Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2024-10962 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via… Migration\, Backup\, Staging 0.9.108+ Fix from $1,9502024-11-14 HIGH 7.8 CVE-2024-43080 In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esc… Android Patch available Fix from $1,9502024-11-13 CRITICAL 9.8 CVE-2024-52306 FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter coul… Filemanager 2.0.2 / 3.0.9+ Fix from $2,3002024-11-13 HIGH 7.8 CVE-2024-10012 In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulne… Ui For Wpf 2024.4.1111+ Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-10013 In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization … Telerik Ui For Winforms 2024.4.1113+ Fix from $1,9502024-11-13 CRITICAL 9.8 CVE-2024-10828 The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via … Advanced Order Export For Woocommerce 3.5.6+ Fix from $2,3002024-11-13 HIGH 8.0 CVE-2024-8069 KEVEPSS 15% Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user … Session Recording 2407+ Fix from $1,9502024-11-12 CRITICAL 10.0 CVE-2024-44102 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy co… Telecontrol Server Basic 3.1.2.1+ Fix from $2,3002024-11-12 HIGH 7.3 CVE-2023-32736 A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All ver… Mitigation only Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-47072 XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application w… Patch available Fix from $1,9502024-11-08 HIGH 8.1 CVE-2024-10749 A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/contr… Thinkadmin after 6.1.67 Fix from $1,9502024-11-04 HIGH 8.1 CVE-2024-43383 Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8… Lucene.net Mitigation only Fix from $1,9502024-10-31 CRITICAL 9.8 CVE-2024-48112 A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. Thinkphp after 8.0.4 Fix from $2,3002024-10-30 CRITICAL 9.8 CVE-2024-10456EPSS 18% Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, … Mitigation only Fix from $2,3002024-10-30 CRITICAL 9.8 CVE-2024-50507 Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList:… Mitigation only Fix from $2,3002024-10-30 CRITICAL 9.8 CVE-2024-48063 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch… Pytorch after 2.4.1 Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-48206 A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code. Mitigation only Fix from $2,3002024-10-29 HIGH 8.8 CVE-2024-50408 Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a thr… Namaste\! Lms 2.6.4+ Fix from $1,9502024-10-28 HIGH 8.8 CVE-2024-50416 Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This … Wpc Shop As A Customer For Woocommerce 1.2.7+ Fix from $1,9502024-10-28 HIGH 7.2 CVE-2024-49684 Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue a… Mitigation only Fix from $1,9502024-10-23 CRITICAL 9.8 CVE-2024-49624 Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This is… Advanced Advertising System after 1.3.1 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49625 Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This … Sitebuilder Dynamic Components after 1.0 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49332 Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Bo… Giveaway Boost after 2.1.4 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49626 Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managment allows Object Injection.Th… Shipyaari Shipping Management after 1.2 Fix from $2,3002024-10-20 HIGH 8.8 CVE-2024-10079 The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untr… Wp Easy Post Types after 1.4.4 Fix from $1,9502024-10-18 CRITICAL 9.8 CVE-2024-49318 Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading … Mitigation only Fix from $2,3002024-10-17 HIGH 8.8 CVE-2024-49226 Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affec… Mitigation only Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-49227 Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects F… Mitigation only Fix from $2,3002024-10-16 CRITICAL 9.8 CVE-2024-49218 Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Objec… Mitigation only Fix from $2,3002024-10-16 CRITICAL 9.8 CVE-2024-48028 Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through… Mitigation only Fix from $2,3002024-10-16