Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified MEDIUM 5.4
CVE-2024-4606

Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addon…

Mitigation only
Fix from $1,600 2024-05-14
Unclassified CRITICAL 9.8
CVE-2024-4413

The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of…

Mitigation only
Fix from $2,300 2024-05-14
Unclassified HIGH 7.8
CVE-2024-4044EPSS 15%

A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execut…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2024-3954

The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding …

Mitigation only
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.8
CVE-2024-3070

The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deseri…

Mitigation only
Fix from $2,300 2024-05-14
One Click Demo Import HIGH 7.2
CVE-2024-34433

Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.

Fix: 3.2.1+
Fix from $1,950 2024-05-14
Unclassified HIGH 7.2
CVE-2024-2290

The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untru…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 8.0
CVE-2024-29800

Deserialization of Untrusted Data vulnerability in Timber Team & Contributors Timber.This issue affects Timber: from n/a through 1.23.0.

Mitigation only
Fix from $1,950 2024-05-14
Veeam Service Provider Console CRITICAL 9.9
CVE-2024-29212

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and i…

Fix: 7.0.0.19551 / 8.0.0.19552+
Fix from $2,300 2024-05-14
Access Rights Manager HIGH 8.0
CVE-2024-28075EPSS 78%

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse…

Fix: 2023.2.4+
Fix from $1,950 2024-05-14
Java Software Development Kit HIGH 7.5
CVE-2023-38264

The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of…

Fix: 7.1.5.22 / 8.0.8.25+
Fix from $1,950 2024-05-14
Dm5500 Firmware HIGH 7.2
CVE-2024-22460

Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability. A remote attacker with high privileges could …

Fix: 5.16.0.0+
Fix from $1,950 2024-05-08
Inlong CRITICAL 9.8
CVE-2024-26579

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can by…

Fix: 1.12.0+
Fix from $2,300 2024-05-08
Unclassified HIGH 8.8
CVE-2024-34515

image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().

Patch available
Fix from $1,950 2024-05-05
Unclassified HIGH 8.8
CVE-2024-3240

The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrus…

Mitigation only
Fix from $1,950 2024-05-04
Unclassified MEDIUM 6.2
CVE-2024-34075

kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the `MarkovData#getNext` method u…

Patch available
Fix from $1,600 2024-05-03
Unclassified HIGH 7.8
CVE-2024-34072

sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeser…

Patch available
Fix from $1,950 2024-05-03
Viewpower CRITICAL 9.8
CVE-2023-51576

Voltronic Power ViewPower Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Mitigation only
Fix from $2,300 2024-05-03
Ignition HIGH 8.8
CVE-2023-50220

Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50221

Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50222

Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability a…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50223EPSS 55%

Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows …

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50218EPSS 55%

Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote at…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50219

Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attack…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-39473EPSS 62%

Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allow…

Fix: 8.1.35+
Fix from $1,950 2024-05-03
Ignition CRITICAL 9.8
CVE-2023-39475EPSS 64%

Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vuln…

Fix: 8.1.35+
Fix from $2,300 2024-05-03
Ignition CRITICAL 9.8
CVE-2023-39476

Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows…

Fix: 8.1.35+
Fix from $2,300 2024-05-03
Unclassified HIGH 7.5
CVE-2024-1896

The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to P…

Mitigation only
Fix from $1,950 2024-05-02
Unclassified HIGH 7.5
CVE-2024-1897

The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 vi…

Mitigation only
Fix from $1,950 2024-05-02
Shortcodes And Extra Features For Phlox Theme HIGH 7.5
CVE-2023-7064

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.…

Fix: 2.17.6+
Fix from $1,950 2024-05-02