Known vulnerabilities in xstream - page 2

Vendor: XStream
Software: xstream
Software CPE: cpe:2.3:a:x-stream:xstream:*:*:*:*:*:*:*:*
Total vulnerabilities: 36
Public exploits: 11
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.5

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting xstream xstream is affected by 36 known vulnerabilities: 1 critical, 21 high, 14 medium Critical High Medium Low

Vulnerabilities (36)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU52572 - Deserialization of Untrusted Data
CVE-2021-21349
CWE-502 Medium
Available
No
1.4.16 26.04.2021 SB2021042607
SB2021062144
SB2021062145
and 16 more
#VU52571 - Deserialization of Untrusted Data
CVE-2021-21351
CWE-502 High
No
No
1.4.16 26.04.2021 SB2021042607
SB2021062144
SB2021062145
and 19 more
#VU52570 - Resource exhaustion
CVE-2021-21341
CWE-400 Medium
No
No
1.4.16 26.04.2021 SB2021042607
SB2021062144
SB2021062145
and 16 more
#VU52569 - Deserialization of Untrusted Data
CVE-2021-21342
CWE-502 High
No
No
1.4.16 26.04.2021 SB2021042607
SB2021062144
SB2021062145
and 19 more
#VU52568 - Deserialization of Untrusted Data
CVE-2021-21343
CWE-502 Medium
No
No
1.4.16 26.04.2021 SB2021042607
SB2021062144
SB2021062145
and 16 more
#VU52566 - Resource exhaustion
CVE-2021-21348
CWE-400 Medium
No
No
1.4.16 26.04.2021 SB2021042607
SB2021062144
SB2021062145
and 16 more
#VU52565 - Deserialization of Untrusted Data
CVE-2021-21350
CWE-502 High
No
No
1.4.16 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 21 more
#VU52564 - Deserialization of Untrusted Data
CVE-2021-21347
CWE-502 High
No
No
1.4.16 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 21 more
#VU52563 - Deserialization of Untrusted Data
CVE-2021-21346
CWE-502 High
No
No
1.4.16 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 21 more
#VU52562 - Deserialization of Untrusted Data
CVE-2021-21345
CWE-502 High
No
No
1.4.16 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 28 more
#VU52561 - Deserialization of Untrusted Data
CVE-2021-21344
CWE-502 High
No
No
1.4.16 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 19 more
#VU49040 - Improper input validation
CVE-2020-26259
CWE-20 Medium
Available
No
1.4.15 16.12.2020 SB2020121623
SB2021010802
SB2021062144
and 17 more
#VU49041 - Server-Side Request Forgery (SSRF)
CVE-2020-26258
CWE-918 Medium
Available
No
1.4.15 16.12.2020 SB2020121623
SB2021010802
SB2021062144
and 16 more
#VU49039 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-26217
CWE-78 Medium
Available
No
1.4.14 16.11.2020 SB2020111622
SB2020121624
SB20210120118
and 14 more
#VU22876 - Improper input validation
CVE-2013-7285
CWE-20 High
Available
No
1.4.11 20.11.2019 SB2019072308
SB2019112016
SB2016121356
and 7 more
#VU22875 - Deserialization of Untrusted Data
CVE-2019-10173
CWE-502 High
No
No
1.4.11 20.11.2019 SB2019072308
SB2019112016
SB2019121922
and 11 more


Showing elements 21 - 40 out of 36