Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
String Locator HIGH 8.8
CVE-2022-2434

The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to…

Fix: after 2.5.0
Fix from $1,950 2022-09-06
Download Manager HIGH 8.8
CVE-2022-2436

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to…

Fix: 3.2.50+
Fix from $1,950 2022-09-06
Broken Link Checker HIGH 7.2
CVE-2022-2438

The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and inc…

Fix: 1.11.17+
Fix from $1,950 2022-09-06
Migration\, Backup\, Staging HIGH 7.2
CVE-2022-2442

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versi…

Fix: after 0.9.74
Fix from $1,950 2022-09-06
Gravityzone CRITICAL 9.8
CVE-2022-2830

Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass uns…

Fix: 6.27.2-2 / 6.29.2-1+
Fix from $2,300 2022-09-05
Ofbiz CRITICAL 9.8
CVE-2022-29063

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Geode CRITICAL 9.8
CVE-2022-37021

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A…

Fix: after 1.13.4
Fix from $2,300 2022-08-31
Geode HIGH 8.8
CVE-2022-37022

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user…

Fix: after 1.13.2
Fix from $1,950 2022-08-31
Geode MEDIUM 6.5
CVE-2022-37023

Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user w…

Fix: 1.15.0+
Fix from $1,600 2022-08-31
Nvflare CRITICAL 9.8
CVE-2022-34668EPSS 9%

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged netwo…

Fix: 2.1.4+
Fix from $2,300 2022-08-29
Blue Prism HIGH 8.8
CVE-2022-36119

An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it …

Fix: 7.1+
Fix from $1,950 2022-08-25
Isagraf Workbench HIGH 7.8
CVE-2022-2465

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF …

Fix: after 6.6.9
Fix from $1,950 2022-08-25
Hadoop HIGH 8.8
CVE-2021-25642

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation…

Fix: 2.10.2 / 3.2.4+
Fix from $1,950 2022-08-25
Openshift HIGH 8.1
CVE-2021-4125

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J…

Fix: 4.6.52 / 4.7.40+
Fix from $1,950 2022-08-24
Fabric8 Kubernetes MEDIUM 6.7
CVE-2021-4178

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configure…

Fix: 5.0.3 / 5.1.2+
Fix from $1,600 2022-08-24
Easy Digital Downloads HIGH 7.2
CVE-2022-33900

PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.

Fix: after 3.0.1
Fix from $1,950 2022-08-22
Fishbowl CRITICAL 9.8
CVE-2022-29805EPSS 27%

A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code v…

Fix: 2022.4.1+
Fix from $2,300 2022-08-19
Laravel HIGH 8.8
CVE-2022-2886

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserializati…

Fix: after 5.1.46
Fix from $1,950 2022-08-19
Laravel CRITICAL 9.8
CVE-2022-2870

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deseria…

Fix: after 5.1.46
Fix from $2,300 2022-08-17
Arvados HIGH 8.8
CVE-2022-36006

Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execut…

Fix: 2.4.2+
Fix from $1,950 2022-08-15
Big Ip Domain Name System MEDIUM 6.5
CVE-2022-33947

In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclo…

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,600 2022-08-04
Devexpress HIGH 8.8
CVE-2022-28684

This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit t…

Fix: 18.1.18 / 18.2.17+
Fix from $1,950 2022-08-03
Mailhunter Ultimate CRITICAL 9.8
CVE-2022-35223

EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious…

Fix: after 2020
Fix from $2,300 2022-08-02
Debian Linux HIGH 8.0
CVE-2022-30287EPSS 71%

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This th…

Fix: after 5.2.22
Fix from $1,950 2022-07-28
Ignition HIGH 7.8
CVE-2022-35872

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…

Mitigation only
Fix from $1,950 2022-07-25
Ignition HIGH 7.8
CVE-2022-35870EPSS 43%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…

Mitigation only
Fix from $1,950 2022-07-25
Genesis64 HIGH 7.8
CVE-2022-33315

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut…

Fix: after 10.95.210.01
Fix from $1,950 2022-07-20
Genesis64 HIGH 7.8
CVE-2022-33316

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut…

Fix: after 10.95.210.01
Fix from $1,950 2022-07-20
Genesis64 CRITICAL 9.8
CVE-2022-33318EPSS 45%

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut…

Fix: after 10.95.210.01
Fix from $2,300 2022-07-20
Genesis64 HIGH 7.8
CVE-2022-33320

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut…

Fix: after 10.95.210.01
Fix from $1,950 2022-07-20