Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.0
CVE-2024-43252

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

Mitigation only
Fix from $2,300 2024-08-19
Ultimate Membership Pro CRITICAL 10.0
CVE-2024-43242

Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro:…

Fix: after 12.6
Fix from $2,300 2024-08-19
Givewp CRITICAL 9.8
CVE-2024-37099

Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.

Fix: 3.14.2+
Fix from $2,300 2024-08-19
Web Help Desk CRITICAL 9.8
CVE-2024-28986 KEVEPSS 85%

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an…

Fix: after 12.8.2
Fix from $2,300 2024-08-13
Unclassified CRITICAL 9.8
CVE-2024-43141

Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Par…

Mitigation only
Fix from $2,300 2024-08-13
Unclassified HIGH 8.8
CVE-2024-7561

The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted i…

Mitigation only
Fix from $1,950 2024-08-08
Unclassified HIGH 8.8
CVE-2024-7486

The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrust…

Mitigation only
Fix from $1,950 2024-08-08
Unclassified HIGH 7.2
CVE-2024-7560

The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted…

Mitigation only
Fix from $1,950 2024-08-08
Endpoint Manager Mobile HIGH 8.8
CVE-2024-36131

An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary com…

Fix: 12.1.0.1+
Fix from $1,950 2024-08-07
Unclassified HIGH 8.3
CVE-2024-39636

Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.…

Mitigation only
Fix from $1,950 2024-08-01
Unclassified MEDIUM 5.5
CVE-2024-39630

Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Ev…

Mitigation only
Fix from $1,600 2024-08-01
Unclassified HIGH 8.8
CVE-2024-6152

The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5 via deserialization of untru…

Mitigation only
Fix from $1,950 2024-07-27
Emui HIGH 7.1
CVE-2024-39673

Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect servic…

No fix yet
Fix from $1,950 2024-07-25
Telerik Report Server CRITICAL 9.8
CVE-2024-6327

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deseriali…

Fix: 10.1.24.709+
Fix from $2,300 2024-07-24
Ecommerce Laravel Bootstrap HIGH 8.8
CVE-2024-7067

A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. A…

Fix: 2024-07-03+
Fix from $1,950 2024-07-24
Veristand CRITICAL 9.8
CVE-2024-6793

A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful ex…

Fix: after 2024
Fix from $2,300 2024-07-22
Veristand CRITICAL 9.8
CVE-2024-6794

A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Success…

Fix: after 2024
Fix from $2,300 2024-07-22
Unclassified HIGH 7.8
CVE-2024-6675

A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires …

Mitigation only
Fix from $1,950 2024-07-22
Search \& Replace CRITICAL 9.8
CVE-2024-38759

Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a thr…

Fix: after 3.2.2
Fix from $2,300 2024-07-22
Unclassified HIGH 7.5
CVE-2024-6960

The H2O machine learning platform uses "Iced" classes as the primary means of moving Java Objects around the cluster. The Iced format supports inclus…

Mitigation only
Fix from $1,950 2024-07-21
Crmeb HIGH 7.5
CVE-2024-6944

A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of t…

Fix: after 5.4.0
Fix from $1,950 2024-07-21
Crmeb HIGH 8.8
CVE-2024-6943

A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function download…

Fix: after 5.4.0
Fix from $1,950 2024-07-21
Unclassified HIGH 8.8
CVE-2024-5726

The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization o…

Mitigation only
Fix from $1,950 2024-07-18
Access Rights Manager HIGH 8.8
CVE-2024-28074EPSS 11%

It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Unclassified CRITICAL 9.8
CVE-2024-40624

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks(…

Patch available
Fix from $2,300 2024-07-15
Linkis HIGH 8.8
CVE-2023-46801

In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version …

Fix: 1.6.0+
Fix from $1,950 2024-07-15
Linkis HIGH 8.8
CVE-2023-49566

In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSourc…

Fix: 1.6.0+
Fix from $1,950 2024-07-15
Unclassified MEDIUM 6.3
CVE-2024-6645

A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an un…

Mitigation only
Fix from $1,600 2024-07-10
Unclassified MEDIUM 6.3
CVE-2024-6644

A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the fi…

Mitigation only
Fix from $1,600 2024-07-10
Android HIGH 7.8
CVE-2024-31317

In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe des…

Patch available
Fix from $1,950 2024-07-09