Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2024-09-12 CVE-2024-45852 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
network
low complexity
mindsdb CWE-502
8.8
2024-09-12 CVE-2024-45853 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.
network
high complexity
mindsdb CWE-502
7.5
2024-09-12 CVE-2024-45854 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.
network
high complexity
mindsdb CWE-502
7.5
2024-09-12 CVE-2024-45855 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.
network
high complexity
mindsdb CWE-502
7.5
2024-09-12 CVE-2024-29847 Deserialization of Untrusted Data vulnerability in Ivanti Endpoint Manager
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
network
low complexity
ivanti CWE-502
critical
9.8
2024-09-09 CVE-2024-44902 Deserialization of Untrusted Data vulnerability in Thinkphp
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
network
low complexity
thinkphp CWE-502
critical
9.8
2024-09-09 CVE-2024-37288 Deserialization of Untrusted Data vulnerability in Elastic Kibana 8.15.0
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload.
network
low complexity
elastic CWE-502
8.8
2024-09-07 CVE-2024-40711 Deserialization of Untrusted Data vulnerability in Veeam Backup & Replication 12.0.0.1420
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
network
low complexity
veeam CWE-502
critical
9.8
2024-08-31 CVE-2024-7435 The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input.
network
low complexity
CWE-502
8.8
2024-08-30 CVE-2024-8016 Deserialization of Untrusted Data vulnerability in Theeventscalendar Events Calendar PRO
The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets.
network
low complexity
theeventscalendar CWE-502
7.2