Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Betheme HIGH 8.8
CVE-2022-3861

The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted inp…

Fix: 26.6+
Fix from $1,950 2022-11-21
Librenms HIGH 8.8
CVE-2022-3525

Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

Fix: 22.10.0+
Fix from $1,950 2022-11-20
Betheme HIGH 8.8
CVE-2022-45077

Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.

Fix: 26.6+
Fix from $1,950 2022-11-17
Sshd CRITICAL 9.8
CVE-2022-45047

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j…

Fix: after 2.9.1
Fix from $2,300 2022-11-16
Jena Sdb CRITICAL 9.8
CVE-2022-45136

Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u…

Fix: after 3.17.0
Fix from $2,300 2022-11-14
Hyperic Agent CRITICAL 9.9
CVE-2022-38652

A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authent…

Mitigation only
Fix from $2,300 2022-11-12
Hyperic Server CRITICAL 10.0
CVE-2022-38650

A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m…

Mitigation only
Fix from $2,300 2022-11-12
Harmonyos CRITICAL 9.8
CVE-2022-44558

The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escal…

No fix yet
Fix from $2,300 2022-11-09
Harmonyos CRITICAL 9.8
CVE-2022-44559

The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escal…

No fix yet
Fix from $2,300 2022-11-09
Emui CRITICAL 9.8
CVE-2022-44562

The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause pri…

Mitigation only
Fix from $2,300 2022-11-09
Businessobjects Business Intelligence HIGH 8.8
CVE-2022-41203

In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can …

Mitigation only
Fix from $1,950 2022-11-08
Android HIGH 7.8
CVE-2022-32601

In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additio…

Mitigation only
Fix from $1,950 2022-11-08
Auditor CRITICAL 9.8
CVE-2022-31199 KEVEPSS 36%

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server …

Fix: 10.5+
Fix from $2,300 2022-11-08
Role Based Pricing For Woocommerce HIGH 8.8
CVE-2022-3536

The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate…

Fix: 1.6.3+
Fix from $1,950 2022-11-07
Python HIGH 7.8
CVE-2022-42919

Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiproces…

Fix: 3.9.16 / 3.10.9+
Fix from $1,950 2022-11-07
Splunk HIGH 8.8
CVE-2022-43567

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the …

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Fedora CRITICAL 9.8
CVE-2022-39379EPSS 45%

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE)…

Fix: 1.15.3+
Fix from $2,300 2022-11-02
Lesspipe CRITICAL 9.8
CVE-2022-44542

lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/va…

Fix: 2.06+
Fix from $2,300 2022-11-01
Infrasuite Device Master CRITICAL 9.8
CVE-2022-41779

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connec…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master CRITICAL 9.8
CVE-2022-38142EPSS 18%

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service po…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Easy Wp Smtp HIGH 7.2
CVE-2022-3334

The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an a…

Fix: 1.5.0+
Fix from $1,950 2022-10-31
Smart Slider 3 HIGH 8.8
CVE-2022-3357

The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues whe…

Fix: 3.5.1.11+
Fix from $1,950 2022-10-31
Learnpress HIGH 8.1
CVE-2022-3360

The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to…

Fix: 4.1.7.2+
Fix from $1,950 2022-10-31
Capabilities HIGH 7.2
CVE-2022-3366

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of …

Fix: 2.5.2+
Fix from $1,950 2022-10-31
Ocean Extra HIGH 7.2
CVE-2022-3374

The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a h…

Fix: 2.0.5+
Fix from $1,950 2022-10-31
Customizer Export\/import HIGH 7.2
CVE-2022-3380

The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection iss…

Fix: 0.9.5+
Fix from $1,950 2022-10-31
Linkis HIGH 8.8
CVE-2022-39944

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…

Fix: after 1.2.0
Fix from $1,950 2022-10-26
Vince HIGH 8.8
CVE-2022-40238

A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object a…

Fix: 1.50.5+
Fix from $1,950 2022-10-26
Kadence Woocommerce Email Designer HIGH 7.2
CVE-2022-3335

The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object inj…

Fix: 1.5.7+
Fix from $1,950 2022-10-25
Dataease CRITICAL 9.8
CVE-2022-39312

Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat…

Fix: 1.15.2+
Fix from $2,300 2022-10-25