Total
1658 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-1731 | 1 Rymera | 1 Auto Refresh Single Page | 2025-01-08 | N/A | N/A |
The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the arsp_options post meta option. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. | |||||
CVE-2024-49063 | 1 Microsoft | 1 Muzic | 2025-01-08 | N/A | 8.4 HIGH |
Microsoft/Muzic Remote Code Execution Vulnerability | |||||
CVE-2023-33496 | 1 Xxl-rpc Project | 1 Xxl-rpc | 2025-01-07 | N/A | 9.8 CRITICAL |
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode. | |||||
CVE-2023-20888 | 1 Vmware | 1 Vrealize Network Insight | 2025-01-07 | N/A | 8.8 HIGH |
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution. | |||||
CVE-2023-33284 | 1 Marvalglobal | 1 Msm | 2025-01-07 | N/A | 8.8 HIGH |
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server. | |||||
CVE-2024-56291 | 2025-01-07 | N/A | N/A | ||
Deserialization of Untrusted Data vulnerability in plainware.com PlainInventory allows Object Injection.This issue affects PlainInventory: from n/a through 3.1.6. | |||||
CVE-2024-49222 | 2025-01-07 | N/A | N/A | ||
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object Injection.This issue affects WPGuppy: from n/a through 1.1.0. | |||||
CVE-2024-56283 | 2025-01-07 | N/A | N/A | ||
Deserialization of Untrusted Data vulnerability in plainware.com Locatoraid Store Locator allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through 3.9.50. | |||||
CVE-2024-12313 | 2025-01-07 | N/A | 8.1 HIGH | ||
The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.1 via deserialization of untrusted input from the 'woo_compare_list' cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. | |||||
CVE-2023-30262 | 1 Mimsoftware | 2 Mim Concurrent License Server, Mim Local Concurrent License Server | 2025-01-06 | N/A | 8.8 HIGH |
An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacker to execute arbitrary code via the RMI Registry service. | |||||
CVE-2024-10932 | 2025-01-04 | N/A | 8.8 HIGH | ||
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files, retrieve sensitive data, or execute code. An administrator must create a staging site in order to trigger the exploit. | |||||
CVE-2024-6943 | 1 Crmeb | 1 Crmeb | 2025-01-03 | N/A | 8.8 HIGH |
A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function downloadImage of the file app/services/product/product/CopyTaobaoServices.php. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272065 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2024-6944 | 1 Crmeb | 1 Crmeb | 2025-01-03 | N/A | 7.5 HIGH |
A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of the file PublicController.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272066 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2024-56068 | 2024-12-31 | N/A | N/A | ||
Deserialization of Untrusted Data vulnerability in Azzaroco WP SuperBackup.This issue affects WP SuperBackup: from n/a through 2.3.3. | |||||
CVE-2024-12994 | 2024-12-28 | N/A | N/A | ||
A vulnerability was found in running-elephant Datart 1.0.0-rc3. It has been rated as critical. Affected by this issue is the function extractModel of the file /import of the component File Upload. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2024-12677 | 2024-12-20 | N/A | N/A | ||
Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code. | |||||
CVE-2024-40711 | 1 Veeam | 1 Veeam Backup \& Replication | 2024-12-20 | N/A | 9.8 CRITICAL |
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | |||||
CVE-2018-9474 | 1 Google | 1 Android | 2024-12-18 | N/A | 7.8 HIGH |
In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2024-10095 | 1 Telerik | 1 Ui For Wpf | 2024-12-18 | N/A | 9.8 CRITICAL |
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability. | |||||
CVE-2024-56058 | 2024-12-18 | N/A | N/A | ||
Deserialization of Untrusted Data vulnerability in Gueststream VRPConnector allows Object Injection.This issue affects VRPConnector: from n/a through 2.0.1. |