Vulnerabilities
Summary — last 7 days
New vulnerabilities2,731▼ 12 vs. last week
Critical / high1,272▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
268 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (8.1) | 4.1% | 💥 PoC | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+41 | 1/7/2021 | 8/25/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS. | |
| Modified | High (8.1) | 17% | 💥 PoC | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+39 | 1/7/2021 | 8/25/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS. | |
| Analyzed | High (8.1) | 5.0% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 1/6/2021 | 10/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool. | |
| Modified | High (8.1) | 8.4% | 💥 PoC | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+41 | 1/6/2021 | 8/25/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource. | |
| Modified | High (8.1) | 4.1% | — | Netapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+40 | 1/6/2021 | 8/25/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS. | |
| Modified | High (8.1) | 4.0% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+36 | 1/6/2021 | 10/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource. | |
| Modified | High (8.1) | 8.8% | 💥 PoC | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 1/6/2021 | 10/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource. | |
| Modified | High (8.1) | 4.2% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 1/6/2021 | 10/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource. | |
| Modified | High (8.1) | 4.2% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 1/6/2021 | 10/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource. | |
| Modified | High (8.1) | 4.2% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 1/6/2021 | 10/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource. | |
| Analyzed | High (8.1) | 13% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Service Level ManagerOracle Agile Product Lifecycle Management+36 | 12/27/2020 | 8/25/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl). | |
| Modified | High (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 12/14/2020 | 6/17/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modified | High (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 12/14/2020 | 6/17/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modified | Low (3.7) | 3.9% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+18 | 12/14/2020 | 6/17/2026 | A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. | |
| Modified | Critical (9.8) | 6.6% | — | Ubilling | 12/10/2020 | 6/17/2026 | Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software. | |
| Modified | High (7.5) | 17% | — | Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+35 | 12/3/2020 | 10/8/2026 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. | |
| Modified | Medium (5.4) | 0.56% | — | Ericsson Bscs IX R18 Billing & Rating AdmxEricsson Bscs IX R18 Billing & Rating MX | 11/27/2020 | 6/17/2026 | In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceDataSU Access Rights Group. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability.… | |
| Modified | Medium (5.4) | 0.56% | — | Ericsson Bscs IX R18 Billing & Rating AdmxEricsson Bscs IX R18 Billing & Rating MX | 11/27/2020 | 6/17/2026 | In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or exploiting admins'… | |
| Modified | Critical (9.8) | 2.6% | — | Water Billing System Project Water Billing System | 11/17/2020 | 6/17/2026 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php. | |
| Modified | Medium (6.7) | 1.2% | — | Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools | 7/27/2020 | 6/17/2026 | In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization. | |
| Modified | Medium (4.8) | 1.1% | — | Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools | 7/27/2020 | 6/17/2026 | Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive. | |
| Modified | High (7.4) | 5.2% | — | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+14 | 7/15/2020 | 6/17/2026 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | |
| Modified | High (7.5) | 6.0% | — | PerlNetapp Oncommand Workflow AutomationNetapp Snap Creator FrameworkFedoraproject Fedora+12 | 6/5/2020 | 6/17/2026 | regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. | |
| Modified | High (8.6) | 4.9% | — | PerlFedoraproject FedoraOpensuse LeapNetapp Oncommand Workflow Automation+13 | 6/5/2020 | 6/17/2026 | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. | |
| Modified | High (8.2) | 11% | — | PerlFedoraproject FedoraOpensuse LeapOracle Communications Billing AND Revenue Management+11 | 6/5/2020 | 6/17/2026 | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. |