Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-3861
The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted inp…
Betheme
26.6+
HIGH 8.8
CVE-2022-3525
Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.
Librenms
22.10.0+
HIGH 8.8
CVE-2022-45077
Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.
Betheme
26.6+
CRITICAL 9.8
CVE-2022-45047
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j…
Sshd
after 2.9.1
CRITICAL 9.8
CVE-2022-45136
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u…
Jena Sdb
after 3.17.0
CRITICAL 9.9
CVE-2022-38652
A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authent…
Hyperic Agent
Mitigation only
CRITICAL 10.0
CVE-2022-38650
A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m…
Hyperic Server
Mitigation only
CRITICAL 9.8
CVE-2022-44558
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escal…
Harmonyos
No fix yet
CRITICAL 9.8
CVE-2022-44559
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escal…
Harmonyos
No fix yet
CRITICAL 9.8
CVE-2022-44562
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause pri…
Emui
Mitigation only
HIGH 8.8
CVE-2022-41203
In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can …
Businessobjects Business Intelligence
Mitigation only
HIGH 7.8
CVE-2022-32601
In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additio…
Android
Mitigation only
CRITICAL 9.8
CVE-2022-31199 KEVEPSS 36%
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server …
Auditor
10.5+
HIGH 8.8
CVE-2022-3536
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate…
Role Based Pricing For Woocommerce
1.6.3+
HIGH 7.8
CVE-2022-42919
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiproces…
Python
3.9.16 / 3.10.9+
HIGH 8.8
CVE-2022-43567
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the …
Splunk
8.1.12 / 8.2.9+
CRITICAL 9.8
CVE-2022-39379EPSS 45%
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE)…
Fedora
1.15.3+
CRITICAL 9.8
CVE-2022-44542
lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/va…
Lesspipe
2.06+
CRITICAL 9.8
CVE-2022-41779
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connec…
Infrasuite Device Master
00.00.02a+
CRITICAL 9.8
CVE-2022-38142EPSS 18%
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service po…
Infrasuite Device Master
00.00.02a+
HIGH 7.2
CVE-2022-3334
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an a…
Easy Wp Smtp
1.5.0+
HIGH 8.8
CVE-2022-3357
The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PHP object injection issues whe…
Smart Slider 3
3.5.1.11+
HIGH 8.1
CVE-2022-3360
The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to…
Learnpress
4.1.7.2+
HIGH 7.2
CVE-2022-3366
The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of …
Capabilities
2.5.2+
HIGH 7.2
CVE-2022-3374
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a h…
Ocean Extra
2.0.5+
HIGH 7.2
CVE-2022-3380
The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection iss…
Customizer Export\/import
0.9.5+
HIGH 8.8
CVE-2022-39944
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…
Linkis
after 1.2.0
HIGH 8.8
CVE-2022-40238
A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object a…
Vince
1.50.5+
HIGH 7.2
CVE-2022-3335
The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object inj…
Kadence Woocommerce Email Designer
1.5.7+
CRITICAL 9.8
CVE-2022-39312
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat…
Dataease
1.15.2+