Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Wp Activity Log CRITICAL 9.8
CVE-2025-0767

WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-c…

Mitigation only
Fix from $2,300 2025-02-27
Unclassified CRITICAL 9.8
CVE-2025-26900

Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue affects Flexmls® IDX: from n/a…

Mitigation only
Fix from $2,300 2025-02-25
Unclassified HIGH 7.2
CVE-2025-27300

Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified HIGH 7.2
CVE-2025-27301

Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager nhrrob-options-table-manager allows Object Injection.…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified CRITICAL 9.8
CVE-2025-26763

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Object Injection.This issue affects Re…

Mitigation only
Fix from $2,300 2025-02-22
Cicadascms CRITICAL 9.8
CVE-2025-1556

A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the fil…

No fix yet
Fix from $2,300 2025-02-22
Mambo Joomla Importer HIGH 7.2
CVE-2024-13899

The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrus…

Mitigation only
Fix from $1,950 2025-02-22
Qiskit HIGH 8.6
CVE-2025-1403

Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malforme…

Fix: after 1.2.4
Fix from $1,950 2025-02-21
Ravpage CRITICAL 9.8
CVE-2024-13789

The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted in…

Fix: after 2.31
Fix from $2,300 2025-02-20
Unclassified CRITICAL 9.9
CVE-2024-37361

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara P…

Mitigation only
Fix from $2,300 2025-02-20
Cognos Controller HIGH 8.8
CVE-2024-28777

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allow…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Affiliate Links CRITICAL 9.8
CVE-2024-13556

The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all version…

Fix: 3.1.0+
Fix from $2,300 2025-02-18
S2member CRITICAL 9.8
CVE-2024-12562

The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untru…

Fix: 250214+
Fix from $2,300 2025-02-15
Eventmesh CRITICAL 9.8
CVE-2024-56180

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo…

Fix: 1.11.0+
Fix from $2,300 2025-02-14
Ignite CRITICAL 9.0
CVE-2024-52577

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili…

Fix: 2.17.0+
Fix from $2,300 2025-02-14
Puzzles CRITICAL 9.8
CVE-2024-13770

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, …

Fix: 4.2.5+
Fix from $2,300 2025-02-13
Xunruicms CRITICAL 9.8
CVE-2025-1186

A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects unknown code of the file /Con…

Fix: after 4.6.4
Fix from $2,300 2025-02-12
Xunruicms CRITICAL 9.8
CVE-2025-1177

A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/…

No fix yet
Fix from $2,300 2025-02-11
Wazuh CRITICAL 9.9
CVE-2025-24016 KEVEPSS 94%

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, a…

Fix: 4.9.1+
Fix from $2,300 2025-02-10
Tarzan Cms CRITICAL 9.8
CVE-2025-1113

A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#…

No fix yet
Fix from $2,300 2025-02-07
Unclassified MEDIUM 6.6
CVE-2021-27017

Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Age…

Mitigation only
Fix from $1,600 2025-02-07
Wp All Import HIGH 7.2
CVE-2024-9664

The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of u…

Fix: 4.9.8+
Fix from $1,950 2025-02-07
Unclassified CRITICAL 9.5
CVE-2025-1077

A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weat…

Mitigation only
Fix from $2,300 2025-02-07
Cityworks HIGH 8.8
CVE-2025-0994 KEVEPSS 31%

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerabil…

Fix: 15.8.9 / 23.10+
Fix from $1,950 2025-02-06
Identity Services Engine HIGH 7.2
CVE-2025-20124EPSS 18%

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected de…

Fix: 3.1+
Fix from $1,950 2025-02-05
Unclassified HIGH 8.8
CVE-2025-24661

Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Object Inject…

Mitigation only
Fix from $1,950 2025-02-03
Unclassified MEDIUM 5.0
CVE-2025-0974

A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation o…

Mitigation only
Fix from $1,600 2025-02-03
Icontrolwp CRITICAL 9.8
CVE-2024-13742

The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4…

Fix: after 4.4.5
Fix from $2,300 2025-01-30
Snowflake Connector HIGH 7.8
CVE-2025-24794

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op…

Fix: 3.13.1+
Fix from $1,950 2025-01-29
Unclassified HIGH 7.3
CVE-2025-0841

A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore…

Mitigation only
Fix from $1,950 2025-01-29