Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2023-39680 Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code. Unicopia 1.2.0+ Fix from $2,3002023-10-20 CRITICAL 9.8 CVE-2023-4402 The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrus… Essential Blocks 1.1.1 / 4.2.1+ Fix from $2,3002023-10-20 HIGH 7.8 CVE-2023-34052 VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can tr… Aria Operations For Logs Patch available Fix from $1,9502023-10-20 CRITICAL 9.8 CVE-2023-35182 The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated user… Access Rights Manager after 2023.2.0.73 Fix from $2,3002023-10-19 CRITICAL 9.8 CVE-2023-35184 The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abu… Access Rights Manager after 2023.2.0.73 Fix from $2,3002023-10-19 HIGH 8.8 CVE-2023-35186 The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse… Access Rights Manager after 2023.2.0.73 Fix from $1,9502023-10-19 HIGH 8.8 CVE-2023-35180EPSS 27% The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse S… Access Rights Manager after 2023.2.0.73 Fix from $1,9502023-10-19 HIGH 7.5 CVE-2023-46227 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.… Inlong 1.9.0+ Fix from $1,9502023-10-19 CRITICAL 10.0 CVE-2023-45146 XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization… Xxl Rpc after 1.7.0 Fix from $2,3002023-10-18 CRITICAL 9.8 CVE-2023-35084 Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions… Endpoint Manager 2022+ Fix from $2,3002023-10-18 HIGH 7.2 CVE-2023-4971 The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections… Weaver Xtreme Theme Support 6.3.1+ Fix from $1,9502023-10-16 HIGH 7.2 CVE-2023-23930 vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default se… Vantage6 4.0.2+ Fix from $1,9502023-10-11 CRITICAL 9.0 CVE-2023-44392 Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library… Garden 0.12.65 / 0.13.17+ Fix from $2,3002023-10-09 CRITICAL 9.8 CVE-2023-26153 Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location'… Geokit Rails 2.5.0+ Fix from $2,3002023-10-06 CRITICAL 9.8 CVE-2023-43981 Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php. Test Site Creator after 1.1.1 Fix from $2,3002023-10-05 HIGH 8.8 CVE-2023-42809 Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain J… Redisson 3.22.0+ Fix from $1,9502023-10-04 CRITICAL 9.8 CVE-2023-5391 A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by se… Ecostruxure Power Monitoring Expert No fix yet Fix from $2,3002023-10-04 HIGH 8.8 CVE-2023-43176 A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file. Aurora Files Patch available Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-43268 Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability. Deyue Remote Vehicle Management System No fix yet Fix from $1,9502023-10-02 HIGH 7.5 CVE-2023-39410 When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of … Avro 1.11.3+ Fix from $1,9502023-09-29 CRITICAL 9.8 CVE-2023-44273 Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensur… Gnark Crypto 0.12.0+ Fix from $2,3002023-09-28 HIGH 8.8 CVE-2023-5183 Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is req… Core Policy Compute Engine 19.3.7 / 21.2.8+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-43291 Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component. Emlog after 2.1.15 Fix from $2,3002023-09-27 HIGH 8.8 CVE-2023-40044 KEVEPSS 90% In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tr… Ws Ftp Server 8.7.4 / 8.8.2+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-40619 phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data… Phppgadmin after 7.14.4 Fix from $2,3002023-09-20 CRITICAL 9.8 CVE-2023-5016 A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability is the function DriverManager.… Spider Flow after 0.5.0 Fix from $2,3002023-09-17 HIGH 7.5 CVE-2023-32636 A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation adde… Glib 2.74.4+ Fix from $1,9502023-09-14 MEDIUM 5.5 CVE-2023-32665 A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processi… Glib 2.74.4+ Fix from $1,6002023-09-14 CRITICAL 9.8 CVE-2023-38204EPSS 67% Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vu… Coldfusion Mitigation only Fix from $2,3002023-09-14 HIGH 8.1 CVE-2023-38155 Azure DevOps Server Remote Code Execution Vulnerability Azure Devops Server Patch available Fix from $1,9502023-09-12