Skip to content
English

Products › Server applications and development

Server applications and development

ERP, business applications and databases

ERP and CRM suites, business applications, business intelligence tools and databases.

For example: SAP NetWeaver, Oracle E-Business Suite, Metabase, SQL Server.

Category RSS feed

Pace of additions

Number of “Business apps and data” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20252
Oct 4, 2025 to Nov 2, 20254
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20262
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20261
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20262
Jul 1, 2026 to Jul 30, 20261
Jul 31, 2026 to Aug 29, 20262
Aug 30, 2026 to Sep 28, 2026 (in progress)0

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Metabase

    CVE-2026-72898

    Active CERT-FR alertHunt for compromise (CISA)

    Metabase SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 11, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2Oracle E-Business Suite

    CVE-2026-46817

    Hunt for compromise (CISA)

    Oracle E-Business Suite Improper Privilege Management Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 15, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3PTC Windchill and FlexPLM

    CVE-2026-12569

    Ransomware

    PTC Windchill and FlexPLM Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 25, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Oracle PeopleSoft

    CVE-2026-35273

    Ransomware

    Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 12, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Samsung MagicINFO Server

    CVE-2024-7399

    CVE from 2024, added in 2026

    Samsung MagicINFO 9 Server Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  6. Rank 6OSGeo GeoServer

    CVE-2025-58360

    OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 11, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Oracle E-Business Suite

    CVE-2025-61882

    Ransomware

    Oracle E-Business Suite Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Dassault Systèmes DELMIA Apriso

    CVE-2025-6205

    Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 28, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  9. Rank 9Microsoft SQL Server

    CVE-2019-1068

    Hunt for compromise (CISA)CVE from 2019, added in 2026

    Microsoft SQL Server Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  10. Rank 10Dassault Systèmes DELMIA Apriso

    CVE-2025-6204

    Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 28, 2025
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
Show 62 more vulnerabilities
  1. Rank 11MongoDB Server

    CVE-2025-14847

    MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  2. Rank 12Oracle E-Business Suite

    CVE-2025-61884

    Ransomware

    Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  3. Rank 13Adminer

    CVE-2021-21311

    CVE from 2021, added in 2025

    Adminer Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  4. Rank 14OSGeo GeoServer

    CVE-2022-24816

    CVE from 2022, added in 2024

    OSGeo GeoServer JAI-EXT Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 26, 2024
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  5. Rank 15SAP NetWeaver

    CVE-2022-22536

    SAP Multiple Products HTTP Request Smuggling Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  6. Rank 16Redis Server

    CVE-2022-0543

    Debian-specific Redis Server Lua Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  7. Rank 17Elastic Kibana

    CVE-2019-7609

    CVE from 2019, added in 2022

    Kibana Arbitrary Code Execution

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  8. Rank 18SAP NetWeaver

    CVE-2010-5326

    CVE from 2010, added in 2021

    SAP NetWeaver Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  9. Rank 19SAP NetWeaver

    CVE-2020-6287

    SAP NetWeaver Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  10. Rank 20Qlik Sense

    CVE-2023-48365

    RansomwareCVE from 2023, added in 2025

    Qlik Sense HTTP Tunneling Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 13, 2025
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  11. Rank 21Qlik Sense

    CVE-2023-41265

    Ransomware

    Qlik Sense HTTP Tunneling Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  12. Rank 22MongoDB mongo-express

    CVE-2019-10758

    CVE from 2019, added in 2021

    MongoDB mongo-express Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.9 (critical)
  13. Rank 23Samsung MagicINFO Server

    CVE-2025-4632

    Samsung MagicINFO 9 Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24SAP NetWeaver

    CVE-2025-31324

    Ransomware

    SAP NetWeaver Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 29, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Hitachi Vantara Pentaho Business Analytics (BA) Server

    CVE-2022-43939

    CVE from 2022, added in 2025

    Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Apache HugeGraph

    CVE-2024-27348

    Apache HugeGraph-Server Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Apache OFBiz

    CVE-2024-38856

    Apache OFBiz Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 27, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Apache OFBiz

    CVE-2024-32113

    Apache OFBiz Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Rank 29OSGeo GeoServer

    CVE-2024-36401

    OSGeo GeoServer GeoTools Eval Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Progress Telerik Report Server

    CVE-2024-4358

    Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  21. Rank 31NextGen Healthcare Mirth Connect

    CVE-2023-43208

    Ransomware

    NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Apache Superset

    CVE-2023-27524

    Apache Superset Insecure Default Initialization of Resource Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Novi Survey

    CVE-2023-29492

    Novi Survey Insecure Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  24. Rank 34Oracle E-Business Suite

    CVE-2022-21587

    Ransomware

    Oracle E-Business Suite Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Apache CouchDB

    CVE-2022-24706

    Apache CouchDB Insecure Default Initialization of Resource Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  26. Rank 36SAP NetWeaver

    CVE-2016-2386

    CVE from 2016, added in 2022

    SAP NetWeaver SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  27. Rank 37phpMyAdmin

