Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2024-41874EPSS 30% ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code… Coldfusion Mitigation only Fix from $2,3002024-09-13 HIGH 8.0 CVE-2024-28991 SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would a… Access Rights Manager 2024.3.1+ Fix from $1,9502024-09-12 HIGH 7.8 CVE-2024-45857 Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to ru… Mitigation only Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-45855 Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model … Mindsdb No fix yet Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-45852 Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbi… Mindsdb No fix yet Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-45853 Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model … Mindsdb No fix yet Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-45854 Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model … Mindsdb No fix yet Fix from $1,9502024-09-12 CRITICAL 9.8 CVE-2024-29847EPSS 53% Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated att… Endpoint Manager 2022+ Fix from $2,3002024-09-12 HIGH 7.5 CVE-2024-43466 Microsoft SharePoint Server Denial of Service Vulnerability Sharepoint Server Patch available Fix from $1,9502024-09-10 HIGH 7.2 CVE-2024-43464EPSS 36% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502024-09-10 HIGH 8.8 CVE-2024-38018EPSS 51% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2023-37227 Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. Spectrum 4.6+ Fix from $2,3002024-09-10 CRITICAL 9.8 CVE-2024-44902 A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. Thinkphp after 8.0.4 Fix from $2,3002024-09-09 HIGH 8.8 CVE-2024-37288 A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. Th… Kibana Mitigation only Fix from $1,9502024-09-09 CRITICAL 9.8 CVE-2024-40711 KEVEPSS 90% A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). Veeam Backup \& Replication 12.2.0.334+ Fix from $2,3002024-09-07 CRITICAL 9.1 CVE-2024-45758 H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. … H2o after 3.46.0.4 Fix from $2,3002024-09-06 HIGH 8.8 CVE-2024-7435 The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted inp… Attire 2.0.7+ Fix from $1,9502024-08-31 HIGH 7.2 CVE-2024-8016 The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of… Events Calendar Pro 7.0.2.1+ Fix from $1,9502024-08-30 HIGH 8.8 CVE-2024-2694 The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted i… Betheme after 27.5.6 Fix from $1,9502024-08-30 CRITICAL 9.8 CVE-2024-8255 Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrust… Dtn Soft after 2.0.1 Fix from $2,3002024-08-29 CRITICAL 9.8 CVE-2024-43931 Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3. Jobsearch Wp Job Board 2.5.4+ Fix from $2,3002024-08-29 HIGH 7.2 CVE-2022-2440 The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and inc… Theme Editor 2.9+ Fix from $1,9502024-08-29 CRITICAL 9.8 CVE-2024-8030 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider p… Ultimate Store Kit 2.0.4+ Fix from $2,3002024-08-28 HIGH 7.2 CVE-2024-7351 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of u… Simple Job Board 2.12.4+ Fix from $1,9502024-08-24 CRITICAL 9.8 CVE-2024-5335 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider p… Ultimate Store Kit 2.0.0+ Fix from $2,3002024-08-21 HIGH 8.8 CVE-2024-42362 Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/… Hertzbeat 1.6.0+ Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42363 Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows int… Patch available Fix from $1,9502024-08-20 CRITICAL 9.8 CVE-2024-8003 A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file … Gotribe Admin Patch available Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-5932EPSS 74% The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including… Givewp 3.14.2+ Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-43354 Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2. Mitigation only Fix from $2,3002024-08-19