Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2022-2434 The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to… String Locator after 2.5.0 Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-2436 The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to… Download Manager 3.2.50+ Fix from $1,9502022-09-06 HIGH 7.2 CVE-2022-2438 The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and inc… Broken Link Checker 1.11.17+ Fix from $1,9502022-09-06 HIGH 7.2 CVE-2022-2442 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versi… Migration\, Backup\, Staging after 0.9.74 Fix from $1,9502022-09-06 CRITICAL 9.8 CVE-2022-2830 Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass uns… Gravityzone 6.27.2-2 / 6.29.2-1+ Fix from $2,3002022-09-05 CRITICAL 9.8 CVE-2022-29063 The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier… Ofbiz 18.12.06+ Fix from $2,3002022-09-02 CRITICAL 9.8 CVE-2022-37021 Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A… Geode after 1.13.4 Fix from $2,3002022-08-31 HIGH 8.8 CVE-2022-37022 Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user… Geode after 1.13.2 Fix from $1,9502022-08-31 MEDIUM 6.5 CVE-2022-37023 Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user w… Geode 1.15.0+ Fix from $1,6002022-08-31 CRITICAL 9.8 CVE-2022-34668EPSS 9% NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged netwo… Nvflare 2.1.4+ Fix from $2,3002022-08-29 HIGH 8.8 CVE-2022-36119 An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it … Blue Prism 7.1+ Fix from $1,9502022-08-25 HIGH 7.8 CVE-2022-2465 Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF … Isagraf Workbench after 6.6.9 Fix from $1,9502022-08-25 HIGH 8.8 CVE-2021-25642 ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation… Hadoop 2.10.2 / 3.2.4+ Fix from $1,9502022-08-25 HIGH 8.1 CVE-2021-4125 It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J… Openshift 4.6.52 / 4.7.40+ Fix from $1,9502022-08-24 MEDIUM 6.7 CVE-2021-4178 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configure… Fabric8 Kubernetes 5.0.3 / 5.1.2+ Fix from $1,6002022-08-24 HIGH 7.2 CVE-2022-33900 PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress. Easy Digital Downloads after 3.0.1 Fix from $1,9502022-08-22 CRITICAL 9.8 CVE-2022-29805EPSS 27% A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code v… Fishbowl 2022.4.1+ Fix from $2,3002022-08-19 HIGH 8.8 CVE-2022-2886 A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserializati… Laravel after 5.1.46 Fix from $1,9502022-08-19 CRITICAL 9.8 CVE-2022-2870 A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deseria… Laravel after 5.1.46 Fix from $2,3002022-08-17 HIGH 8.8 CVE-2022-36006 Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execut… Arvados 2.4.2+ Fix from $1,9502022-08-15 MEDIUM 6.5 CVE-2022-33947 In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclo… Big Ip Domain Name System 14.1.5 / 15.1.6.1+ Fix from $1,6002022-08-04 HIGH 8.8 CVE-2022-28684 This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit t… Devexpress 18.1.18 / 18.2.17+ Fix from $1,9502022-08-03 CRITICAL 9.8 CVE-2022-35223 EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious… Mailhunter Ultimate after 2020 Fix from $2,3002022-08-02 HIGH 8.0 CVE-2022-30287EPSS 71% Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This th… Debian Linux after 5.2.22 Fix from $1,9502022-07-28 HIGH 7.8 CVE-2022-35872 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).… Ignition Mitigation only Fix from $1,9502022-07-25 HIGH 7.8 CVE-2022-35870EPSS 43% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).… Ignition Mitigation only Fix from $1,9502022-07-25 HIGH 7.8 CVE-2022-33315 Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut… Genesis64 after 10.95.210.01 Fix from $1,9502022-07-20 HIGH 7.8 CVE-2022-33316 Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut… Genesis64 after 10.95.210.01 Fix from $1,9502022-07-20 CRITICAL 9.8 CVE-2022-33318EPSS 45% Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut… Genesis64 after 10.95.210.01 Fix from $2,3002022-07-20 HIGH 7.8 CVE-2022-33320 Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solut… Genesis64 after 10.95.210.01 Fix from $1,9502022-07-20