Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 7.5
CVE-2024-12627

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection…

Mitigation only
Fix from $1,950 2025-01-11
Node Export MEDIUM 6.6
CVE-2024-13295

Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3…

Fix: 7.x-3.3+
Fix from $1,600 2025-01-09
Mailjet MEDIUM 6.6
CVE-2024-13296

Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.

Fix: 4.0.1+
Fix from $1,600 2025-01-09
Eloqua MEDIUM 6.6
CVE-2024-13297

Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.

Fix: 7.x-1.5+
Fix from $1,600 2025-01-09
Unclassified HIGH 7.2
CVE-2025-22510

Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affec…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified MEDIUM 5.3
CVE-2023-27531

There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

Mitigation only
Fix from $1,600 2025-01-09
Openmeetings CRITICAL 9.8
CVE-2024-54676EPSS 65%

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions …

Fix: 8.0.0+
Fix from $2,300 2025-01-08
Suitecrm HIGH 8.8
CVE-2022-45185

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to…

No fix yet
Fix from $1,950 2025-01-07
Unclassified HIGH 8.8
CVE-2024-55555EPSS 7%

Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .…

Patch available
Fix from $1,950 2025-01-07
Unclassified CRITICAL 9.8
CVE-2024-55556EPSS 44%

A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server …

Mitigation only
Fix from $2,300 2025-01-07
Unclassified HIGH 8.1
CVE-2024-56291

Deserialization of Untrusted Data vulnerability in plainware PlainInventory z-inventory-manager allows Object Injection.This issue affects PlainInven…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 8.1
CVE-2024-56283

Deserialization of Untrusted Data vulnerability in plainware Locatoraid Store Locator locatoraid allows Object Injection.This issue affects Locatorai…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified CRITICAL 9.8
CVE-2024-49222

Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy…

Mitigation only
Fix from $2,300 2025-01-07
Unclassified HIGH 8.1
CVE-2024-12313

The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.1 via deser…

Mitigation only
Fix from $1,950 2025-01-07
Custom Product Tabs For Woocommerce HIGH 7.2
CVE-2024-11465

The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via de…

Fix: after 1.8.5
Fix from $1,950 2025-01-07
Lr12a HIGH 7.5
CVE-2024-20150

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges …

Mitigation only
Fix from $1,950 2025-01-06
Mysiteforme CRITICAL 9.8
CVE-2024-13136

A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the fi…

No fix yet
Fix from $2,300 2025-01-05
Unclassified HIGH 8.8
CVE-2024-10957

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via d…

Mitigation only
Fix from $1,950 2025-01-04
Unclassified HIGH 8.8
CVE-2024-10932

The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of un…

Mitigation only
Fix from $1,950 2025-01-04
Unclassified HIGH 7.5
CVE-2024-56068

Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through …

Mitigation only
Fix from $1,950 2024-12-31
Unclassified MEDIUM 6.3
CVE-2024-12994

A vulnerability was found in running-elephant Datart 1.0.0-rc3. It has been rated as critical. Affected by this issue is the function extractModel of…

Mitigation only
Fix from $1,600 2024-12-28
Mina CRITICAL 9.8
CVE-2024-52046EPSS 24%

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary…

Fix: 2.0.27 / 2.1.10+
Fix from $2,300 2024-12-25
Custom Product Tabs For Woocommerce HIGH 7.2
CVE-2024-12721

The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.4 via de…

Fix: after 1.2.4
Fix from $1,950 2024-12-21
Unclassified HIGH 7.8
CVE-2024-12677

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

Mitigation only
Fix from $1,950 2024-12-20
Unclassified HIGH 7.8
CVE-2024-12741

A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires …

Mitigation only
Fix from $1,950 2024-12-18
Unclassified CRITICAL 9.8
CVE-2024-56058

Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector…

Mitigation only
Fix from $2,300 2024-12-18
Plextrac CRITICAL 9.8
CVE-2024-12687

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue a…

Fix: 2.8.1+
Fix from $2,300 2024-12-16
Ui For Wpf CRITICAL 9.8
CVE-2024-10095

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulne…

Fix: 24.4.1213+
Fix from $2,300 2024-12-16
Forumwp CRITICAL 9.8
CVE-2024-54367

Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a throu…

Fix: 2.1.1+
Fix from $2,300 2024-12-16
Unclassified HIGH 7.2
CVE-2024-54282

Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu wp-megamenu allows Object Injection.This issue affects WP Mega Menu: from n/a…

Mitigation only
Fix from $1,950 2024-12-13