Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.8 CVE-2024-37064 Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted… Mitigation only Fix from $1,9502024-06-04 HIGH 7.8 CVE-2024-37065 Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitra… Mitigation only Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37058 Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37059 Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37060 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 7.8 CVE-2024-37062 Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted … Mitigation only Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37054 Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37055 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdar… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37056 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded Light… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37057 Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Ten… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37052 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37053 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.5 CVE-2024-3301 An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code … Mitigation only Fix from $1,9502024-05-30 CRITICAL 9.0 CVE-2024-3300 An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code e… Mitigation only Fix from $2,3002024-05-30 CRITICAL 9.8 CVE-2024-26289 Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, f… Pmb 7.3.18 / 7.4.9+ Fix from $2,3002024-05-27 CRITICAL 9.8 CVE-2024-5352 A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been rated as critical. Affected by this issue is the function validationRules o… Aj Report after 1.4.1 Fix from $2,3002024-05-26 CRITICAL 9.8 CVE-2024-5351 A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been declared as critical. Affected by this vulnerability is the function getVal… Aj Report after 1.4.1 Fix from $2,3002024-05-26 CRITICAL 9.8 CVE-2024-5085 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d… Hash Form 1.1.1+ Fix from $2,3002024-05-23 HIGH 8.0 CVE-2024-4471 The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.3.1 via… Mitigation only Fix from $1,9502024-05-23 HIGH 8.8 CVE-2024-4157 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection … Contact Form 5.1.16+ Fix from $1,9502024-05-22 HIGH 7.5 CVE-2024-31879 IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused… I Mitigation only Fix from $1,9502024-05-18 HIGH 7.5 CVE-2024-34997 joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE… Joblib No fix yet Fix from $1,9502024-05-17 HIGH 7.5 CVE-2024-4733 The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_sessio… Mitigation only Fix from $1,9502024-05-16 HIGH 7.5 CVE-2024-4838 The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrus… Mitigation only Fix from $1,9502024-05-16 HIGH 7.8 CVE-2024-4200 In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an ins… Telerik Reporting 18.1.24.514+ Fix from $1,9502024-05-15 CRITICAL 9.8 CVE-2024-3967 Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java ob… Imanager 3.2.6+ Fix from $2,3002024-05-15 CRITICAL 9.8 CVE-2024-3483 Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserializat… Imanager after 3.2.6 Fix from $2,3002024-05-15 HIGH 7.2 CVE-2024-30044EPSS 84% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server 16.0.17328.20292+ Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-30042 Microsoft Excel Remote Code Execution Vulnerability 365 Apps 16.0.10410.20003+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-4699EPSS 6% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue af… Dar 8000 10 Firmware after 20230922 Fix from $2,3002024-05-14