Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Access Rights Manager CRITICAL 9.0
CVE-2023-40057

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an…

Fix: 2023.2.2+
Fix from $2,300 2024-02-15
Gambio CRITICAL 9.8
CVE-2024-23759EPSS 48%

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/Add…

No fix yet
Fix from $2,300 2024-02-12
Kd Coming Soon CRITICAL 9.8
CVE-2023-46615

Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

Fix: after 1.7
Fix from $2,300 2024-02-12
Wowstore CRITICAL 9.8
CVE-2024-23512

Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.This issue affects ProductX – …

Fix: 3.1.5+
Fix from $2,300 2024-02-12
Ere Recently Viewed CRITICAL 9.8
CVE-2024-24797

Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed …

Fix: 2.0+
Fix from $2,300 2024-02-12
Brooklyn HIGH 8.8
CVE-2024-24926

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brook…

Fix: after 4.9.7.6
Fix from $1,950 2024-02-12
Propertyhive CRITICAL 9.8
CVE-2024-23513

Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.

Fix: 2.0.6+
Fix from $2,300 2024-02-12
Event Manager And Tickets Selling For Woocommerce HIGH 8.8
CVE-2024-24796

Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress P…

Fix: 4.1.2+
Fix from $1,950 2024-02-12
Coupon Referral Program CRITICAL 9.8
CVE-2024-25100

Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Progr…

Fix: 1.8.4+
Fix from $2,300 2024-02-12
Deepfacelab MEDIUM 5.0
CVE-2024-1432

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22 and classified as problematic. This iss…

Mitigation only
Fix from $1,600 2024-02-11
Phpems CRITICAL 9.8
CVE-2024-1353

A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the file app/w…

Fix: after 1.0
Fix from $2,300 2024-02-09
Clearml HIGH 8.8
CVE-2024-24590

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously u…

Fix: after 1.14.2
Fix from $1,950 2024-02-06
Advanced Database Cleaner HIGH 7.2
CVE-2024-0668

The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserializat…

Fix: after 3.1.3
Fix from $1,950 2024-02-05
Better Search Replace HIGH 8.8
CVE-2023-6933EPSS 68%

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization …

Fix: 1.4.5+
Fix from $1,950 2024-02-05
Qibocms X1 CRITICAL 9.8
CVE-2024-1225

A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the fi…

Fix: after 1.0.6
Fix from $2,300 2024-02-05
Openbi CRITICAL 9.8
CVE-2024-1198

A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/contro…

Fix: after 6.0.3
Fix from $2,300 2024-02-03
Operational Decision Manager HIGH 8.8
CVE-2024-22320EPSS 73%

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe dese…

Patch available
Fix from $1,950 2024-02-02
Openbi CRITICAL 9.8
CVE-2024-1032

A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /ap…

Fix: after 1.0.8
Fix from $2,300 2024-01-30
Aiflow CRITICAL 9.8
CVE-2024-0960

A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpick…

Mitigation only
Fix from $2,300 2024-01-27
Gibsonenv CRITICAL 9.8
CVE-2024-0959

A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gi…

Mitigation only
Fix from $2,300 2024-01-27
Temporai CRITICAL 9.8
CVE-2024-0937

A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_…

No fix yet
Fix from $2,300 2024-01-26
Unified Communications Manager CRITICAL 10.0
CVE-2024-20253

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to exe…

Fix: 12.5 / 14su3+
Fix from $2,300 2024-01-26
Temporai HIGH 8.8
CVE-2024-0936

A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file …

No fix yet
Fix from $1,950 2024-01-26
Airflow HIGH 7.5
CVE-2023-50943

Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "…

Fix: 2.8.1+
Fix from $1,950 2024-01-24
Wpbot CRITICAL 9.8
CVE-2024-22309

Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.

Fix: 5.1.1+
Fix from $2,300 2024-01-24
Asgaros Forum CRITICAL 9.8
CVE-2024-22284

Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.

Fix: 2.8.0+
Fix from $2,300 2024-01-24
Sofarpc CRITICAL 9.8
CVE-2024-23636

SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol us…

Fix: 5.12.0+
Fix from $2,300 2024-01-23
Clojure CRITICAL 9.8
CVE-2017-20189

In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if …

Fix: 1.9.0+
Fix from $2,300 2024-01-22
Leadshop CRITICAL 9.8
CVE-2024-0739

A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leads…

Fix: after 1.4.20
Fix from $2,300 2024-01-19
Profilepress HIGH 7.2
CVE-2022-45083

Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form…

Fix: 4.4.0+
Fix from $1,950 2024-01-19