CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
2,435 results Clear all
CVE-2020-35938 7.5 HIGH EPSS 0.01
Pickplugins Post Grid < 2.0.73 - Insecure Deserialization
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
CWE-502 Jan 01, 2021
CVE-2020-35932 7.5 HIGH EPSS 0.01
Tribulant Newsletter < 6.8.2 - Insecure Deserialization
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
CWE-502 Jan 01, 2021
CVE-2020-26165 8.8 HIGH EPSS 0.01
Qdpm < 9.1 - Insecure Deserialization
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
CWE-502 Dec 31, 2020
CVE-2019-7725 9.8 CRITICAL 1 Writeup EPSS 0.01
NukeViet <4.3.04 - Deserialization
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
CWE-502 Dec 31, 2020
CVE-2020-35728 8.1 HIGH 3 PoCs Analysis EPSS 0.40
Fasterxml Jackson-databind < 2.9.10.8 - Insecure Deserialization
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
CWE-502 Dec 27, 2020
CVE-2020-35491 8.1 HIGH 2 PoCs Analysis EPSS 0.06
Fasterxml Jackson-databind < 2.9.10.8 - Insecure Deserialization
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
CWE-502 Dec 17, 2020
CVE-2020-35490 8.1 HIGH 2 PoCs Analysis EPSS 0.04
Fasterxml Jackson-databind < 2.9.10.8 - Insecure Deserialization
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
CWE-502 Dec 17, 2020
CVE-2020-22083 9.8 CRITICAL 1 Writeup EPSS 0.05
Jsonpickle < 1.4.1 - Insecure Deserialization
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data
CWE-502 Dec 17, 2020
CVE-2020-20136 9.8 CRITICAL EPSS 0.00
Quantconnect Lean < 2.4.0.1 - Insecure Deserialization
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
CWE-502 Dec 14, 2020
CVE-2020-9301 8.8 HIGH 1 Writeup EPSS 0.01
Linuxfoundation Spinnaker < 1.21.5 - Insecure Deserialization
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.
CWE-502 Dec 11, 2020
CVE-2020-17144 8.4 HIGH KEV 5 PoCs Analysis EPSS 0.93
Microsoft Exchange - RCE
Microsoft Exchange Remote Code Execution Vulnerability
CWE-502 Dec 10, 2020
CVE-2020-17531 9.8 CRITICAL 1 PoC Analysis EPSS 0.36
Apache Tapestry 4 - Deserialization
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.
CWE-502 Dec 08, 2020
CVE-2020-28948 7.8 HIGH 3 PoCs Analysis EPSS 0.76
PHP Archive Tar < 1.4.11 - Insecure Deserialization
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CWE-502 Nov 19, 2020
CVE-2020-27131 8.1 HIGH EPSS 0.88
Cisco Security Manager - RCE
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit these vulnerabilities by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of NT AUTHORITY\SYSTEM on the Windows target host. Cisco has not released software updates that address these vulnerabilities.
CWE-502 Nov 17, 2020
CVE-2020-5664 9.8 CRITICAL EPSS 0.06
XooNIps <3.49 - Code Injection
Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.
CWE-502 Nov 16, 2020
CVE-2020-28339 7.5 HIGH EPSS 0.01
Welcart E-commerce < 1.9.36 - Insecure Deserialization
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain.
CWE-502 Nov 07, 2020
CVE-2020-26207 8.0 HIGH 1 Writeup EPSS 0.01
Databaseschemareader Dbschemareader - Insecure Deserialization
DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.
CWE-502 Nov 04, 2020
CVE-2020-28032 9.8 CRITICAL 1 PoC Analysis EPSS 0.26
Wordpress < 5.5.2 - Insecure Deserialization
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CWE-502 Nov 02, 2020
CVE-2020-10721 7.8 HIGH EPSS 0.00
fabric8-maven-plugin >=4.0.0 - Code Injection
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CWE-502 Oct 22, 2020
CVE-2020-15244 8.0 HIGH EPSS 0.01
Magento <19.4.8-20.0.4 - Code Injection
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.
CWE-502 Oct 21, 2020