Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2025-0767 WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-c… Wp Activity Log Mitigation only Fix from $2,3002025-02-27 CRITICAL 9.8 CVE-2025-26900 Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue affects Flexmls® IDX: from n/a… Mitigation only Fix from $2,3002025-02-25 HIGH 7.2 CVE-2025-27300 Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1… Mitigation only Fix from $1,9502025-02-24 HIGH 7.2 CVE-2025-27301 Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager nhrrob-options-table-manager allows Object Injection.… Mitigation only Fix from $1,9502025-02-24 CRITICAL 9.8 CVE-2025-26763 Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Object Injection.This issue affects Re… Mitigation only Fix from $2,3002025-02-22 CRITICAL 9.8 CVE-2025-1556 A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the fil… Cicadascms No fix yet Fix from $2,3002025-02-22 HIGH 7.2 CVE-2024-13899 The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrus… Mambo Joomla Importer Mitigation only Fix from $1,9502025-02-22 HIGH 8.6 CVE-2025-1403 Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malforme… Qiskit after 1.2.4 Fix from $1,9502025-02-21 CRITICAL 9.8 CVE-2024-13789 The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted in… Ravpage after 2.31 Fix from $2,3002025-02-20 CRITICAL 9.9 CVE-2024-37361 The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara P… Mitigation only Fix from $2,3002025-02-20 HIGH 8.8 CVE-2024-28777 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allow… Cognos Controller 11.0.1.4+ Fix from $1,9502025-02-19 CRITICAL 9.8 CVE-2024-13556 The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all version… Affiliate Links 3.1.0+ Fix from $2,3002025-02-18 CRITICAL 9.8 CVE-2024-12562 The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untru… S2member 250214+ Fix from $2,3002025-02-15 CRITICAL 9.8 CVE-2024-56180 CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windo… Eventmesh 1.11.0+ Fix from $2,3002025-02-14 CRITICAL 9.0 CVE-2024-52577 In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabili… Ignite 2.17.0+ Fix from $2,3002025-02-14 CRITICAL 9.8 CVE-2024-13770 The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, … Puzzles 4.2.5+ Fix from $2,3002025-02-13 CRITICAL 9.8 CVE-2025-1186 A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects unknown code of the file /Con… Xunruicms after 4.6.4 Fix from $2,3002025-02-12 CRITICAL 9.8 CVE-2025-1177 A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/… Xunruicms No fix yet Fix from $2,3002025-02-11 CRITICAL 9.9 CVE-2025-24016 KEVEPSS 94% Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, a… Wazuh 4.9.1+ Fix from $2,3002025-02-10 CRITICAL 9.8 CVE-2025-1113 A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#… Tarzan Cms No fix yet Fix from $2,3002025-02-07 MEDIUM 6.6 CVE-2021-27017 Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Age… Mitigation only Fix from $1,6002025-02-07 HIGH 7.2 CVE-2024-9664 The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.7 via deserialization of u… Wp All Import 4.9.8+ Fix from $1,9502025-02-07 CRITICAL 9.5 CVE-2025-1077 A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weat… Mitigation only Fix from $2,3002025-02-07 HIGH 8.8 CVE-2025-0994 KEVEPSS 31% Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerabil… Cityworks 15.8.9 / 23.10+ Fix from $1,9502025-02-06 HIGH 7.2 CVE-2025-20124EPSS 18% A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected de… Identity Services Engine 3.1+ Fix from $1,9502025-02-05 HIGH 8.8 CVE-2025-24661 Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Object Inject… Mitigation only Fix from $1,9502025-02-03 MEDIUM 5.0 CVE-2025-0974 A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation o… Mitigation only Fix from $1,6002025-02-03 CRITICAL 9.8 CVE-2024-13742 The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4… Icontrolwp after 4.4.5 Fix from $2,3002025-01-30 HIGH 7.8 CVE-2025-24794 The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op… Snowflake Connector 3.13.1+ Fix from $1,9502025-01-29 HIGH 7.3 CVE-2025-0841 A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore… Mitigation only Fix from $1,9502025-01-29