Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.5
CVE-2024-31094

Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light…

Mitigation only
Fix from $1,950 2024-03-31
Essential Addons For Elementor HIGH 8.8
CVE-2024-3018

The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deseri…

Fix: 5.9.14+
Fix from $1,950 2024-03-30
Unclassified HIGH 8.8
CVE-2024-1872

The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via deserialization of untrusted i…

Mitigation only
Fix from $1,950 2024-03-29
Unclassified MEDIUM 5.4
CVE-2024-1858

The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.…

Mitigation only
Fix from $1,600 2024-03-29
Unclassified HIGH 8.1
CVE-2023-23649

Deserialization of Untrusted Data vulnerability in MainWP MainWP Links Manager Extension.This issue affects MainWP Links Manager Extension: from n/a …

Mitigation only
Fix from $1,950 2024-03-28
Sunshine Photo Cart CRITICAL 9.8
CVE-2024-30221

Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: …

Fix: 3.1.2+
Fix from $2,300 2024-03-28
Unclassified CRITICAL 9.9
CVE-2024-30228

Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.

Mitigation only
Fix from $2,300 2024-03-28
Givewp HIGH 7.2
CVE-2024-30229

Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2.

Fix: 3.5.0+
Fix from $1,950 2024-03-28
Pdf Invoices And Packing Slips For Woocommerce HIGH 8.8
CVE-2024-30230

Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing…

Fix: 1.3.8+
Fix from $1,950 2024-03-28
Armember CRITICAL 9.8
CVE-2024-30223

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.

Fix: 4.0.27+
Fix from $2,300 2024-03-28
Wholesalex CRITICAL 9.8
CVE-2024-30224

Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.

Fix: 1.3.3+
Fix from $2,300 2024-03-28
Unclassified CRITICAL 10.0
CVE-2024-30225

Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.

Mitigation only
Fix from $2,300 2024-03-28
Betterdocs CRITICAL 9.0
CVE-2024-30226

Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.

Fix: 3.3.4+
Fix from $2,300 2024-03-28
Unclassified CRITICAL 9.0
CVE-2024-30227

Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.

Mitigation only
Fix from $2,300 2024-03-28
Armember HIGH 8.8
CVE-2024-30222

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.

Fix: 4.0.27+
Fix from $1,950 2024-03-28
Unclassified HIGH 8.8
CVE-2024-1770

The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.2 via deserialization of un…

Mitigation only
Fix from $1,950 2024-03-28
Unclassified HIGH 8.7
CVE-2024-24842

Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledg…

Mitigation only
Fix from $1,950 2024-03-27
User Registration \& Membership HIGH 8.8
CVE-2023-27459

Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.

Fix: 2.3.3+
Fix from $1,950 2024-03-26
Gibbon HIGH 8.8
CVE-2024-24725EPSS 51%

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/Syst…

Fix: after 26.0.00
Fix from $1,950 2024-03-23
Unclassified HIGH 8.8
CVE-2024-2025

The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in al…

Mitigation only
Fix from $1,950 2024-03-23
Symfony1 CRITICAL 9.8
CVE-2024-28861

Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1…

Fix: 1.5.9+
Fix from $2,300 2024-03-22
Artica Proxy CRITICAL 9.8
CVE-2024-2054EPSS 81%

The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code…

No fix yet
Fix from $2,300 2024-03-21
Qiskit Ibm Runtime HIGH 7.8
CVE-2024-29032

Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. …

Fix: 0.21.2+
Fix from $1,950 2024-03-20
Telerik Reporting HIGH 8.8
CVE-2024-1856

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an inse…

Fix: 18.0.24.130+
Fix from $1,950 2024-03-20
Telerik Reporting HIGH 7.8
CVE-2024-1801

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insec…

Fix: 18.0.24.130+
Fix from $1,950 2024-03-20
Telerik Report Server HIGH 8.8
CVE-2024-1800EPSS 40%

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deseriali…

Fix: 10.0.24.130+
Fix from $1,950 2024-03-20
Social Media Share Buttons HIGH 8.8
CVE-2024-2721

Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media S…

Fix: after 2.1.0
Fix from $1,950 2024-03-20
Tourfic HIGH 8.8
CVE-2024-29136

Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17.

Fix: 2.11.19+
Fix from $1,950 2024-03-19
Unclassified HIGH 7.8
CVE-2024-2229

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into t…

Mitigation only
Fix from $1,950 2024-03-18
Social Media Share Buttons HIGH 8.8
CVE-2024-1685

The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserializa…

Fix: after 2.1.0
Fix from $1,950 2024-03-16