cwe-502
Safeguard articles tagged "cwe-502" — guides, analysis, and best practices for software supply chain and application security.
77 articles
CVE-2020-17144: Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2020-17144 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-7961: Liferay Portal Deserialization of Untrusted Data Vulnerability
CVE-2020-7961 affects Liferay Liferay Portal and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-35464: ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
CVE-2021-35464 affects ForgeRock Access Management (AM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2017-9805: Apache Struts Deserialization of Untrusted Data Vulnerability
CVE-2017-9805 affects Apache Struts and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2018-4939: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
CVE-2018-4939 affects Adobe ColdFusion and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-42321: Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42321 affects Microsoft Exchange and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-17.
CVE-2021-44228: Apache Log4j2 Remote Code Execution Vulnerability
CVE-2021-44228 affects Apache Log4j2 and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-12-10.
CVE-2017-12149: Red Hat JBoss Application Server Remote Code Execution Vulnerability
CVE-2017-12149 affects Red Hat JBoss Application Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-12-10.
CVE-2020-10189: Zoho ManageEngine Desktop Central File Upload Vulnerability
CVE-2020-10189 affects Zoho ManageEngine and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2019-18935: Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
CVE-2019-18935 affects Progress Telerik UI for ASP.NET AJAX and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2015-4852: Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
CVE-2015-4852 affects Oracle WebLogic Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-2555: Oracle Multiple Products Remote Code Execution Vulnerability
CVE-2020-2555 affects Oracle Multiple Products and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.