CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
2,435 results Clear all
CVE-2019-10086 7.3 HIGH 1 PoC EPSS 0.01
Apache Commons Beanutils 1.9.2 - Info Disclosure
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
CWE-502 Aug 20, 2019
CVE-2019-0344 9.8 CRITICAL KEV EPSS 0.41
SAP Commerce Cloud - Insecure Deserialization
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
CWE-502 Aug 14, 2019
CVE-2019-14439 7.5 HIGH 3 PoCs Analysis EPSS 0.10
FasterXML jackson-databind <2.9.9.2 - Info Disclosure
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
CWE-502 Jul 30, 2019
CVE-2018-11779 9.8 CRITICAL EPSS 0.01
Apache Storm < 1.2.2 - Insecure Deserialization
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
CWE-502 Jul 26, 2019
CVE-2019-10173 9.8 CRITICAL EPSS 0.93
xstream API <1.4.11 - Use After Free
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
CWE-502 Jul 23, 2019
CVE-2019-1010306 9.8 CRITICAL EPSS 0.02
Slanger 0.6.0 - RCE
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.
CWE-502 Jul 15, 2019
CVE-2019-10135 7.2 HIGH EPSS 0.01
osbs-client <0.56.1 - Code Injection
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.
CWE-502 Jul 11, 2019
CVE-2018-11307 9.8 CRITICAL 2 PoCs Analysis EPSS 0.13
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
CWE-502 Jul 09, 2019
CVE-2019-12747 8.8 HIGH EPSS 0.02
Typo3 < 8.7.26 - Insecure Deserialization
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
CWE-502 Jul 09, 2019
CVE-2019-12384 5.9 MEDIUM 4 PoCs Analysis EPSS 0.52
FasterXML jackson-databind <2.9.9.1 - Deserialization
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
CWE-502 Jun 24, 2019
CVE-2019-11011 9.8 CRITICAL EPSS 0.04
Akamai Cloudtest < 58.30 - Insecure Deserialization
Akamai CloudTest before 58.30 allows remote code execution.
CWE-502 Jun 21, 2019
CVE-2018-15890 9.8 CRITICAL 1 Writeup EPSS 0.01
Ethereumj - Insecure Deserialization
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.
CWE-502 Jun 20, 2019
CVE-2019-12814 5.9 MEDIUM 3 PoCs Analysis EPSS 0.18
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.
CWE-502 Jun 19, 2019
CVE-2019-12868 7.2 HIGH 1 Writeup EPSS 0.02
Misp - Insecure Deserialization
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
CWE-502 Jun 18, 2019
CVE-2019-12799 8.8 HIGH EPSS 0.29
Shopware < 5.6.0 - Insecure Deserialization
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
CWE-502 Jun 13, 2019
CVE-2019-7840 9.8 CRITICAL EPSS 0.50
ColdFusion <Update 3 - Deserialization
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
CWE-502 Jun 12, 2019
CVE-2019-12760 3.3 LOW EPSS 0.01
Parso < 0.4.0 - Insecure Deserialization
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration.
CWE-502 Jun 06, 2019
CVE-2019-11080 8.8 HIGH 1 PoC Analysis EPSS 0.42
Sitecore Experience Platform < 9.1.1 - Insecure Deserialization
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.
CWE-502 Jun 06, 2019
CVE-2019-11956 8.8 HIGH EPSS 0.32
HPE IMC <7.3 - RCE
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CWE-502 Jun 05, 2019
CVE-2019-11950 8.8 HIGH EPSS 0.38
HPE IMC <7.3 - RCE
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CWE-502 Jun 05, 2019