Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Symfony1 CRITICAL 9.0
CVE-2024-28859

Symfony1 is a community fork of symfony 1.4 with DIC, form enhancements, latest Swiftmailer, better performance, composer compatible and PHP 8 suppor…

Fix: 1.5.18+
Fix from $2,300 2024-03-15
Post Grid\, Slider \& Carousel Ultimate HIGH 8.8
CVE-2024-2006

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injec…

Fix: 1.6.8+
Fix from $1,950 2024-03-13
Product Carousel Slider \& Grid Ultimate For Woocommerce HIGH 8.8
CVE-2024-1950

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc…

Fix: 1.9.8+
Fix from $1,950 2024-03-13
Unclassified HIGH 7.5
CVE-2024-1951

The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,…

Mitigation only
Fix from $1,950 2024-03-13
Play.ht HIGH 8.8
CVE-2024-1772

The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object Injection in all versions up…

Fix: after 3.6.4
Fix from $1,950 2024-03-13
Android MEDIUM 5.5
CVE-2024-0047

In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to …

Patch available
Fix from $1,600 2024-03-11
Pdf Invoices And Packing Slips For Woocommerce HIGH 8.8
CVE-2024-1773

The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1…

Fix: 1.3.8+
Fix from $1,950 2024-03-07
Ngrinder CRITICAL 9.8
CVE-2024-28211

nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry…

Fix: 3.5.9+
Fix from $2,300 2024-03-07
Ngrinder CRITICAL 9.8
CVE-2024-28212

nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

Fix: 3.5.9+
Fix from $2,300 2024-03-07
Ngrinder CRITICAL 9.8
CVE-2024-28213

nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary cod…

Fix: 3.5.9+
Fix from $2,300 2024-03-07
Inlong CRITICAL 9.1
CVE-2024-26580

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use…

Fix: 1.11.0+
Fix from $2,300 2024-03-06
Auto Refresh Single Page HIGH 8.8
CVE-2024-1731

The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization…

Fix: after 1.1
Fix from $1,950 2024-03-05
Vimeography HIGH 8.8
CVE-2024-0825

The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including…

Fix: 2.3.3+
Fix from $1,950 2024-03-05
Product Designer CRITICAL 9.8
CVE-2024-24302

An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to …

Fix: 1.178.36+
Fix from $2,300 2024-03-03
Security Event Manager HIGH 8.8
CVE-2024-0692EPSS 92%

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to ab…

Fix: 2023.4.1+
Fix from $1,950 2024-03-01
Slider Responsive Slideshow HIGH 8.8
CVE-2024-1859

The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a…

Fix: 1.4.0+
Fix from $1,950 2024-03-01
Fedora HIGH 7.5
CVE-2024-22871

An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 functi…

Fix: 1.11.2+
Fix from $1,950 2024-02-29
Dataease CRITICAL 9.1
CVE-2024-23328

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploite…

Fix: 1.18.15 / 2.3.0+
Fix from $2,300 2024-02-29
Wukong Crm CRITICAL 9.8
CVE-2024-23052

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in th…

No fix yet
Fix from $2,300 2024-02-29
James CRITICAL 9.8
CVE-2023-51518

Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi…

Mitigation only
Fix from $2,300 2024-02-27
Autoprognosis HIGH 7.5
CVE-2024-1748

A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_…

Mitigation only
Fix from $1,950 2024-02-22
Temmokumvc HIGH 8.1
CVE-2024-1750

A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library…

Fix: 2.3+
Fix from $1,950 2024-02-22
Hertzbeat CRITICAL 9.8
CVE-2023-51389

Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co…

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Php Svg Lib CRITICAL 9.8
CVE-2024-25117

php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-famil…

Fix: 0.5.2+
Fix from $2,300 2024-02-21
Camel HIGH 7.8
CVE-2024-22369

Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 b…

Fix: 3.21.4 / 4.0.4+
Fix from $1,950 2024-02-20
Camel CRITICAL 9.8
CVE-2024-23114

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa…

Fix: 3.21.4 / 4.0.4+
Fix from $2,300 2024-02-20
Torrentpier CRITICAL 9.8
CVE-2024-1651EPSS 34%

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure dese…

No fix yet
Fix from $2,300 2024-02-20
Emui HIGH 7.5
CVE-2023-52357

Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availabil…

Mitigation only
Fix from $1,950 2024-02-18
Agile Product Lifecycle Management HIGH 8.8
CVE-2024-20953 KEV

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily e…

Mitigation only
Fix from $1,950 2024-02-17
Access Rights Manager HIGH 8.0
CVE-2024-23478EPSS 82%

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows …

Fix: 2023.2.3+
Fix from $1,950 2024-02-15