Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Coldfusion CRITICAL 9.8
CVE-2024-41874EPSS 30%

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code…

Mitigation only
Fix from $2,300 2024-09-13
Access Rights Manager HIGH 8.0
CVE-2024-28991

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would a…

Fix: 2024.3.1+
Fix from $1,950 2024-09-12
Unclassified HIGH 7.8
CVE-2024-45857

Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to ru…

Mitigation only
Fix from $1,950 2024-09-12
Mindsdb HIGH 7.5
CVE-2024-45855

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …

No fix yet
Fix from $1,950 2024-09-12
Mindsdb HIGH 8.8
CVE-2024-45852

Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbi…

No fix yet
Fix from $1,950 2024-09-12
Mindsdb HIGH 7.5
CVE-2024-45853

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …

No fix yet
Fix from $1,950 2024-09-12
Mindsdb HIGH 7.5
CVE-2024-45854

Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …

No fix yet
Fix from $1,950 2024-09-12
Endpoint Manager CRITICAL 9.8
CVE-2024-29847EPSS 53%

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated att…

Fix: 2022+
Fix from $2,300 2024-09-12
Sharepoint Server HIGH 7.5
CVE-2024-43466

Microsoft SharePoint Server Denial of Service Vulnerability

Patch available
Fix from $1,950 2024-09-10
Sharepoint Server HIGH 7.2
CVE-2024-43464EPSS 36%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-09-10
Sharepoint Server HIGH 8.8
CVE-2024-38018EPSS 51%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-09-10
Spectrum CRITICAL 9.8
CVE-2023-37227

Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.

Fix: 4.6+
Fix from $2,300 2024-09-10
Thinkphp CRITICAL 9.8
CVE-2024-44902

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Fix: after 8.0.4
Fix from $2,300 2024-09-09
Kibana HIGH 8.8
CVE-2024-37288

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. Th…

Mitigation only
Fix from $1,950 2024-09-09
Veeam Backup \& Replication CRITICAL 9.8
CVE-2024-40711 KEVEPSS 90%

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Fix: 12.2.0.334+
Fix from $2,300 2024-09-07
H2o CRITICAL 9.1
CVE-2024-45758

H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. …

Fix: after 3.46.0.4
Fix from $2,300 2024-09-06
Attire HIGH 8.8
CVE-2024-7435

The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted inp…

Fix: 2.0.7+
Fix from $1,950 2024-08-31
Events Calendar Pro HIGH 7.2
CVE-2024-8016

The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of…

Fix: 7.0.2.1+
Fix from $1,950 2024-08-30
Betheme HIGH 8.8
CVE-2024-2694

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted i…

Fix: after 27.5.6
Fix from $1,950 2024-08-30
Dtn Soft CRITICAL 9.8
CVE-2024-8255

Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrust…

Fix: after 2.0.1
Fix from $2,300 2024-08-29
Jobsearch Wp Job Board CRITICAL 9.8
CVE-2024-43931

Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.

Fix: 2.5.4+
Fix from $2,300 2024-08-29
Theme Editor HIGH 7.2
CVE-2022-2440

The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and inc…

Fix: 2.9+
Fix from $1,950 2024-08-29
Ultimate Store Kit CRITICAL 9.8
CVE-2024-8030

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider p…

Fix: 2.0.4+
Fix from $2,300 2024-08-28
Simple Job Board HIGH 7.2
CVE-2024-7351

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of u…

Fix: 2.12.4+
Fix from $1,950 2024-08-24
Ultimate Store Kit CRITICAL 9.8
CVE-2024-5335

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider p…

Fix: 2.0.0+
Fix from $2,300 2024-08-21
Hertzbeat HIGH 8.8
CVE-2024-42362

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/…

Fix: 1.6.0+
Fix from $1,950 2024-08-20
Unclassified HIGH 8.8
CVE-2024-42363

Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows int…

Patch available
Fix from $1,950 2024-08-20
Gotribe Admin CRITICAL 9.8
CVE-2024-8003

A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file …

Patch available
Fix from $2,300 2024-08-20
Givewp CRITICAL 9.8
CVE-2024-5932EPSS 74%

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including…

Fix: 3.14.2+
Fix from $2,300 2024-08-20
Unclassified CRITICAL 9.8
CVE-2024-43354

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

Mitigation only
Fix from $2,300 2024-08-19