Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.0 CVE-2024-28859 Symfony1 is a community fork of symfony 1.4 with DIC, form enhancements, latest Swiftmailer, better performance, composer compatible and PHP 8 suppor… Symfony1 1.5.18+ Fix from $2,3002024-03-15 HIGH 8.8 CVE-2024-2006 The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injec… Post Grid\, Slider \& Carousel Ultimate 1.6.8+ Fix from $1,9502024-03-13 HIGH 8.8 CVE-2024-1950 The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… Product Carousel Slider \& Grid Ultimate For Woocommerce 1.9.8+ Fix from $1,9502024-03-13 HIGH 7.5 CVE-2024-1951 The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,… Mitigation only Fix from $1,9502024-03-13 HIGH 8.8 CVE-2024-1772 The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object Injection in all versions up… Play.ht after 3.6.4 Fix from $1,9502024-03-13 MEDIUM 5.5 CVE-2024-0047 In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to … Android Patch available Fix from $1,6002024-03-11 HIGH 8.8 CVE-2024-1773 The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1… Pdf Invoices And Packing Slips For Woocommerce 1.3.8+ Fix from $1,9502024-03-07 CRITICAL 9.8 CVE-2024-28211 nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry… Ngrinder 3.5.9+ Fix from $2,3002024-03-07 CRITICAL 9.8 CVE-2024-28212 nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization. Ngrinder 3.5.9+ Fix from $2,3002024-03-07 CRITICAL 9.8 CVE-2024-28213 nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary cod… Ngrinder 3.5.9+ Fix from $2,3002024-03-07 CRITICAL 9.1 CVE-2024-26580 Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use… Inlong 1.11.0+ Fix from $2,3002024-03-06 HIGH 8.8 CVE-2024-1731 The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization… Auto Refresh Single Page after 1.1 Fix from $1,9502024-03-05 HIGH 8.8 CVE-2024-0825 The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including… Vimeography 2.3.3+ Fix from $1,9502024-03-05 CRITICAL 9.8 CVE-2024-24302 An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to … Product Designer 1.178.36+ Fix from $2,3002024-03-03 HIGH 8.8 CVE-2024-0692EPSS 92% The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to ab… Security Event Manager 2023.4.1+ Fix from $1,9502024-03-01 HIGH 8.8 CVE-2024-1859 The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a… Slider Responsive Slideshow 1.4.0+ Fix from $1,9502024-03-01 HIGH 7.5 CVE-2024-22871 An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 functi… Fedora 1.11.2+ Fix from $1,9502024-02-29 CRITICAL 9.1 CVE-2024-23328 Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploite… Dataease 1.18.15 / 2.3.0+ Fix from $2,3002024-02-29 CRITICAL 9.8 CVE-2024-23052 An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in th… Wukong Crm No fix yet Fix from $2,3002024-02-29 CRITICAL 9.8 CVE-2023-51518 Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Gi… James Mitigation only Fix from $2,3002024-02-27 HIGH 7.5 CVE-2024-1748 A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_… Autoprognosis Mitigation only Fix from $1,9502024-02-22 HIGH 8.1 CVE-2024-1750 A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library… Temmokumvc 2.3+ Fix from $1,9502024-02-22 CRITICAL 9.8 CVE-2023-51389 Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co… Hertzbeat 1.4.1+ Fix from $2,3002024-02-22 CRITICAL 9.8 CVE-2024-25117 php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-famil… Php Svg Lib 0.5.2+ Fix from $2,3002024-02-21 HIGH 7.8 CVE-2024-22369 Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 b… Camel 3.21.4 / 4.0.4+ Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2024-23114 Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserializa… Camel 3.21.4 / 4.0.4+ Fix from $2,3002024-02-20 CRITICAL 9.8 CVE-2024-1651EPSS 34% Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure dese… Torrentpier No fix yet Fix from $2,3002024-02-20 HIGH 7.5 CVE-2023-52357 Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availabil… Emui Mitigation only Fix from $1,9502024-02-18 HIGH 8.8 CVE-2024-20953 KEV Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily e… Agile Product Lifecycle Management Mitigation only Fix from $1,9502024-02-17 HIGH 8.0 CVE-2024-23478EPSS 82% SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows … Access Rights Manager 2023.2.3+ Fix from $1,9502024-02-15