Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2023-3232 A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wec… Crmeb after 4.6.0 Fix from $2,3002023-06-14 MEDIUM 6.5 CVE-2023-34212 The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all… Nifi after 1.21.0 Fix from $1,6002023-06-12 HIGH 8.8 CVE-2023-30262 An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacke… Mim Concurrent License Server after 7.0.9 Fix from $1,9502023-06-09 CRITICAL 9.8 CVE-2023-33496 xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode… Xxl Rpc after 1.7.0 Fix from $2,3002023-06-07 HIGH 8.8 CVE-2023-33284 Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute c… Msm after 14.19.0.12476 Fix from $1,9502023-06-07 HIGH 8.8 CVE-2023-20888EPSS 82% Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations… Vrealize Network Insight after 6.10.0 Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2020-36718 The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization… Gpdr Ccpa Compliance Support after 2.3 Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2020-36726 The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untru… Ultimate Reviews after 2.1.32 Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2020-36727 The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanit… Newsletter Manager after 1.5.1 Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2023-33963 DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase data… Dataease 1.18.7+ Fix from $2,3002023-06-01 HIGH 8.8 CVE-2023-2288EPSS 18% The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a … Otter 2.2.6+ Fix from $1,9502023-05-30 HIGH 8.8 CVE-2023-2500 The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3… Go Pricing after 3.3.19 Fix from $1,9502023-05-25 HIGH 8.8 CVE-2022-4815 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constr… Vantara Pentaho after 9.3.0.3 Fix from $1,9502023-05-24 CRITICAL 9.8 CVE-2023-27068 Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp… Experience Platform 10.2+ Fix from $2,3002023-05-23 HIGH 7.5 CVE-2023-31058 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.… Inlong after 1.6.0 Fix from $1,9502023-05-22 CRITICAL 9.8 CVE-2023-32336 IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X… Infosphere Information Server Mitigation only Fix from $2,3002023-05-22 CRITICAL 9.8 CVE-2023-31890 An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter. Glazed Lists No fix yet Fix from $2,3002023-05-16 HIGH 7.2 CVE-2023-20878 VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and … Cloud Foundation after 4.5 Fix from $1,9502023-05-12 HIGH 8.8 CVE-2023-30898 A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 … Siveillance Video No fix yet Fix from $1,9502023-05-09 HIGH 8.8 CVE-2023-30899 A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 … Siveillance Video Mitigation only Fix from $1,9502023-05-09 HIGH 7.2 CVE-2023-1347EPSS 16% The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users … Customizer Export\/import 0.9.6+ Fix from $1,9502023-05-08 CRITICAL 9.8 CVE-2023-1650EPSS 34% The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could … Wpbot 4.4.7+ Fix from $2,3002023-05-08 HIGH 8.8 CVE-2023-1196 The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which coul… Advanced Custom Fields 5.12.5 / 6.1.0+ Fix from $1,9502023-05-02 HIGH 7.2 CVE-2023-1669EPSS 18% The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin … Seopress 6.5.0.3+ Fix from $1,9502023-05-02 CRITICAL 9.8 CVE-2023-1967 Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid. N8844a after 2.1.7351 Fix from $2,3002023-04-27 CRITICAL 9.8 CVE-2023-20852 aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can… A\+hrd Mitigation only Fix from $2,3002023-04-27 CRITICAL 9.8 CVE-2023-20853 aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated r… A\+hrd Mitigation only Fix from $2,3002023-04-27 HIGH 8.8 CVE-2023-2141 An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution. Delmia Apriso after 2022 Fix from $1,9502023-04-21 CRITICAL 9.8 CVE-2023-20864EPSS 70% VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Oper… Aria Operations For Logs 8.12.0+ Fix from $2,3002023-04-20 CRITICAL 9.8 CVE-2021-28254 A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands. Laravel No fix yet Fix from $2,3002023-04-19