Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.5 CVE-2024-12627 The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection… Mitigation only Fix from $1,9502025-01-11 MEDIUM 6.6 CVE-2024-13295 Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3… Node Export 7.x-3.3+ Fix from $1,6002025-01-09 MEDIUM 6.6 CVE-2024-13296 Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1. Mailjet 4.0.1+ Fix from $1,6002025-01-09 MEDIUM 6.6 CVE-2024-13297 Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15. Eloqua 7.x-1.5+ Fix from $1,6002025-01-09 HIGH 7.2 CVE-2025-22510 Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affec… Mitigation only Fix from $1,9502025-01-09 MEDIUM 5.3 CVE-2023-27531 There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code Mitigation only Fix from $1,6002025-01-09 CRITICAL 9.8 CVE-2024-54676EPSS 65% Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions … Openmeetings 8.0.0+ Fix from $2,3002025-01-08 HIGH 8.8 CVE-2022-45185 An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to… Suitecrm No fix yet Fix from $1,9502025-01-07 HIGH 8.8 CVE-2024-55555EPSS 7% Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .… Patch available Fix from $1,9502025-01-07 CRITICAL 9.8 CVE-2024-55556EPSS 44% A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server … Mitigation only Fix from $2,3002025-01-07 HIGH 8.1 CVE-2024-56291 Deserialization of Untrusted Data vulnerability in plainware PlainInventory z-inventory-manager allows Object Injection.This issue affects PlainInven… Mitigation only Fix from $1,9502025-01-07 HIGH 8.1 CVE-2024-56283 Deserialization of Untrusted Data vulnerability in plainware Locatoraid Store Locator locatoraid allows Object Injection.This issue affects Locatorai… Mitigation only Fix from $1,9502025-01-07 CRITICAL 9.8 CVE-2024-49222 Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy… Mitigation only Fix from $2,3002025-01-07 HIGH 8.1 CVE-2024-12313 The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.1 via deser… Mitigation only Fix from $1,9502025-01-07 HIGH 7.2 CVE-2024-11465 The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via de… Custom Product Tabs For Woocommerce after 1.8.5 Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-20150 In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges … Lr12a Mitigation only Fix from $1,9502025-01-06 CRITICAL 9.8 CVE-2024-13136 A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the fi… Mysiteforme No fix yet Fix from $2,3002025-01-05 HIGH 8.8 CVE-2024-10957 The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via d… Mitigation only Fix from $1,9502025-01-04 HIGH 8.8 CVE-2024-10932 The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of un… Mitigation only Fix from $1,9502025-01-04 HIGH 7.5 CVE-2024-56068 Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through … Mitigation only Fix from $1,9502024-12-31 MEDIUM 6.3 CVE-2024-12994 A vulnerability was found in running-elephant Datart 1.0.0-rc3. It has been rated as critical. Affected by this issue is the function extractModel of… Mitigation only Fix from $1,6002024-12-28 CRITICAL 9.8 CVE-2024-52046EPSS 24% The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary… Mina 2.0.27 / 2.1.10+ Fix from $2,3002024-12-25 HIGH 7.2 CVE-2024-12721 The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.4 via de… Custom Product Tabs For Woocommerce after 1.2.4 Fix from $1,9502024-12-21 HIGH 7.8 CVE-2024-12677 Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code. Mitigation only Fix from $1,9502024-12-20 HIGH 7.8 CVE-2024-12741 A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires … Mitigation only Fix from $1,9502024-12-18 CRITICAL 9.8 CVE-2024-56058 Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector… Mitigation only Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-12687 Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue a… Plextrac 2.8.1+ Fix from $2,3002024-12-16 CRITICAL 9.8 CVE-2024-10095 In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulne… Ui For Wpf 24.4.1213+ Fix from $2,3002024-12-16 CRITICAL 9.8 CVE-2024-54367 Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a throu… Forumwp 2.1.1+ Fix from $2,3002024-12-16 HIGH 7.2 CVE-2024-54282 Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu wp-megamenu allows Object Injection.This issue affects WP Mega Menu: from n/a… Mitigation only Fix from $1,9502024-12-13