Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.0 CVE-2024-43252 Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1. Mitigation only Fix from $2,3002024-08-19 CRITICAL 10.0 CVE-2024-43242 Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro:… Ultimate Membership Pro after 12.6 Fix from $2,3002024-08-19 CRITICAL 9.8 CVE-2024-37099 Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1. Givewp 3.14.2+ Fix from $2,3002024-08-19 CRITICAL 9.8 CVE-2024-28986 KEVEPSS 85% SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… Web Help Desk after 12.8.2 Fix from $2,3002024-08-13 CRITICAL 9.8 CVE-2024-43141 Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Par… Mitigation only Fix from $2,3002024-08-13 HIGH 8.8 CVE-2024-7561 The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted i… Mitigation only Fix from $1,9502024-08-08 HIGH 8.8 CVE-2024-7486 The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrust… Mitigation only Fix from $1,9502024-08-08 HIGH 7.2 CVE-2024-7560 The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted… Mitigation only Fix from $1,9502024-08-08 HIGH 8.8 CVE-2024-36131 An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary com… Endpoint Manager Mobile 12.1.0.1+ Fix from $1,9502024-08-07 HIGH 8.3 CVE-2024-39636 Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.… Mitigation only Fix from $1,9502024-08-01 MEDIUM 5.5 CVE-2024-39630 Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Ev… Mitigation only Fix from $1,6002024-08-01 HIGH 8.8 CVE-2024-6152 The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5 via deserialization of untru… Mitigation only Fix from $1,9502024-07-27 HIGH 7.1 CVE-2024-39673 Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect servic… Emui No fix yet Fix from $1,9502024-07-25 CRITICAL 9.8 CVE-2024-6327 In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deseriali… Telerik Report Server 10.1.24.709+ Fix from $2,3002024-07-24 HIGH 8.8 CVE-2024-7067 A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. A… Ecommerce Laravel Bootstrap 2024-07-03+ Fix from $1,9502024-07-24 CRITICAL 9.8 CVE-2024-6793 A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful ex… Veristand after 2024 Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-6794 A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Success… Veristand after 2024 Fix from $2,3002024-07-22 HIGH 7.8 CVE-2024-6675 A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires … Mitigation only Fix from $1,9502024-07-22 CRITICAL 9.8 CVE-2024-38759 Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a thr… Search \& Replace after 3.2.2 Fix from $2,3002024-07-22 HIGH 7.5 CVE-2024-6960 The H2O machine learning platform uses "Iced" classes as the primary means of moving Java Objects around the cluster. The Iced format supports inclus… Mitigation only Fix from $1,9502024-07-21 HIGH 7.5 CVE-2024-6944 A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of t… Crmeb after 5.4.0 Fix from $1,9502024-07-21 HIGH 8.8 CVE-2024-6943 A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function download… Crmeb after 5.4.0 Fix from $1,9502024-07-21 HIGH 8.8 CVE-2024-5726 The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization o… Mitigation only Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-28074EPSS 11% It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented … Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 CRITICAL 9.8 CVE-2024-40624 TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks(… Patch available Fix from $2,3002024-07-15 HIGH 8.8 CVE-2023-46801 In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version … Linkis 1.6.0+ Fix from $1,9502024-07-15 HIGH 8.8 CVE-2023-49566 In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSourc… Linkis 1.6.0+ Fix from $1,9502024-07-15 MEDIUM 6.3 CVE-2024-6645 A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an un… Mitigation only Fix from $1,6002024-07-10 MEDIUM 6.3 CVE-2024-6644 A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the fi… Mitigation only Fix from $1,6002024-07-10 HIGH 7.8 CVE-2024-31317 In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe des… Android Patch available Fix from $1,9502024-07-09