CVE-2026-102455Critical· 9.8▾ MidnightEasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102457Medium· 6.5EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability
CVE-2026-102458Critical· 9.8EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability
CVE-2026-102459Medium· 6.1EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability
CVE-2026-102456Medium· 6.5EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability
CVE-2026-102454High· 7.2EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability
CVE-2017-12149Critical· 9.8In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserializatio…