Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2024-48030

Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Te…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.8
CVE-2024-48026

Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf…

Mitigation only
Fix from $2,300 2024-10-16
Ninjafirewall HIGH 7.2
CVE-2021-4451

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authe…

Fix: after 4.3.3
Fix from $1,950 2024-10-16
Givewp CRITICAL 9.8
CVE-2024-9634

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including…

Fix: 3.16.4+
Fix from $2,300 2024-10-16
Splunk HIGH 8.8
CVE-2024-45733

In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could p…

Fix: 9.1.6 / 9.2.3+
Fix from $1,950 2024-10-14
Unclassified CRITICAL 9.8
CVE-2024-48033

Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue aff…

Mitigation only
Fix from $2,300 2024-10-11
Dataease CRITICAL 9.8
CVE-2024-47074

DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JD…

Fix: 1.18.25+
Fix from $2,300 2024-10-11
Jobsearch Wp Job Board CRITICAL 9.8
CVE-2024-47636

Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a throu…

Fix: after 2.5.9
Fix from $2,300 2024-10-10
Unclassified CRITICAL 9.2
CVE-2023-25581

pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulnerability. The vulnerability af…

Mitigation only
Fix from $2,300 2024-10-10
Unclassified HIGH 7.3
CVE-2024-9005

CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialize…

Mitigation only
Fix from $1,950 2024-10-08
Seo HIGH 7.2
CVE-2024-9314

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…

Fix: 1.0.229+
Fix from $1,950 2024-10-05
Avro HIGH 7.3
CVE-2024-47561

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgr…

Fix: 1.11.4+
Fix from $1,950 2024-10-03
Unclassified HIGH 8.8
CVE-2024-8885

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbi…

Mitigation only
Fix from $1,950 2024-10-02
Unseen Blog HIGH 8.8
CVE-2024-7432

The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untruste…

Fix: after 1.0.0
Fix from $1,950 2024-10-01
Empowerment HIGH 8.8
CVE-2024-7433

The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of untruste…

Fix: after 1.0.2
Fix from $1,950 2024-10-01
Ultrapress HIGH 8.8
CVE-2024-7434

The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via deserialization of untrusted…

Fix: after 1.2.1
Fix from $1,950 2024-10-01
Lucene Replicator HIGH 8.0
CVE-2024-45772

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before…

Fix: 9.12.0+
Fix from $1,950 2024-09-30
Givewp CRITICAL 9.8
CVE-2024-8353EPSS 29%

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including…

Fix: 3.16.2+
Fix from $2,300 2024-09-28
Product Enquiry For Woocommerce HIGH 8.8
CVE-2024-8922

The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an…

Fix: 2.2.33.34+
Fix from $1,950 2024-09-27
Cloud Pak For Multicloud Management Monitoring HIGH 8.8
CVE-2024-43191

IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

Mitigation only
Fix from $1,950 2024-09-26
Ui For Wpf HIGH 7.8
CVE-2024-8316

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulner…

Fix: 2024.3.924+
Fix from $1,950 2024-09-25
Ui For Wpf CRITICAL 9.8
CVE-2024-7576

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulner…

Fix: 2024.3.924+
Fix from $2,300 2024-09-25
Google Website Translator HIGH 7.2
CVE-2024-8514

The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 vi…

Fix: 1.4.12+
Fix from $1,950 2024-09-25
Easy Digital Downloads HIGH 7.2
CVE-2022-2439

The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via …

Fix: 3.3.4+
Fix from $1,950 2024-09-24
Hertzbeat HIGH 8.8
CVE-2024-42323EPSS 8%

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attac…

Fix: 1.6.0+
Fix from $1,950 2024-09-21
Reverb HIGH 7.8
CVE-2024-8375

There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C+…

Fix: 2024-08-05+
Fix from $1,950 2024-09-19
Langchain HIGH 7.8
CVE-2024-5998

A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can …

Fix: 0.2.9+
Fix from $1,950 2024-09-17
Seata CRITICAL 9.8
CVE-2024-22399

Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seat…

Fix: 1.8.1+
Fix from $2,300 2024-09-16
H2o CRITICAL 9.8
CVE-2024-8862

A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the f…

No fix yet
Fix from $2,300 2024-09-14
Wp Editor HIGH 7.2
CVE-2022-2446

The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and …

Fix: 1.2.9.1+
Fix from $1,950 2024-09-13