Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Computer Vision Annotation Tool CRITICAL 9.8
CVE-2025-23045

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affec…

Fix: 2.26.0+
Fix from $2,300 2025-01-28
Unclassified MEDIUM 6.8
CVE-2024-0140

NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data issue. A successful exploit of …

Mitigation only
Fix from $1,600 2025-01-28
Ruoyi HIGH 7.2
CVE-2025-0734

A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the …

Fix: after 4.8.0
Fix from $1,950 2025-01-27
Vllm HIGH 8.8
CVE-2025-24357

vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoin…

Fix: 0.7.0+
Fix from $1,950 2025-01-27
Unclassified CRITICAL 9.8
CVE-2025-24671

Deserialization of Untrusted Data vulnerability in Pdfcrowd Dev Team Save as PDF save-as-pdf-by-pdfcrowd allows Object Injection.This issue affects S…

Mitigation only
Fix from $2,300 2025-01-27
Unclassified CRITICAL 9.8
CVE-2025-24601

Deserialization of Untrusted Data vulnerability in ThimPress FundPress fundpress allows Object Injection.This issue affects FundPress: from n/a throu…

Mitigation only
Fix from $2,300 2025-01-27
Unclassified HIGH 7.2
CVE-2024-12600

The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.0 v…

Mitigation only
Fix from $1,950 2025-01-25
Sma8200v CRITICAL 9.8
CVE-2025-23006 KEVEPSS 23%

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central …

Fix: 12.4.3-02854+
Fix from $2,300 2025-01-23
Unclassified CRITICAL 9.8
CVE-2025-23914

Deserialization of Untrusted Data vulnerability in muzaara Muzaara Google Ads Report muzaara-adwords-optimize-dashboard allows Object Injection.This …

Mitigation only
Fix from $2,300 2025-01-22
Sterling B2b Integrator HIGH 8.8
CVE-2024-31903

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute ar…

Fix: after 6.2.0.2
Fix from $1,950 2025-01-22
Unclassified HIGH 8.8
CVE-2025-23944

Deserialization of Untrusted Data vulnerability in bulktheme WOOEXIM wooexim allows Object Injection.This issue affects WOOEXIM: from n/a through <= …

Mitigation only
Fix from $1,950 2025-01-22
Unclassified CRITICAL 9.8
CVE-2025-23932

Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue affects Quick Count: from n/a t…

Mitigation only
Fix from $2,300 2025-01-22
Aipower HIGH 7.2
CVE-2025-0428

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserializat…

Fix: 1.8.97+
Fix from $1,950 2025-01-22
Aipower HIGH 7.2
CVE-2025-0429

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserializat…

Fix: 1.8.97+
Fix from $1,950 2025-01-22
Unclassified CRITICAL 9.8
CVE-2024-49688

Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a thr…

Mitigation only
Fix from $2,300 2025-01-21
Unclassified HIGH 8.8
CVE-2024-49699

Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a thr…

Mitigation only
Fix from $1,950 2025-01-21
String Locator HIGH 8.8
CVE-2024-10936

The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untr…

Fix: 2.6.7+
Fix from $1,950 2025-01-21
A\+hrd HIGH 7.2
CVE-2025-0586

The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and …

Fix: after 7.5
Fix from $1,950 2025-01-20
Unclassified HIGH 7.8
CVE-2024-12703

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execu…

Mitigation only
Fix from $1,950 2025-01-17
Matrix Media Repo MEDIUM 6.5
CVE-2024-56515

Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are di…

Fix: 1.3.8+
Fix from $1,600 2025-01-16
Mysiteforme CRITICAL 9.1
CVE-2024-57763

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.

Fix: 2025-01-01+
Fix from $2,300 2025-01-15
Mysiteforme CRITICAL 9.1
CVE-2024-57764

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.

Fix: 2025-01-01+
Fix from $2,300 2025-01-15
Mysiteforme CRITICAL 9.1
CVE-2024-57766

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

Fix: 2025-01-01+
Fix from $2,300 2025-01-15
Mysiteforme HIGH 7.5
CVE-2024-57762

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

Fix: 2025-01-01+
Fix from $1,950 2025-01-15
Unclassified CRITICAL 9.0
CVE-2024-49375

Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciousl…

Mitigation only
Fix from $2,300 2025-01-14
365 Apps HIGH 7.8
CVE-2025-21364

Microsoft Excel Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2025-01-14
Unclassified HIGH 7.3
CVE-2025-0465

A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api…

Mitigation only
Fix from $1,950 2025-01-14
Endpoint Manager HIGH 7.8
CVE-2024-13163EPSS 9%

Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remot…

Fix: 2022+
Fix from $1,950 2025-01-14
Givewp CRITICAL 9.8
CVE-2025-22777

Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.…

Fix: 3.19.4+
Fix from $2,300 2025-01-13
Givewp CRITICAL 9.8
CVE-2024-12877

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including…

Fix: after 3.19.2
Fix from $2,300 2025-01-11