Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-3232
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wec…
Crmeb
after 4.6.0
MEDIUM 6.5
CVE-2023-34212
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all…
Nifi
after 1.21.0
HIGH 8.8
CVE-2023-30262
An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacke…
Mim Concurrent License Server
after 7.0.9
CRITICAL 9.8
CVE-2023-33496
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode…
Xxl Rpc
after 1.7.0
HIGH 8.8
CVE-2023-33284
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute c…
Msm
after 14.19.0.12476
HIGH 8.8
CVE-2023-20888EPSS 82%
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations…
Vrealize Network Insight
after 6.10.0
CRITICAL 9.8
CVE-2020-36718
The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization…
Gpdr Ccpa Compliance Support
after 2.3
CRITICAL 9.8
CVE-2020-36726
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untru…
Ultimate Reviews
after 2.1.32
CRITICAL 9.8
CVE-2020-36727
The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanit…
Newsletter Manager
after 1.5.1
CRITICAL 9.8
CVE-2023-33963
DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase data…
Dataease
1.18.7+
HIGH 8.8
CVE-2023-2288EPSS 18%
The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a …
Otter
2.2.6+
HIGH 8.8
CVE-2023-2500
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3…
Go Pricing
after 3.3.19
HIGH 8.8
CVE-2022-4815
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constr…
Vantara Pentaho
after 9.3.0.3
CRITICAL 9.8
CVE-2023-27068
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…
Experience Platform
10.2+
HIGH 7.5
CVE-2023-31058
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.…
Inlong
after 1.6.0
CRITICAL 9.8
CVE-2023-32336
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X…
Infosphere Information Server
Mitigation only
CRITICAL 9.8
CVE-2023-31890
An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.
Glazed Lists
No fix yet
HIGH 7.2
CVE-2023-20878
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and …
Cloud Foundation
after 4.5
HIGH 8.8
CVE-2023-30898
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 …
Siveillance Video
No fix yet
HIGH 8.8
CVE-2023-30899
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 …
Siveillance Video
Mitigation only
HIGH 7.2
CVE-2023-1347EPSS 16%
The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users …
Customizer Export\/import
0.9.6+
CRITICAL 9.8
CVE-2023-1650EPSS 34%
The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could …
Wpbot
4.4.7+
HIGH 8.8
CVE-2023-1196
The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which coul…
Advanced Custom Fields
5.12.5 / 6.1.0+
HIGH 7.2
CVE-2023-1669EPSS 18%
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin …
Seopress
6.5.0.3+
CRITICAL 9.8
CVE-2023-1967
Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.
N8844a
after 2.1.7351
CRITICAL 9.8
CVE-2023-20852
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can…
A\+hrd
Mitigation only
CRITICAL 9.8
CVE-2023-20853
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated r…
A\+hrd
Mitigation only
HIGH 8.8
CVE-2023-2141
An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.
Delmia Apriso
after 2022
CRITICAL 9.8
CVE-2023-20864EPSS 70%
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Oper…
Aria Operations For Logs
8.12.0+
CRITICAL 9.8
CVE-2021-28254
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
Laravel
No fix yet