 79
  • Go to page 80
  • Go to page 81
  • Go to page 82
  • Interim pages omitted …
  • Go to page 129
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE