Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.0 CVE-2023-40057 The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an… Access Rights Manager 2023.2.2+ Fix from $2,3002024-02-15 CRITICAL 9.8 CVE-2024-23759EPSS 48% Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/Add… Gambio No fix yet Fix from $2,3002024-02-12 CRITICAL 9.8 CVE-2023-46615 Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7. Kd Coming Soon after 1.7 Fix from $2,3002024-02-12 CRITICAL 9.8 CVE-2024-23512 Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.This issue affects ProductX – … Wowstore 3.1.5+ Fix from $2,3002024-02-12 CRITICAL 9.8 CVE-2024-24797 Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed … Ere Recently Viewed 2.0+ Fix from $2,3002024-02-12 HIGH 8.8 CVE-2024-24926 Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brook… Brooklyn after 4.9.7.6 Fix from $1,9502024-02-12 CRITICAL 9.8 CVE-2024-23513 Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. Propertyhive 2.0.6+ Fix from $2,3002024-02-12 HIGH 8.8 CVE-2024-24796 Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress P… Event Manager And Tickets Selling For Woocommerce 4.1.2+ Fix from $1,9502024-02-12 CRITICAL 9.8 CVE-2024-25100 Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Progr… Coupon Referral Program 1.8.4+ Fix from $2,3002024-02-12 MEDIUM 5.0 CVE-2024-1432 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22 and classified as problematic. This iss… Deepfacelab Mitigation only Fix from $1,6002024-02-11 CRITICAL 9.8 CVE-2024-1353 A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the file app/w… Phpems after 1.0 Fix from $2,3002024-02-09 HIGH 8.8 CVE-2024-24590 Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously u… Clearml after 1.14.2 Fix from $1,9502024-02-06 HIGH 7.2 CVE-2024-0668 The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserializat… Advanced Database Cleaner after 3.1.3 Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-6933EPSS 68% The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization … Better Search Replace 1.4.5+ Fix from $1,9502024-02-05 CRITICAL 9.8 CVE-2024-1225 A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the fi… Qibocms X1 after 1.0.6 Fix from $2,3002024-02-05 CRITICAL 9.8 CVE-2024-1198 A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/contro… Openbi after 6.0.3 Fix from $2,3002024-02-03 HIGH 8.8 CVE-2024-22320EPSS 73% IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe dese… Operational Decision Manager Patch available Fix from $1,9502024-02-02 CRITICAL 9.8 CVE-2024-1032 A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /ap… Openbi after 1.0.8 Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2024-0960 A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpick… Aiflow Mitigation only Fix from $2,3002024-01-27 CRITICAL 9.8 CVE-2024-0959 A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gi… Gibsonenv Mitigation only Fix from $2,3002024-01-27 CRITICAL 9.8 CVE-2024-0937 A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_… Temporai No fix yet Fix from $2,3002024-01-26 CRITICAL 10.0 CVE-2024-20253 A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to exe… Unified Communications Manager 12.5 / 14su3+ Fix from $2,3002024-01-26 HIGH 8.8 CVE-2024-0936 A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file … Temporai No fix yet Fix from $1,9502024-01-26 HIGH 7.5 CVE-2023-50943 Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "… Airflow 2.8.1+ Fix from $1,9502024-01-24 CRITICAL 9.8 CVE-2024-22309 Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0. Wpbot 5.1.1+ Fix from $2,3002024-01-24 CRITICAL 9.8 CVE-2024-22284 Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2. Asgaros Forum 2.8.0+ Fix from $2,3002024-01-24 CRITICAL 9.8 CVE-2024-23636 SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol us… Sofarpc 5.12.0+ Fix from $2,3002024-01-23 CRITICAL 9.8 CVE-2017-20189 In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if … Clojure 1.9.0+ Fix from $2,3002024-01-22 CRITICAL 9.8 CVE-2024-0739 A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leads… Leadshop after 1.4.20 Fix from $2,3002024-01-19 HIGH 7.2 CVE-2022-45083 Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form… Profilepress 4.4.0+ Fix from $1,9502024-01-19