Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
A Blog Cms HIGH 7.5
CVE-2025-31103

Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server whe…

Fix: 2.10.58 / 2.11.70+
Fix from $1,950 2025-03-31
Unclassified CRITICAL 9.8
CVE-2025-22526

Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performancestats allows Object Injectio…

Mitigation only
Fix from $2,300 2025-03-28
Drag And Drop Multiple File Upload Contact Form 7 HIGH 8.8
CVE-2025-2485

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…

Fix: 1.3.8.9+
Fix from $1,950 2025-03-28
Unclassified CRITICAL 9.0
CVE-2025-26873

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

Mitigation only
Fix from $2,300 2025-03-27
Eladmin HIGH 7.2
CVE-2025-2855

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of…

Fix: after 2.7
Fix from $1,950 2025-03-27
Unclassified HIGH 7.2
CVE-2025-30773

Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects T…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified CRITICAL 9.8
CVE-2025-2332

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…

Mitigation only
Fix from $2,300 2025-03-27
Product Import Export For Woocommerce HIGH 7.2
CVE-2025-1913

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all version…

Fix: 2.5.1+
Fix from $1,950 2025-03-26
Unclassified HIGH 7.2
CVE-2024-13889

The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of …

Mitigation only
Fix from $1,950 2025-03-26
Onos CRITICAL 9.8
CVE-2025-29310

An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows …

Mitigation only
Fix from $2,300 2025-03-24
Yii CRITICAL 9.8
CVE-2025-2690

A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src…

Fix: after 2.0.39
Fix from $2,300 2025-03-24
Yii CRITICAL 9.8
CVE-2025-2689

A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of…

Fix: after 2.0.45
Fix from $2,300 2025-03-24
Snail Job HIGH 8.8
CVE-2025-2622

A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/w…

No fix yet
Fix from $1,950 2025-03-22
Import Export Wordpress Users HIGH 7.2
CVE-2025-1971

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via …

Fix: 2.6.3+
Fix from $1,950 2025-03-22
Profilegrid HIGH 8.8
CVE-2025-0724

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…

Fix: 5.9.4.6+
Fix from $1,950 2025-03-22
Dataverse HIGH 8.8
CVE-2025-29807

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-03-21
Redlib HIGH 7.5
CVE-2025-30160

Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (…

Fix: 0.36.0+
Fix from $1,950 2025-03-20
Veeam Backup \& Replication HIGH 8.8
CVE-2025-23120EPSS 22%

A vulnerability allowing remote code execution (RCE) for domain users.

Fix: 12.3.1.1139+
Fix from $1,950 2025-03-20
Order Export \& Order Import For Woocommerce HIGH 7.2
CVE-2024-13921

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.…

Fix: 2.6.1+
Fix from $1,950 2025-03-20
Unclassified CRITICAL 9.8
CVE-2024-9701

A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacke…

Patch available
Fix from $2,300 2025-03-20
Vllm CRITICAL 9.8
CVE-2024-9053

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop…

No fix yet
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.8
CVE-2024-9070

A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attac…

Mitigation only
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.8
CVE-2024-8502

A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of u…

Mitigation only
Fix from $2,300 2025-03-20
Ragflow CRITICAL 9.8
CVE-2024-12433

A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey…

Fix: 0.14.0+
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.8
CVE-2024-12029EPSS 6%

A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability…

Patch available
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.8
CVE-2024-12044

A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the `pickle.loads()` fu…

Mitigation only
Fix from $2,300 2025-03-20
Gpt Academic HIGH 8.8
CVE-2024-11039

A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and …

Fix: 3.91+
Fix from $1,950 2025-03-20
Vllm CRITICAL 9.8
CVE-2024-11041

vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse receive…

No fix yet
Fix from $2,300 2025-03-20
H2o CRITICAL 9.8
CVE-2024-10553

A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization o…

Patch available
Fix from $2,300 2025-03-20
Horovod CRITICAL 9.8
CVE-2024-10190

Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling o…

Fix: after 0.28.1
Fix from $2,300 2025-03-20