Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
MEDIUM 6.5 CVE-2024-3591 The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthen… Geo Controller 8.6.5+ Fix from $1,6002024-05-01 HIGH 7.5 CVE-2024-1895 The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up t… Event Monster 1.4.0+ Fix from $1,9502024-04-30 HIGH 8.8 CVE-2024-27322EPSS 24% Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0… Mitigation only Fix from $1,9502024-04-29 MEDIUM 5.4 CVE-2024-33641 Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3. Mitigation only Fix from $1,6002024-04-29 CRITICAL 9.8 CVE-2024-33553 Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5. Xstore Core 5.3.9+ Fix from $2,3002024-04-29 HIGH 8.5 CVE-2024-32876 NewPipe is an Android app for video streaming written in Java. It supports exporting and importing backups, as a way to let users move their data to … Patch available Fix from $1,9502024-04-24 MEDIUM 5.4 CVE-2024-32835 Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a… Mitigation only Fix from $1,6002024-04-24 MEDIUM 6.3 CVE-2024-4019 A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected is an unknown function of the … Mitigation only Fix from $1,6002024-04-20 CRITICAL 9.6 CVE-2024-32600 Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5. Master Slider 3.9.7+ Fix from $2,3002024-04-18 HIGH 8.8 CVE-2024-32603 Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20. Buddypress Woocommerce My Account Integration 3.4.21+ Fix from $1,9502024-04-18 HIGH 7.2 CVE-2024-32431 Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2. Wp All Import 1.3+ Fix from $1,9502024-04-15 CRITICAL 9.8 CVE-2024-3740 A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file… Nginxwebui 4.2.4+ Fix from $2,3002024-04-13 HIGH 7.2 CVE-2024-3054EPSS 42% WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserializatio… Migration\, Backup\, Staging 0.9.100+ Fix from $1,9502024-04-12 HIGH 8.8 CVE-2024-27985 Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. Propertyhive 2.0.10+ Fix from $1,9502024-04-11 CRITICAL 9.6 CVE-2024-3568 The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkp… Transformers 4.38.0+ Fix from $2,3002024-04-10 HIGH 7.2 CVE-2024-3020 The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function… Mitigation only Fix from $1,9502024-04-10 HIGH 8.8 CVE-2024-2693 The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of u… Mitigation only Fix from $1,9502024-04-09 HIGH 7.5 CVE-2024-2501 The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… Mitigation only Fix from $1,9502024-04-09 HIGH 7.5 CVE-2024-1792 The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via deserialization of untrusted inp… Mitigation only Fix from $1,9502024-04-09 CRITICAL 9.8 CVE-2024-1813 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of u… Simple Job Board 2.11.1+ Fix from $2,3002024-04-09 CRITICAL 9.8 CVE-2024-31224 GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The ser… Gpt Academic 3.74+ Fix from $2,3002024-04-08 HIGH 8.8 CVE-2024-3431 A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&… Eyoucms Mitigation only Fix from $1,9502024-04-07 HIGH 7.2 CVE-2024-31308 Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26. Wp Import Export Lite 3.9.27+ Fix from $1,9502024-04-07 HIGH 8.7 CVE-2024-31277 Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32. Mitigation only Fix from $1,9502024-04-07 CRITICAL 9.8 CVE-2024-3366 A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file c… Xxl Job 2.4.1+ Fix from $2,3002024-04-06 CRITICAL 9.8 CVE-2024-31211 WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__… WordPress 6.4.2+ Fix from $2,3002024-04-04 HIGH 8.8 CVE-2024-2008 The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, … Mitigation only Fix from $1,9502024-04-04 CRITICAL 9.8 CVE-2024-27604 Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized. Alldata Mitigation only Fix from $2,3002024-04-02 CRITICAL 9.8 CVE-2023-51570 Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex… Viewpower Mitigation only Fix from $2,3002024-04-01 CRITICAL 9.8 CVE-2024-29433 A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data. Alldata Mitigation only Fix from $2,3002024-04-01