Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Sharepoint Server HIGH 7.2
CVE-2024-38094 KEVEPSS 51%

Microsoft SharePoint Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-07-09
Sharepoint Server HIGH 7.2
CVE-2024-38023EPSS 53%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-07-09
Sharepoint Server HIGH 7.2
CVE-2024-38024EPSS 45%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-07-09
Unclassified MEDIUM 6.5
CVE-2023-32735

A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V17 Update …

Mitigation only
Fix from $1,600 2024-07-09
Unclassified MEDIUM 6.3
CVE-2023-32737

A vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .N…

Mitigation only
Fix from $1,600 2024-07-09
Unclassified HIGH 7.8
CVE-2022-45147

A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIM…

Mitigation only
Fix from $1,950 2024-07-09
Woocommerce Social Login HIGH 7.5
CVE-2024-37502

Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from …

Fix: 2.7.0+
Fix from $1,950 2024-07-09
Seopress CRITICAL 9.8
CVE-2024-5488

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnera…

Fix: 7.9+
Fix from $2,300 2024-07-09
Dar 7000 Firmware HIGH 8.8
CVE-2024-6525

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue…

Fix: after 2023-09-22
Fix from $1,950 2024-07-05
Unclassified MEDIUM 6.3
CVE-2024-6441

A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the fi…

Patch available
Fix from $1,600 2024-07-02
Splunk HIGH 8.8
CVE-2024-36984

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they coul…

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Unclassified CRITICAL 9.8
CVE-2024-39705

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionalit…

Mitigation only
Fix from $2,300 2024-06-27
Whatsup Gold HIGH 7.2
CVE-2024-5016EPSS 22%

In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Re…

Fix: 23.1.0+
Fix from $1,950 2024-06-25
Bludit HIGH 8.8
CVE-2024-24551

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulner…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Bludit HIGH 8.1
CVE-2024-24550

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Unclassified MEDIUM 6.5
CVE-2024-39334

MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a victim opens the details of …

Mitigation only
Fix from $1,600 2024-06-23
Unclassified HIGH 8.1
CVE-2024-32030EPSS 34%

Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their ne…

Patch available
Fix from $1,950 2024-06-19
Unclassified HIGH 8.5
CVE-2024-35780

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: fro…

No fix yet
Fix from $1,950 2024-06-19
Universal Slider HIGH 8.8
CVE-2024-5649

The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.5 via deserialization of un…

Fix: after 1.6.5
Fix from $1,950 2024-06-19
Photo Video Gallery Master HIGH 8.8
CVE-2024-5724

The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserializa…

Fix: after 1.5.3
Fix from $1,950 2024-06-19
Woocommerce Social Login CRITICAL 9.8
CVE-2024-5871

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserializa…

Fix: 2.6.3+
Fix from $2,300 2024-06-15
Unclassified CRITICAL 9.8
CVE-2024-5671

Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access …

Mitigation only
Fix from $2,300 2024-06-14
Codesigner CRITICAL 9.8
CVE-2024-4371

The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object …

Fix: 4.5+
Fix from $2,300 2024-06-13
Pi Asset Framework Client HIGH 7.8
CVE-2024-3467

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under th…

Mitigation only
Fix from $1,950 2024-06-12
Unclassified HIGH 8.4
CVE-2024-3468

There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an inte…

Mitigation only
Fix from $1,950 2024-06-12
Common Event Enabler HIGH 7.8
CVE-2024-28964

Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attack…

Fix: after 8.9.10.0
Fix from $1,950 2024-06-12
Dynamics 365 Business Central HIGH 8.8
CVE-2024-35249

Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-06-11
Egovernment HIGH 8.8
CVE-2024-36528

nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/exten…

Fix: after 4.5.05
Fix from $1,950 2024-06-10
Mentor CRITICAL 9.8
CVE-2024-5675

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an…

Mitigation only
Fix from $2,300 2024-06-06
Element Pack MEDIUM 6.5
CVE-2024-33568

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element P…

Fix: after 7.7.4
Fix from $1,600 2024-06-04