CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

oracle

retail_workforce_management_software

6 known vulnerabilities · sorted by CVSS score

CVE-2018-14719
CRITICAL9.8

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

fasterxml / jackson-databind+53
Network
Published Jan 2, 2019
CVE-2018-19362
CRITICAL9.8

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.

fasterxml / jackson-databind+23
Network
Published Jan 2, 2019
CVE-2018-14718
CRITICAL9.8

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

fasterxml / jackson-databind+56
Network
Published Jan 2, 2019
CVE-2018-19360
CRITICAL9.8

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.

fasterxml / jackson-databind+23
Network
Published Jan 2, 2019
CVE-2018-19361
CRITICAL9.8

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

fasterxml / jackson-databind+24
Network
Published Jan 2, 2019
CVE-2015-9251
MEDIUM6.1

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

jquery / jquery+80
Network
Published Jan 18, 2018