Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Smart Slider 3 HIGH 8.8
CVE-2022-45845

Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.

Fix: 3.5.1.11+
Fix from $1,950 2024-01-19
Deepfacelab HIGH 7.8
CVE-2024-0654

A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function …

Mitigation only
Fix from $1,950 2024-01-18
Debian Linux MEDIUM 5.9
CVE-2024-20926

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup…

Patch available
Fix from $1,600 2024-01-16
Zhicms CRITICAL 9.8
CVE-2024-0603

A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontrolle…

Fix: after 4.0
Fix from $2,300 2024-01-16
Formidable Forms HIGH 7.5
CVE-2023-1405

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a su…

Fix: 6.2+
Fix from $1,950 2024-01-16
Estatik CRITICAL 9.8
CVE-2023-6049

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users…

Fix: 4.1.1+
Fix from $2,300 2024-01-15
Easergy Studio HIGH 7.8
CVE-2023-7032

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher pri…

Fix: after 9.3.5
Fix from $1,950 2024-01-09
Sharepoint Server HIGH 8.8
CVE-2024-21318EPSS 31%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-01-09
Html5 Mp3 Player With Folder Feedburner Playlist Free HIGH 7.2
CVE-2023-52202

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 M…

Fix: after 2.8.0
Fix from $1,950 2024-01-08
Html5 Soundcloud Player With Playlist Free HIGH 7.2
CVE-2023-52205

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud P…

Fix: after 2.8.0
Fix from $1,950 2024-01-08
Page Builder\ HIGH 7.2
CVE-2023-52206

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page …

Fix: after 1.5.25
Fix from $1,950 2024-01-08
Armember CRITICAL 9.8
CVE-2023-52200

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restri…

Fix: after 4.0.22
Fix from $2,300 2024-01-08
Slider Revolution HIGH 8.8
CVE-2023-6528

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when i…

Fix: 6.6.19+
Fix from $1,950 2024-01-08
Html5 Mp3 Player With Playlist Free HIGH 8.8
CVE-2023-52207

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Pla…

Fix: after 3.0.0
Fix from $1,950 2024-01-08
Ovic Responsive Wpbakery HIGH 8.8
CVE-2023-5235

The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow …

Fix: 1.2.9+
Fix from $1,950 2024-01-08
Terms Thumbnails HIGH 8.8
CVE-2023-52219

Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.

Fix: after 1.1
Fix from $1,950 2024-01-08
Taggbox CRITICAL 9.8
CVE-2023-52225

Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects T…

Fix: after 3.1
Fix from $2,300 2024-01-08
Woocommerce Tranzila Payment Gateway CRITICAL 9.8
CVE-2023-52218

Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Ga…

Fix: after 1.0.8
Fix from $2,300 2024-01-08
Iparking CRITICAL 9.8
CVE-2024-0302

A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processi…

No fix yet
Fix from $2,300 2024-01-08
Jeecg CRITICAL 9.8
CVE-2023-49442EPSS 39%

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

Fix: after 4.0
Fix from $2,300 2024-01-03
Inlong HIGH 7.5
CVE-2023-51785

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a…

Fix: after 1.9.0
Fix from $1,950 2024-01-03
Yith Woocommerce Product Add Ons HIGH 8.8
CVE-2023-49777

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/…

Fix: after 4.3.0
Fix from $1,950 2023-12-31
Theme Per User CRITICAL 9.8
CVE-2023-52181

Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.

Fix: after 1.0.1
Fix from $2,300 2023-12-31
Ari Stream Quiz HIGH 8.8
CVE-2023-52182

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPres…

Fix: after 1.3.0
Fix from $1,950 2023-12-31
Job Manager \& Career HIGH 8.8
CVE-2023-51545

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and…

Fix: after 1.4.4
Fix from $1,950 2023-12-29
Envialosimple\ CRITICAL 9.8
CVE-2023-51414

Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email…

Fix: after 2.1
Fix from $2,300 2023-12-29
Webinarignition HIGH 8.8
CVE-2023-51422

Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom M…

Fix: after 3.05.0
Fix from $1,950 2023-12-29
Rencontre HIGH 8.8
CVE-2023-51470

Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a thr…

Fix: after 3.11.1
Fix from $1,950 2023-12-29
Woot CRITICAL 9.8
CVE-2023-51505

Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce st…

Fix: after 1.0.6
Fix from $2,300 2023-12-29
Zippy HIGH 8.8
CVE-2023-36381

Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.

Fix: after 1.6.5
Fix from $1,950 2023-12-28