CVE-2026-107104Critical· 9.3▾ MidnightThis vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to t…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate application data or perform other unintended actions on the targeted system.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107102Critical· 9.3This vulnerability exists in the ERP system due to improper validation of payment callback parameters and inadequate authentication controls in API endpoint
CVE-2026-107103Critical· 9.3This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint
CVE-2017-12149Critical· 9.8In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserializatio…
CVE-2025-34449Critical· 9.1Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function
CVE-2025-10768Medium· 6.3A flaw has been found in h2oai h2o-3 up to 3.46.08
CVE-2020-5411High· 8.1When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution