Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2024-48030 Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Te… Mitigation only Fix from $2,3002024-10-16 CRITICAL 9.8 CVE-2024-48026 Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf… Mitigation only Fix from $2,3002024-10-16 HIGH 7.2 CVE-2021-4451 The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authe… Ninjafirewall after 4.3.3 Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-9634 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including… Givewp 3.16.4+ Fix from $2,3002024-10-16 HIGH 8.8 CVE-2024-45733 In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could p… Splunk 9.1.6 / 9.2.3+ Fix from $1,9502024-10-14 CRITICAL 9.8 CVE-2024-48033 Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue aff… Mitigation only Fix from $2,3002024-10-11 CRITICAL 9.8 CVE-2024-47074 DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JD… Dataease 1.18.25+ Fix from $2,3002024-10-11 CRITICAL 9.8 CVE-2024-47636 Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a throu… Jobsearch Wp Job Board after 2.5.9 Fix from $2,3002024-10-10 CRITICAL 9.2 CVE-2023-25581 pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulnerability. The vulnerability af… Mitigation only Fix from $2,3002024-10-10 HIGH 7.3 CVE-2024-9005 CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialize… Mitigation only Fix from $1,9502024-10-08 HIGH 7.2 CVE-2024-9314 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… Seo 1.0.229+ Fix from $1,9502024-10-05 HIGH 7.3 CVE-2024-47561 Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgr… Avro 1.11.4+ Fix from $1,9502024-10-03 HIGH 8.8 CVE-2024-8885 A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbi… Mitigation only Fix from $1,9502024-10-02 HIGH 8.8 CVE-2024-7432 The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untruste… Unseen Blog after 1.0.0 Fix from $1,9502024-10-01 HIGH 8.8 CVE-2024-7433 The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of untruste… Empowerment after 1.0.2 Fix from $1,9502024-10-01 HIGH 8.8 CVE-2024-7434 The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via deserialization of untrusted… Ultrapress after 1.2.1 Fix from $1,9502024-10-01 HIGH 8.0 CVE-2024-45772 Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before… Lucene Replicator 9.12.0+ Fix from $1,9502024-09-30 CRITICAL 9.8 CVE-2024-8353EPSS 29% The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including… Givewp 3.16.2+ Fix from $2,3002024-09-28 HIGH 8.8 CVE-2024-8922 The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an… Product Enquiry For Woocommerce 2.2.33.34+ Fix from $1,9502024-09-27 HIGH 8.8 CVE-2024-43191 IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request. Cloud Pak For Multicloud Management Monitoring Mitigation only Fix from $1,9502024-09-26 HIGH 7.8 CVE-2024-8316 In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulner… Ui For Wpf 2024.3.924+ Fix from $1,9502024-09-25 CRITICAL 9.8 CVE-2024-7576 In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulner… Ui For Wpf 2024.3.924+ Fix from $2,3002024-09-25 HIGH 7.2 CVE-2024-8514 The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 vi… Google Website Translator 1.4.12+ Fix from $1,9502024-09-25 HIGH 7.2 CVE-2022-2439 The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via … Easy Digital Downloads 3.3.4+ Fix from $1,9502024-09-24 HIGH 8.8 CVE-2024-42323EPSS 8% SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attac… Hertzbeat 1.6.0+ Fix from $1,9502024-09-21 HIGH 7.8 CVE-2024-8375 There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C+… Reverb 2024-08-05+ Fix from $1,9502024-09-19 HIGH 7.8 CVE-2024-5998 A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can … Langchain 0.2.9+ Fix from $1,9502024-09-17 CRITICAL 9.8 CVE-2024-22399 Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seat… Seata 1.8.1+ Fix from $2,3002024-09-16 CRITICAL 9.8 CVE-2024-8862 A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the f… H2o No fix yet Fix from $2,3002024-09-14 HIGH 7.2 CVE-2022-2446 The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and … Wp Editor 1.2.9.1+ Fix from $1,9502024-09-13