Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Crmeb CRITICAL 9.8
CVE-2023-3232

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wec…

Fix: after 4.6.0
Fix from $2,300 2023-06-14
Nifi MEDIUM 6.5
CVE-2023-34212

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all…

Fix: after 1.21.0
Fix from $1,600 2023-06-12
Mim Concurrent License Server HIGH 8.8
CVE-2023-30262

An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacke…

Fix: after 7.0.9
Fix from $1,950 2023-06-09
Xxl Rpc CRITICAL 9.8
CVE-2023-33496

xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode…

Fix: after 1.7.0
Fix from $2,300 2023-06-07
Msm HIGH 8.8
CVE-2023-33284

Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute c…

Fix: after 14.19.0.12476
Fix from $1,950 2023-06-07
Vrealize Network Insight HIGH 8.8
CVE-2023-20888EPSS 82%

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations…

Fix: after 6.10.0
Fix from $1,950 2023-06-07
Gpdr Ccpa Compliance Support CRITICAL 9.8
CVE-2020-36718

The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization…

Fix: after 2.3
Fix from $2,300 2023-06-07
Ultimate Reviews CRITICAL 9.8
CVE-2020-36726

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untru…

Fix: after 2.1.32
Fix from $2,300 2023-06-07
Newsletter Manager CRITICAL 9.8
CVE-2020-36727

The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanit…

Fix: after 1.5.1
Fix from $2,300 2023-06-07
Dataease CRITICAL 9.8
CVE-2023-33963

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase data…

Fix: 1.18.7+
Fix from $2,300 2023-06-01
Otter HIGH 8.8
CVE-2023-2288EPSS 18%

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a …

Fix: 2.2.6+
Fix from $1,950 2023-05-30
Go Pricing HIGH 8.8
CVE-2023-2500

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3…

Fix: after 3.3.19
Fix from $1,950 2023-05-25
Vantara Pentaho HIGH 8.8
CVE-2022-4815

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constr…

Fix: after 9.3.0.3
Fix from $1,950 2023-05-24
Experience Platform CRITICAL 9.8
CVE-2023-27068

Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…

Fix: 10.2+
Fix from $2,300 2023-05-23
Inlong HIGH 7.5
CVE-2023-31058

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Infosphere Information Server CRITICAL 9.8
CVE-2023-32336

IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X…

Mitigation only
Fix from $2,300 2023-05-22
Glazed Lists CRITICAL 9.8
CVE-2023-31890

An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.

No fix yet
Fix from $2,300 2023-05-16
Cloud Foundation HIGH 7.2
CVE-2023-20878

VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and …

Fix: after 4.5
Fix from $1,950 2023-05-12
Siveillance Video HIGH 8.8
CVE-2023-30898

A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 …

No fix yet
Fix from $1,950 2023-05-09
Siveillance Video HIGH 8.8
CVE-2023-30899

A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 …

Mitigation only
Fix from $1,950 2023-05-09
Customizer Export\/import HIGH 7.2
CVE-2023-1347EPSS 16%

The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users …

Fix: 0.9.6+
Fix from $1,950 2023-05-08
Wpbot CRITICAL 9.8
CVE-2023-1650EPSS 34%

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could …

Fix: 4.4.7+
Fix from $2,300 2023-05-08
Advanced Custom Fields HIGH 8.8
CVE-2023-1196

The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which coul…

Fix: 5.12.5 / 6.1.0+
Fix from $1,950 2023-05-02
Seopress HIGH 7.2
CVE-2023-1669EPSS 18%

The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin …

Fix: 6.5.0.3+
Fix from $1,950 2023-05-02
N8844a CRITICAL 9.8
CVE-2023-1967

Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.

Fix: after 2.1.7351
Fix from $2,300 2023-04-27
A\+hrd CRITICAL 9.8
CVE-2023-20852

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can…

Mitigation only
Fix from $2,300 2023-04-27
A\+hrd CRITICAL 9.8
CVE-2023-20853

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated r…

Mitigation only
Fix from $2,300 2023-04-27
Delmia Apriso HIGH 8.8
CVE-2023-2141

An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

Fix: after 2022
Fix from $1,950 2023-04-21
Aria Operations For Logs CRITICAL 9.8
CVE-2023-20864EPSS 70%

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Oper…

Fix: 8.12.0+
Fix from $2,300 2023-04-20
Laravel CRITICAL 9.8
CVE-2021-28254

A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

No fix yet
Fix from $2,300 2023-04-19