Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Enterprise Vault CRITICAL 9.8
CVE-2024-53909

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code be…

Fix: 15.2+
Fix from $2,300 2024-11-24
Enterprise Vault CRITICAL 9.8
CVE-2024-53910

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code be…

Fix: 15.2+
Fix from $2,300 2024-11-24
Unclassified CRITICAL 9.8
CVE-2024-9511

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to PHP …

Mitigation only
Fix from $2,300 2024-11-23
Transformers HIGH 8.8
CVE-2024-11393

Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote at…

Fix: 4.48.0+
Fix from $1,950 2024-11-22
Transformers HIGH 8.8
CVE-2024-11394

Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacker…

Fix: 4.48.0+
Fix from $1,950 2024-11-22
Transformers HIGH 8.8
CVE-2024-11392EPSS 7%

Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacke…

Fix: 4.48.0+
Fix from $1,950 2024-11-22
Allegra HIGH 7.2
CVE-2024-5579

Allegra renderFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

Fix: 7.5.2+
Fix from $1,950 2024-11-22
Allegra HIGH 7.2
CVE-2024-5580

Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

Fix: 7.5.2+
Fix from $1,950 2024-11-22
Allegra MEDIUM 6.3
CVE-2023-51641

Allegra renderFieldMatch Deserialization of Unstrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Fix: 7.5.1+
Fix from $1,600 2024-11-22
Allegra MEDIUM 6.3
CVE-2023-51642

Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

Fix: 7.5.1+
Fix from $1,600 2024-11-22
Unclassified HIGH 7.2
CVE-2024-11409

The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of unt…

Mitigation only
Fix from $1,950 2024-11-21
Android HIGH 7.8
CVE-2018-9474

In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to…

Patch available
Fix from $1,950 2024-11-20
Unclassified HIGH 8.8
CVE-2024-10913

The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted inp…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified HIGH 8.8
CVE-2024-52445

Deserialization of Untrusted Data vulnerability in ModelTheme QRMenu Restaurant QR Menu Lite qrmenu-lite allows Object Injection.This issue affects Q…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified CRITICAL 9.8
CVE-2024-52443

Deserialization of Untrusted Data vulnerability in masikonis Geolocator geolocator allows Object Injection.This issue affects Geolocator: from n/a th…

Mitigation only
Fix from $2,300 2024-11-20
Unclassified CRITICAL 9.8
CVE-2024-52439

Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This issue affects Team Rosters: …

Mitigation only
Fix from $2,300 2024-11-20
Unclassified CRITICAL 9.8
CVE-2024-52440

Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocommerce allows Object Injection…

Mitigation only
Fix from $2,300 2024-11-20
Androidx.car.app HIGH 7.5
CVE-2024-10382

There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction…

Fix: after 1.4.0
Fix from $1,950 2024-11-20
My Geo Posts Free CRITICAL 9.8
CVE-2024-52433

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affe…

Fix: after 1.2
Fix from $2,300 2024-11-18
Video Gallery CRITICAL 9.8
CVE-2024-52430

Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video G…

Fix: after 0.2.1
Fix from $2,300 2024-11-18
Nix Anti Spam Light CRITICAL 9.8
CVE-2024-52432

Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affec…

Fix: after 0.0.4
Fix from $2,300 2024-11-18
Hertzbeat HIGH 8.8
CVE-2024-41151

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue …

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Unclassified CRITICAL 9.8
CVE-2024-52411

Deserialization of Untrusted Data vulnerability in flowcraft Advanced Personalization personalization-by-flowcraft allows Object Injection.This issue…

Mitigation only
Fix from $2,300 2024-11-16
Unclassified CRITICAL 9.8
CVE-2024-52412

Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from n/a through 1.0.8.1.

No fix yet
Fix from $2,300 2024-11-16
Unclassified CRITICAL 9.8
CVE-2024-52413

Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue affects Airin Blog: from n/a t…

Mitigation only
Fix from $2,300 2024-11-16
Unclassified CRITICAL 9.8
CVE-2024-52414

Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-menu allows Object Injection.Thi…

Mitigation only
Fix from $2,300 2024-11-16
Unclassified CRITICAL 9.8
CVE-2024-52409

Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX R…

Mitigation only
Fix from $2,300 2024-11-16
Unclassified CRITICAL 9.8
CVE-2024-52410

Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referr…

Mitigation only
Fix from $2,300 2024-11-16
Dompdf CRITICAL 9.8
CVE-2021-3838

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_conte…

Fix: 2.0.0+
Fix from $2,300 2024-11-15
Kibana HIGH 7.2
CVE-2024-37285

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A …

Fix: after 8.15.0
Fix from $1,950 2024-11-14