Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Geo Controller MEDIUM 6.5
CVE-2024-3591

The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthen…

Fix: 8.6.5+
Fix from $1,600 2024-05-01
Event Monster HIGH 7.5
CVE-2024-1895

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up t…

Fix: 1.4.0+
Fix from $1,950 2024-04-30
Unclassified HIGH 8.8
CVE-2024-27322EPSS 24%

Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0…

Mitigation only
Fix from $1,950 2024-04-29
Unclassified MEDIUM 5.4
CVE-2024-33641

Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3.

Mitigation only
Fix from $1,600 2024-04-29
Xstore Core CRITICAL 9.8
CVE-2024-33553

Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

Fix: 5.3.9+
Fix from $2,300 2024-04-29
Unclassified HIGH 8.5
CVE-2024-32876

NewPipe is an Android app for video streaming written in Java. It supports exporting and importing backups, as a way to let users move their data to …

Patch available
Fix from $1,950 2024-04-24
Unclassified MEDIUM 5.4
CVE-2024-32835

Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a…

Mitigation only
Fix from $1,600 2024-04-24
Unclassified MEDIUM 6.3
CVE-2024-4019

A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected is an unknown function of the …

Mitigation only
Fix from $1,600 2024-04-20
Master Slider CRITICAL 9.6
CVE-2024-32600

Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.

Fix: 3.9.7+
Fix from $2,300 2024-04-18
Buddypress Woocommerce My Account Integration HIGH 8.8
CVE-2024-32603

Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.

Fix: 3.4.21+
Fix from $1,950 2024-04-18
Wp All Import HIGH 7.2
CVE-2024-32431

Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2.

Fix: 1.3+
Fix from $1,950 2024-04-15
Nginxwebui CRITICAL 9.8
CVE-2024-3740

A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file…

Fix: 4.2.4+
Fix from $2,300 2024-04-13
Migration\, Backup\, Staging HIGH 7.2
CVE-2024-3054EPSS 42%

WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserializatio…

Fix: 0.9.100+
Fix from $1,950 2024-04-12
Propertyhive HIGH 8.8
CVE-2024-27985

Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.

Fix: 2.0.10+
Fix from $1,950 2024-04-11
Transformers CRITICAL 9.6
CVE-2024-3568

The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkp…

Fix: 4.38.0+
Fix from $2,300 2024-04-10
Unclassified HIGH 7.2
CVE-2024-3020

The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function…

Mitigation only
Fix from $1,950 2024-04-10
Unclassified HIGH 8.8
CVE-2024-2693

The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of u…

Mitigation only
Fix from $1,950 2024-04-09
Unclassified HIGH 7.5
CVE-2024-2501

The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…

Mitigation only
Fix from $1,950 2024-04-09
Unclassified HIGH 7.5
CVE-2024-1792

The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via deserialization of untrusted inp…

Mitigation only
Fix from $1,950 2024-04-09
Simple Job Board CRITICAL 9.8
CVE-2024-1813

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of u…

Fix: 2.11.1+
Fix from $2,300 2024-04-09
Gpt Academic CRITICAL 9.8
CVE-2024-31224

GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The ser…

Fix: 3.74+
Fix from $2,300 2024-04-08
Eyoucms HIGH 8.8
CVE-2024-3431

A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&…

Mitigation only
Fix from $1,950 2024-04-07
Wp Import Export Lite HIGH 7.2
CVE-2024-31308

Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.

Fix: 3.9.27+
Fix from $1,950 2024-04-07
Unclassified HIGH 8.7
CVE-2024-31277

Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.

Mitigation only
Fix from $1,950 2024-04-07
Xxl Job CRITICAL 9.8
CVE-2024-3366

A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file c…

Fix: 2.4.1+
Fix from $2,300 2024-04-06
WordPress CRITICAL 9.8
CVE-2024-31211

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__…

Fix: 6.4.2+
Fix from $2,300 2024-04-04
Unclassified HIGH 8.8
CVE-2024-2008

The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …

Mitigation only
Fix from $1,950 2024-04-04
Alldata CRITICAL 9.8
CVE-2024-27604

Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.

Mitigation only
Fix from $2,300 2024-04-02
Viewpower CRITICAL 9.8
CVE-2023-51570

Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

Mitigation only
Fix from $2,300 2024-04-01
Alldata CRITICAL 9.8
CVE-2024-29433

A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.

Mitigation only
Fix from $2,300 2024-04-01