    CVE-2009-1151

    CVE from 2009, added in 2022

    phpMyAdmin Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  28. Rank 38Elastic Elasticsearch

    CVE-2015-1427

    CVE from 2015, added in 2022

    Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  29. Rank 39IBM Planning Analytics (TM1)

    CVE-2019-4716

    CVE from 2019, added in 2021

    IBM Planning Analytics Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  30. Rank 40SAP Solution Manager

    CVE-2020-6207

    SAP Solution Manager Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  31. Rank 41BQE BillQuick Web Suite

    CVE-2021-42258

    Ransomware

    BQE BillQuick Web Suite SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  32. Rank 42SAP NetWeaver

    CVE-2025-42999

    Ransomware

    SAP NetWeaver Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 15, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  33. Rank 43Dassault Systèmes DELMIA Apriso

    CVE-2025-5086

    Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 11, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  34. Rank 44Advantive VeraCore

    CVE-2024-57968

    Advantive VeraCore Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  35. Rank 45Oracle Agile PLM

    CVE-2024-20953

    Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 24, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  36. Rank 46Trimble Cityworks

    CVE-2025-0994

    Trimble Cityworks Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 7, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  37. Rank 47Microsoft SQL Server

    CVE-2020-0618

    RansomwareCVE from 2020, added in 2024

    Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  38. Rank 48Apache Spark

    CVE-2022-33891

    Apache Spark Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  39. Rank 49SugarCRM Sugar (Sell, Serve, Enterprise)

    CVE-2023-22952

    Multiple SugarCRM Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 2, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  40. Rank 50TIBCO JasperReports

    CVE-2018-5430

    CVE from 2018, added in 2022

    TIBCO JasperReports Server Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 29, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  41. Rank 51SAP NetWeaver

    CVE-2021-38163

    SAP NetWeaver Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  42. Rank 52Apache Kylin

    CVE-2020-1956

    CVE from 2020, added in 2022

    Apache Kylin OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  43. Rank 53Justice AV Solutions (JAVS) JAVS Viewer

    CVE-2024-4978

    Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 29, 2024
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  44. Rank 54Acclaim Systems USAHERDS

    CVE-2021-44207

    CVE from 2021, added in 2024

    Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 23, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  45. Rank 55Elastic Elasticsearch

    CVE-2014-3120

    CVE from 2014, added in 2022

    Elasticsearch Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  46. Rank 56SAP NetWeaver

    CVE-2017-12637

    CVE from 2017, added in 2025

    SAP NetWeaver Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 19, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  47. Rank 57Advantive VeraCore

    CVE-2025-25181

    Advantive VeraCore SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  48. Rank 58Apache OFBiz

    CVE-2024-45195

    Apache OFBiz Forced Browsing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  49. Rank 59Oracle Agile PLM

    CVE-2024-21287

    Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  50. Rank 60Metabase

    CVE-2021-41277

    CVE from 2021, added in 2024

    Metabase GeoJSON API Local File Inclusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  51. Rank 61Apache Flink

    CVE-2020-17519

    CVE from 2020, added in 2024

    Apache Flink Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  52. Rank 62Oracle Business Intelligence (OBIEE / BI Publisher)

    CVE-2020-14864

    CVE from 2020, added in 2022

    Oracle Business Intelligence Enterprise Edition Path Transversal

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  53. Rank 63SAP NetWeaver

    CVE-2016-3976

    CVE from 2016, added in 2021

    SAP NetWeaver Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  54. Rank 64Apache Solr

    CVE-2019-17558

    CVE from 2019, added in 2021

    Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  55. Rank 65Hitachi Vantara Pentaho Business Analytics (BA) Server

    CVE-2022-43769

    CVE from 2022, added in 2025

    Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  56. Rank 66Oracle Business Intelligence (OBIEE / BI Publisher)

    CVE-2019-2616

    CVE from 2019, added in 2022

    Oracle BI Publisher Unauthorized Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  57. Rank 67Apache Solr

    CVE-2019-0193

    CVE from 2019, added in 2021

    Apache Solr DataImportHandler Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    7.2 (high)
  58. Rank 68SAP CRM

    CVE-2018-2380

    RansomwareCVE from 2018, added in 2021

    SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.6 (medium)
  59. Rank 69Qlik Sense

    CVE-2023-41266

    Ransomware

    Qlik Sense Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 7, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  60. Rank 70TIBCO JasperReports

    CVE-2018-18809

    CVE from 2018, added in 2022

    TIBCO JasperReports Library Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 29, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  61. Rank 71SAP NetWeaver

    CVE-2016-9563

    CVE from 2016, added in 2021

    SAP NetWeaver XML External Entity (XXE) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  62. Rank 72SAP NetWeaver

    CVE-2016-2388

    CVE from 2016, added in 2022

    SAP NetWeaver Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. IBM InfoSphere BigInsights

    CVE-2013-3993

    RansomwareEnd of lifeCVE from 2013, added in 2022

    IBM InfoSphere BigInsights Invalid Input Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  2. Checkbox Survey

    CVE-2021-27852

    End of life

    Checkbox Survey Deserialization of Untrusted Data Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.