Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2024-54273

Deserialization of Untrusted Data vulnerability in PickPlugins Mail Picker mail-picker allows Object Injection.This issue affects Mail Picker: from n…

Mitigation only
Fix from $2,300 2024-12-13
Plextrac HIGH 7.5
CVE-2024-11839

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue aff…

Fix: 2.8.1+
Fix from $1,950 2024-12-13
Update Catalog CRITICAL 9.8
CVE-2024-49147

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

Mitigation only
Fix from $2,300 2024-12-12
Unclassified HIGH 8.1
CVE-2024-12312

The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserializati…

Mitigation only
Fix from $1,950 2024-12-12
Sharepoint Server HIGH 7.4
CVE-2024-49070

Microsoft SharePoint Remote Code Execution Vulnerability

Mitigation only
Fix from $1,950 2024-12-12
Muzic HIGH 8.4
CVE-2024-49063

Microsoft/Muzic Remote Code Execution Vulnerability

Fix: 196.0+
Fix from $1,950 2024-12-12
Archiver HIGH 8.8
CVE-2024-11947

GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Fix: 15.7+
Fix from $1,950 2024-12-12
Archiver HIGH 8.8
CVE-2024-11949

GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Fix: 15.7+
Fix from $1,950 2024-12-12
Unclassified HIGH 8.8
CVE-2024-53247

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud P…

Mitigation only
Fix from $1,950 2024-12-10
Unclassified HIGH 7.8
CVE-2024-49849

A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All ver…

Mitigation only
Fix from $1,950 2024-12-10
Drupal CRITICAL 9.8
CVE-2024-55636

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro…

Fix: 10.2.11 / 10.3.9+
Fix from $2,300 2024-12-10
Drupal CRITICAL 9.8
CVE-2024-55637

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro…

Fix: 10.2.11 / 10.3.9+
Fix from $2,300 2024-12-10
Drupal CRITICAL 9.8
CVE-2024-55638

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.…

Fix: 7.102 / 10.2.11+
Fix from $2,300 2024-12-10
Unclassified HIGH 8.8
CVE-2024-11501

The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via deserialization of untrusted inp…

Mitigation only
Fix from $1,950 2024-12-07
Clipbucket HIGH 8.8
CVE-2024-54135

ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserializat…

Fix: 5.5.1-200+
Fix from $1,950 2024-12-06
Clipbucket CRITICAL 9.8
CVE-2024-54136

ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vu…

Fix: 5.5.1-200+
Fix from $2,300 2024-12-06
Hive HIGH 8.3
CVE-2022-41137

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is un…

Patch available
Fix from $1,950 2024-12-05
Horilla HIGH 8.8
CVE-2024-12138

A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/creat…

Fix: after 1.2.1
Fix from $1,950 2024-12-04
Unclassified HIGH 8.8
CVE-2024-10587

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to PHP Object …

Mitigation only
Fix from $1,950 2024-12-04
Unclassified CRITICAL 9.8
CVE-2024-51363

Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2024-12-03
Jfinal Cms CRITICAL 9.8
CVE-2024-53477

JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

Mitigation only
Fix from $2,300 2024-12-02
Arrow CRITICAL 9.8
CVE-2024-52338

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execut…

Fix: 17.0.0+
Fix from $2,300 2024-11-28
Insight Remote Support CRITICAL 9.8
CVE-2024-53673

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

Fix: 7.14.0.629+
Fix from $2,300 2024-11-26
Easy Folder Listing Pro CRITICAL 9.8
CVE-2024-11145

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with…

Fix: 4.5+
Fix from $2,300 2024-11-26
Unclassified MEDIUM 6.3
CVE-2024-11662

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deplo…

Mitigation only
Fix from $1,600 2024-11-25
Enterprise Vault CRITICAL 9.8
CVE-2024-53911

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code be…

Fix: 15.2+
Fix from $2,300 2024-11-24
Enterprise Vault CRITICAL 9.8
CVE-2024-53912

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code be…

Fix: 15.2+
Fix from $2,300 2024-11-24
Enterprise Vault CRITICAL 9.8
CVE-2024-53913

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code be…

Fix: 15.2+
Fix from $2,300 2024-11-24
Enterprise Vault CRITICAL 9.8
CVE-2024-53914

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code be…

Fix: 15.2+
Fix from $2,300 2024-11-24
Enterprise Vault CRITICAL 9.8
CVE-2024-53915

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code be…

Fix: 15.2+
Fix from $2,300 2024-11-24