Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Migration\, Backup\, Staging HIGH 8.8
CVE-2024-10962

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via…

Fix: 0.9.108+
Fix from $1,950 2024-11-14
Android HIGH 7.8
CVE-2024-43080

In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esc…

Patch available
Fix from $1,950 2024-11-13
Filemanager CRITICAL 9.8
CVE-2024-52306

FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter coul…

Fix: 2.0.2 / 3.0.9+
Fix from $2,300 2024-11-13
Ui For Wpf HIGH 7.8
CVE-2024-10012

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulne…

Fix: 2024.4.1111+
Fix from $1,950 2024-11-13
Telerik Ui For Winforms HIGH 7.8
CVE-2024-10013

In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization …

Fix: 2024.4.1113+
Fix from $1,950 2024-11-13
Advanced Order Export For Woocommerce CRITICAL 9.8
CVE-2024-10828

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via …

Fix: 3.5.6+
Fix from $2,300 2024-11-13
Session Recording HIGH 8.0
CVE-2024-8069 KEVEPSS 15%

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user …

Fix: 2407+
Fix from $1,950 2024-11-12
Telecontrol Server Basic CRITICAL 10.0
CVE-2024-44102

A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy co…

Fix: 3.1.2.1+
Fix from $2,300 2024-11-12
Unclassified HIGH 7.3
CVE-2023-32736

A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All ver…

Mitigation only
Fix from $1,950 2024-11-12
Unclassified HIGH 7.5
CVE-2024-47072

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application w…

Patch available
Fix from $1,950 2024-11-08
Thinkadmin HIGH 8.1
CVE-2024-10749

A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/contr…

Fix: after 6.1.67
Fix from $1,950 2024-11-04
Lucene.net HIGH 8.1
CVE-2024-43383

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8…

Mitigation only
Fix from $1,950 2024-10-31
Thinkphp CRITICAL 9.8
CVE-2024-48112

A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Fix: after 8.0.4
Fix from $2,300 2024-10-30
Unclassified CRITICAL 9.8
CVE-2024-10456EPSS 18%

Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, …

Mitigation only
Fix from $2,300 2024-10-30
Unclassified CRITICAL 9.8
CVE-2024-50507

Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList:…

Mitigation only
Fix from $2,300 2024-10-30
Pytorch CRITICAL 9.8
CVE-2024-48063

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch…

Fix: after 2.4.1
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.8
CVE-2024-48206

A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.

Mitigation only
Fix from $2,300 2024-10-29
Namaste\! Lms HIGH 8.8
CVE-2024-50408

Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a thr…

Fix: 2.6.4+
Fix from $1,950 2024-10-28
Wpc Shop As A Customer For Woocommerce HIGH 8.8
CVE-2024-50416

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This …

Fix: 1.2.7+
Fix from $1,950 2024-10-28
Unclassified HIGH 7.2
CVE-2024-49684

Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue a…

Mitigation only
Fix from $1,950 2024-10-23
Advanced Advertising System CRITICAL 9.8
CVE-2024-49624

Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This is…

Fix: after 1.3.1
Fix from $2,300 2024-10-20
Sitebuilder Dynamic Components CRITICAL 9.8
CVE-2024-49625

Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This …

Fix: after 1.0
Fix from $2,300 2024-10-20
Giveaway Boost CRITICAL 9.8
CVE-2024-49332

Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Bo…

Fix: after 2.1.4
Fix from $2,300 2024-10-20
Shipyaari Shipping Management CRITICAL 9.8
CVE-2024-49626

Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.Th…

Fix: after 1.2
Fix from $2,300 2024-10-20
Wp Easy Post Types HIGH 8.8
CVE-2024-10079

The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untr…

Fix: after 1.4.4
Fix from $1,950 2024-10-18
Unclassified CRITICAL 9.8
CVE-2024-49318

Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading …

Mitigation only
Fix from $2,300 2024-10-17
Unclassified HIGH 8.8
CVE-2024-49226

Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affec…

Mitigation only
Fix from $1,950 2024-10-16
Unclassified CRITICAL 9.8
CVE-2024-49227

Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects F…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.8
CVE-2024-49218

Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Objec…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.8
CVE-2024-48028

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through…

Mitigation only
Fix from $2,300 2024-10-16