Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2022-3861 The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted inp… Betheme 26.6+ Fix from $1,9502022-11-21 HIGH 8.8 CVE-2022-3525 Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0. Librenms 22.10.0+ Fix from $1,9502022-11-20 HIGH 8.8 CVE-2022-45077 Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress. Betheme 26.6+ Fix from $1,9502022-11-17 CRITICAL 9.8 CVE-2022-45047 Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j… Sshd after 2.9.1 Fix from $2,3002022-11-16 CRITICAL 9.8 CVE-2022-45136 Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u… Jena Sdb after 3.17.0 Fix from $2,3002022-11-14 CRITICAL 9.9 CVE-2022-38652 A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authent… Hyperic Agent Mitigation only Fix from $2,3002022-11-12 CRITICAL 10.0 CVE-2022-38650 A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m… Hyperic Server Mitigation only Fix from $2,3002022-11-12 CRITICAL 9.8 CVE-2022-44558 The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escal… Harmonyos No fix yet Fix from $2,3002022-11-09 CRITICAL 9.8 CVE-2022-44559 The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escal… Harmonyos No fix yet Fix from $2,3002022-11-09 CRITICAL 9.8 CVE-2022-44562 The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause pri… Emui Mitigation only Fix from $2,3002022-11-09 HIGH 8.8 CVE-2022-41203 In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can … Businessobjects Business Intelligence Mitigation only Fix from $1,9502022-11-08 HIGH 7.8 CVE-2022-32601 In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additio… Android Mitigation only Fix from $1,9502022-11-08 CRITICAL 9.8 CVE-2022-31199 KEVEPSS 36% Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server … Auditor 10.5+ Fix from $2,3002022-11-08 HIGH 8.8 CVE-2022-3536 The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate… Role Based Pricing For Woocommerce 1.6.3+ Fix from $1,9502022-11-07 HIGH 7.8 CVE-2022-42919 Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiproces… Python 3.9.16 / 3.10.9+ Fix from $1,9502022-11-07 HIGH 8.8 CVE-2022-43567 In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the … Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 CRITICAL 9.8 CVE-2022-39379EPSS 45% Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE)… Fedora 1.15.3+ Fix from $2,3002022-11-02 CRITICAL 9.8 CVE-2022-44542 lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/va… Lesspipe 2.06+ Fix from $2,3002022-11-01 CRITICAL 9.8 CVE-2022-41779 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connec… Infrasuite Device Master 00.00.02a+ Fix from $2,3002022-10-31 CRITICAL 9.8 CVE-2022-38142EPSS 18% Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service po… Infrasuite Device Master 00.00.02a+ Fix from $2,3002022-10-31 HIGH 7.2 CVE-2022-3334 The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an a… Easy Wp Smtp 1.5.0+ Fix from $1,9502022-10-31 HIGH 8.8 CVE-2022-3357 The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues whe… Smart Slider 3 3.5.1.11+ Fix from $1,9502022-10-31 HIGH 8.1 CVE-2022-3360 The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to… Learnpress 4.1.7.2+ Fix from $1,9502022-10-31 HIGH 7.2 CVE-2022-3366 The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of … Capabilities 2.5.2+ Fix from $1,9502022-10-31 HIGH 7.2 CVE-2022-3374 The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a h… Ocean Extra 2.0.5+ Fix from $1,9502022-10-31 HIGH 7.2 CVE-2022-3380 The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection iss… Customizer Export\/import 0.9.5+ Fix from $1,9502022-10-31 HIGH 8.8 CVE-2022-39944 In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when… Linkis after 1.2.0 Fix from $1,9502022-10-26 HIGH 8.8 CVE-2022-40238 A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object a… Vince 1.50.5+ Fix from $1,9502022-10-26 HIGH 7.2 CVE-2022-3335 The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object inj… Kadence Woocommerce Email Designer 1.5.7+ Fix from $1,9502022-10-25 CRITICAL 9.8 CVE-2022-39312 Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat… Dataease 1.15.2+ Fix from $2,3002022-10-25