VendorsOracleretail_xstore_point_of_service16.0.6
Vulnerabilities

Oracle Retail Xstore Point 16.0.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2021-21345
XStream is vulnerable to a Remote Command Execution attack
Published 2021-03-22 · Analyzed
9.9EPSS 0.723
CVE-2021-21346
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.764
CVE-2021-21344
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.760
CVE-2021-21350
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.152
CVE-2021-21347
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.143
CVE-2019-0228
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Published 2019-04-17 · Modified
9.8EPSS 0.095
CVE-2019-0219
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Published 2020-01-14 · Modified
9.8EPSS 0.078
CVE-2020-10683
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Published 2020-05-01 · Modified
9.8EPSS 0.073
CVE-2020-26217
Remote Code Execution in XStream
Published 2020-11-16 · Analyzed
9.3EPSS 0.850
CVE-2020-8174
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Published 2020-07-24 · Modified
9.3EPSS 0.076
CVE-2021-21351
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.1EPSS 0.821
CVE-2021-21342
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
9.1EPSS 0.500
CVE-2021-29505
XStream is vulnerable to a Remote Command Execution attack
Published 2021-05-28 · Modified
8.8EPSS 0.772
CVE-2020-36179
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.210
CVE-2020-36184
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
Published 2021-01-06 · Modified
8.8EPSS 0.104
CVE-2020-36180
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.050
CVE-2020-36181
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.050
CVE-2020-36182
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.050
CVE-2021-39139
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.8EPSS 0.045
CVE-2020-5421
RFD Protection Bypass via jsessionid
Published 2020-09-19 · Modified
8.7EPSS 0.107
CVE-2021-21349
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
8.6EPSS 0.468
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
Published 2021-08-23 · Analyzed
8.5KEVEPSS 0.981
CVE-2021-39141
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.161
CVE-2021-39146
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.143
CVE-2021-39152
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
Published 2021-08-23 · Analyzed
8.5EPSS 0.114
CVE-2021-39154
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39148
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39147
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39151
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39149
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39145
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.041
CVE-2021-39150
A Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling
Published 2021-08-23 · Analyzed
8.5EPSS 0.034
CVE-2020-35728
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
Published 2020-12-27 · Analyzed
8.1EPSS 0.125
CVE-2020-36188
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
Published 2021-01-06 · Modified
8.1EPSS 0.109
CVE-2020-35491
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
Published 2020-12-17 · Modified
8.1EPSS 0.096
CVE-2020-35490
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
Published 2020-12-17 · Modified
8.1EPSS 0.078
CVE-2020-36185
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
Published 2021-01-06 · Modified
8.1EPSS 0.052
CVE-2020-36186
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
Published 2021-01-06 · Modified
8.1EPSS 0.052
CVE-2020-36187
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
Published 2021-01-06 · Modified
8.1EPSS 0.052
CVE-2020-36189
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
Published 2021-01-06 · Modified
8.1EPSS 0.049
1 / 2Next →