Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2022-45845 Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9. Smart Slider 3 3.5.1.11+ Fix from $1,9502024-01-19 HIGH 7.8 CVE-2024-0654 A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function … Deepfacelab Mitigation only Fix from $1,9502024-01-18 MEDIUM 5.9 CVE-2024-20926 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Sup… Debian Linux Patch available Fix from $1,6002024-01-16 CRITICAL 9.8 CVE-2024-0603 A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontrolle… Zhicms after 4.0 Fix from $2,3002024-01-16 HIGH 7.5 CVE-2023-1405 The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a su… Formidable Forms 6.2+ Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2023-6049 The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users… Estatik 4.1.1+ Fix from $2,3002024-01-15 HIGH 7.8 CVE-2023-7032 A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher pri… Easergy Studio after 9.3.5 Fix from $1,9502024-01-09 HIGH 8.8 CVE-2024-21318EPSS 31% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502024-01-09 HIGH 7.2 CVE-2023-52202 Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 M… Html5 Mp3 Player With Folder Feedburner Playlist Free after 2.8.0 Fix from $1,9502024-01-08 HIGH 7.2 CVE-2023-52205 Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud P… Html5 Soundcloud Player With Playlist Free after 2.8.0 Fix from $1,9502024-01-08 HIGH 7.2 CVE-2023-52206 Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page … Page Builder\ after 1.5.25 Fix from $1,9502024-01-08 CRITICAL 9.8 CVE-2023-52200 Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restri… Armember after 4.0.22 Fix from $2,3002024-01-08 HIGH 8.8 CVE-2023-6528 The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when i… Slider Revolution 6.6.19+ Fix from $1,9502024-01-08 HIGH 8.8 CVE-2023-52207 Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Pla… Html5 Mp3 Player With Playlist Free after 3.0.0 Fix from $1,9502024-01-08 HIGH 8.8 CVE-2023-5235 The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow … Ovic Responsive Wpbakery 1.2.9+ Fix from $1,9502024-01-08 HIGH 8.8 CVE-2023-52219 Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1. Terms Thumbnails after 1.1 Fix from $1,9502024-01-08 CRITICAL 9.8 CVE-2023-52225 Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects T… Taggbox after 3.1 Fix from $2,3002024-01-08 CRITICAL 9.8 CVE-2023-52218 Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Ga… Woocommerce Tranzila Payment Gateway after 1.0.8 Fix from $2,3002024-01-08 CRITICAL 9.8 CVE-2024-0302 A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processi… Iparking No fix yet Fix from $2,3002024-01-08 CRITICAL 9.8 CVE-2023-49442EPSS 39% Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. Jeecg after 4.0 Fix from $2,3002024-01-03 HIGH 7.5 CVE-2023-51785 Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a… Inlong after 1.9.0 Fix from $1,9502024-01-03 HIGH 8.8 CVE-2023-49777 Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/… Yith Woocommerce Product Add Ons after 4.3.0 Fix from $1,9502023-12-31 CRITICAL 9.8 CVE-2023-52181 Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1. Theme Per User after 1.0.1 Fix from $2,3002023-12-31 HIGH 8.8 CVE-2023-52182 Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPres… Ari Stream Quiz after 1.3.0 Fix from $1,9502023-12-31 HIGH 8.8 CVE-2023-51545 Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and… Job Manager \& Career after 1.4.4 Fix from $1,9502023-12-29 CRITICAL 9.8 CVE-2023-51414 Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email… Envialosimple\ after 2.1 Fix from $2,3002023-12-29 HIGH 8.8 CVE-2023-51422 Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom M… Webinarignition after 3.05.0 Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-51470 Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a thr… Rencontre after 3.11.1 Fix from $1,9502023-12-29 CRITICAL 9.8 CVE-2023-51505 Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce st… Woot after 1.0.6 Fix from $2,3002023-12-29 HIGH 8.8 CVE-2023-36381 Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5. Zippy after 1.6.5 Fix from $1,9502023-12-28