Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Givewp CRITICAL 9.8
CVE-2023-32513

Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plug…

Fix: after 2.25.3
Fix from $2,300 2023-12-28
Product Addons HIGH 7.2
CVE-2023-32795

Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.

Fix: after 6.1.3
Fix from $1,950 2023-12-28
Unofficial Mobile Bankid Integration CRITICAL 9.8
CVE-2023-51700

Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1,…

Fix: 1.0.1+
Fix from $2,300 2023-12-27
Worldserver CRITICAL 9.8
CVE-2022-34268

An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution…

Fix: 11.7.3+
Fix from $2,300 2023-12-25
Sayfa Sayac CRITICAL 9.8
CVE-2023-49778

Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

Fix: after 2.6
Fix from $2,300 2023-12-21
Soledad CRITICAL 9.8
CVE-2023-49826

Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affec…

Fix: 8.4.2+
Fix from $2,300 2023-12-21
Woodmart CRITICAL 9.8
CVE-2023-32242

Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCom…

Fix: 1.0.37+
Fix from $2,300 2023-12-21
Iotdb CRITICAL 9.8
CVE-2023-51656

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended t…

Fix: after 0.13.4
Fix from $2,300 2023-12-21
File Manager HIGH 7.2
CVE-2022-47599

Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordP…

Fix: 6.0.0+
Fix from $1,950 2023-12-20
Transformers HIGH 7.8
CVE-2023-7018

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

Fix: 4.36.0+
Fix from $1,950 2023-12-20
Genesis Simple Love CRITICAL 9.8
CVE-2023-49772

Deserialization of Untrusted Data vulnerability in Phpbits Creative Studio Genesis Simple Love.This issue affects Genesis Simple Love: from n/a throu…

Fix: after 2.0
Fix from $2,300 2023-12-20
Bcorp Shortcodes CRITICAL 9.8
CVE-2023-49773

Deserialization of Untrusted Data vulnerability in Tim Brattberg BCorp Shortcodes.This issue affects BCorp Shortcodes: from n/a through 0.23.

Fix: after 0.23
Fix from $2,300 2023-12-20
Gravity Forms CRITICAL 9.8
CVE-2023-28782

Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.

Fix: 2.7.4+
Fix from $2,300 2023-12-20
Master Slider Pro CRITICAL 9.8
CVE-2023-47507

Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.

Fix: after 3.6.5
Fix from $2,300 2023-12-20
Flatsome CRITICAL 9.8
CVE-2023-40555

Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Mult…

Fix: 3.17.6+
Fix from $2,300 2023-12-20
Ultra HIGH 8.8
CVE-2023-46147

Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Fix: 7.3.6+
Fix from $1,950 2023-12-20
Recently Viewed Products CRITICAL 9.8
CVE-2023-34027

Deserialization of Untrusted Data vulnerability in Rajnish Arora Recently Viewed Products.This issue affects Recently Viewed Products: from n/a throu…

Fix: after 1.0.0
Fix from $2,300 2023-12-19
Dokan HIGH 8.8
CVE-2023-34382

Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Et…

Fix: 3.7.20+
Fix from $1,950 2023-12-19
Themesflat Addons For Elementor CRITICAL 9.8
CVE-2023-37390

Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: fro…

Fix: after 2.0.0
Fix from $2,300 2023-12-19
Transformers HIGH 8.8
CVE-2023-6730

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

Fix: 4.36.0+
Fix from $1,950 2023-12-19
Structured Content CRITICAL 9.8
CVE-2023-49819

Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Con…

Fix: after 1.5.3
Fix from $2,300 2023-12-19
E2pdf HIGH 7.2
CVE-2023-46154

Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool f…

Fix: after 1.20.18
Fix from $1,950 2023-12-19
Dubbo CRITICAL 9.8
CVE-2023-29234EPSS 7%

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…

Fix: after 3.2.4
Fix from $2,300 2023-12-15
Dubbo CRITICAL 9.8
CVE-2023-46279

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the …

Mitigation only
Fix from $2,300 2023-12-15
Php Svg Lib CRITICAL 9.8
CVE-2023-50252EPSS 24%

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges…

Fix: 0.5.1+
Fix from $2,300 2023-12-12
Deepfacelab HIGH 7.5
CVE-2023-6656

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has been rated as critical. Affecte…

Mitigation only
Fix from $1,950 2023-12-10
Phpems HIGH 8.8
CVE-2023-6654

A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library…

Mitigation only
Fix from $1,950 2023-12-10
Dir 846 Firmware HIGH 8.8
CVE-2023-6580

A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part of the file /HNAP1/ of the c…

No fix yet
Fix from $1,950 2023-12-07
Pydrive2 HIGH 7.8
CVE-2023-49297

PyDrive2 is a wrapper library of google-api-python-client that simplifies many common Google Drive API V2 tasks. Unsafe YAML deserilization will resu…

Fix: 1.16.2+
Fix from $1,950 2023-12-05
Elasticsearch HIGH 7.8
CVE-2023-46674

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been mo…

Fix: 7.17.11 / 8.9.0+
Fix from $1,950 2023-12-05