Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-41874EPSS 30%
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code…
Coldfusion
Mitigation only
HIGH 8.0
CVE-2024-28991
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would a…
Access Rights Manager
2024.3.1+
HIGH 7.8
CVE-2024-45857
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to ru…
Mitigation only
HIGH 7.5
CVE-2024-45855
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …
Mindsdb
No fix yet
HIGH 8.8
CVE-2024-45852
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbi…
Mindsdb
No fix yet
HIGH 7.5
CVE-2024-45853
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …
Mindsdb
No fix yet
HIGH 7.5
CVE-2024-45854
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …
Mindsdb
No fix yet
CRITICAL 9.8
CVE-2024-29847EPSS 53%
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated att…
Endpoint Manager
2022+
HIGH 7.5
CVE-2024-43466
Microsoft SharePoint Server Denial of Service Vulnerability
Sharepoint Server
Patch available
HIGH 7.2
CVE-2024-43464EPSS 36%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
Patch available
HIGH 8.8
CVE-2024-38018EPSS 51%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
Patch available
CRITICAL 9.8
CVE-2023-37227
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
Spectrum
4.6+
CRITICAL 9.8
CVE-2024-44902
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
Thinkphp
after 8.0.4
HIGH 8.8
CVE-2024-37288
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. Th…
Kibana
Mitigation only
CRITICAL 9.8
CVE-2024-40711 KEVEPSS 90%
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Veeam Backup \& Replication
12.2.0.334+
CRITICAL 9.1
CVE-2024-45758
H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. …
H2o
after 3.46.0.4
HIGH 8.8
CVE-2024-7435
The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted inp…
Attire
2.0.7+
HIGH 7.2
CVE-2024-8016
The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of…
Events Calendar Pro
7.0.2.1+
HIGH 8.8
CVE-2024-2694
The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted i…
Betheme
after 27.5.6
CRITICAL 9.8
CVE-2024-8255
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrust…
Dtn Soft
after 2.0.1
CRITICAL 9.8
CVE-2024-43931
Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.
Jobsearch Wp Job Board
2.5.4+
HIGH 7.2
CVE-2022-2440
The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and inc…
Theme Editor
2.9+
CRITICAL 9.8
CVE-2024-8030
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider p…
Ultimate Store Kit
2.0.4+
HIGH 7.2
CVE-2024-7351
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of u…
Simple Job Board
2.12.4+
CRITICAL 9.8
CVE-2024-5335
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider p…
Ultimate Store Kit
2.0.0+
HIGH 8.8
CVE-2024-42362
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/…
Hertzbeat
1.6.0+
HIGH 8.8
CVE-2024-42363
Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows int…
Patch available
CRITICAL 9.8
CVE-2024-8003
A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file …
Gotribe Admin
Patch available
CRITICAL 9.8
CVE-2024-5932EPSS 74%
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including…
Givewp
3.14.2+
CRITICAL 9.8
CVE-2024-43354
Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.
Mitigation only