Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unicopia CRITICAL 9.8
CVE-2023-39680

Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.

Fix: 1.2.0+
Fix from $2,300 2023-10-20
Essential Blocks CRITICAL 9.8
CVE-2023-4402

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrus…

Fix: 1.1.1 / 4.2.1+
Fix from $2,300 2023-10-20
Aria Operations For Logs HIGH 7.8
CVE-2023-34052

VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can tr…

Patch available
Fix from $1,950 2023-10-20
Access Rights Manager CRITICAL 9.8
CVE-2023-35182

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated user…

Fix: after 2023.2.0.73
Fix from $2,300 2023-10-19
Access Rights Manager CRITICAL 9.8
CVE-2023-35184

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abu…

Fix: after 2023.2.0.73
Fix from $2,300 2023-10-19
Access Rights Manager HIGH 8.8
CVE-2023-35186

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse…

Fix: after 2023.2.0.73
Fix from $1,950 2023-10-19
Access Rights Manager HIGH 8.8
CVE-2023-35180EPSS 27%

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse S…

Fix: after 2023.2.0.73
Fix from $1,950 2023-10-19
Inlong HIGH 7.5
CVE-2023-46227

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.…

Fix: 1.9.0+
Fix from $1,950 2023-10-19
Xxl Rpc CRITICAL 10.0
CVE-2023-45146

XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization…

Fix: after 1.7.0
Fix from $2,300 2023-10-18
Endpoint Manager CRITICAL 9.8
CVE-2023-35084

Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions…

Fix: 2022+
Fix from $2,300 2023-10-18
Weaver Xtreme Theme Support HIGH 7.2
CVE-2023-4971

The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections…

Fix: 6.3.1+
Fix from $1,950 2023-10-16
Vantage6 HIGH 7.2
CVE-2023-23930

vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default se…

Fix: 4.0.2+
Fix from $1,950 2023-10-11
Garden CRITICAL 9.0
CVE-2023-44392

Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library…

Fix: 0.12.65 / 0.13.17+
Fix from $2,300 2023-10-09
Geokit Rails CRITICAL 9.8
CVE-2023-26153

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location'…

Fix: 2.5.0+
Fix from $2,300 2023-10-06
Test Site Creator CRITICAL 9.8
CVE-2023-43981

Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.

Fix: after 1.1.1
Fix from $2,300 2023-10-05
Redisson HIGH 8.8
CVE-2023-42809

Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain J…

Fix: 3.22.0+
Fix from $1,950 2023-10-04
Ecostruxure Power Monitoring Expert CRITICAL 9.8
CVE-2023-5391

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by se…

No fix yet
Fix from $2,300 2023-10-04
Aurora Files HIGH 8.8
CVE-2023-43176

A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

Patch available
Fix from $1,950 2023-10-03
Deyue Remote Vehicle Management System HIGH 8.8
CVE-2023-43268

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

No fix yet
Fix from $1,950 2023-10-02
Avro HIGH 7.5
CVE-2023-39410

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of …

Fix: 1.11.3+
Fix from $1,950 2023-09-29
Gnark Crypto CRITICAL 9.8
CVE-2023-44273

Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensur…

Fix: 0.12.0+
Fix from $2,300 2023-09-28
Core Policy Compute Engine HIGH 8.8
CVE-2023-5183

Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is req…

Fix: 19.3.7 / 21.2.8+
Fix from $1,950 2023-09-27
Emlog CRITICAL 9.8
CVE-2023-43291

Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

Fix: after 2.1.15
Fix from $2,300 2023-09-27
Ws Ftp Server HIGH 8.8
CVE-2023-40044 KEVEPSS 90%

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tr…

Fix: 8.7.4 / 8.8.2+
Fix from $1,950 2023-09-27
Phppgadmin CRITICAL 9.8
CVE-2023-40619

phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data…

Fix: after 7.14.4
Fix from $2,300 2023-09-20
Spider Flow CRITICAL 9.8
CVE-2023-5016

A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability is the function DriverManager.…

Fix: after 0.5.0
Fix from $2,300 2023-09-17
Glib HIGH 7.5
CVE-2023-32636

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation adde…

Fix: 2.74.4+
Fix from $1,950 2023-09-14
Glib MEDIUM 5.5
CVE-2023-32665

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processi…

Fix: 2.74.4+
Fix from $1,600 2023-09-14
Coldfusion CRITICAL 9.8
CVE-2023-38204EPSS 67%

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vu…

Mitigation only
Fix from $2,300 2023-09-14
Azure Devops Server HIGH 8.1
CVE-2023-38155

Azure DevOps Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-09-12