| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file. |
| ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user. |
| EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. |
| MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function. |
| Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory.
To remediate this issue, users should upgrade to version 0.17.0 or later. |
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. |
| Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. |
| Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. |
| Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. |
| Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. |
| Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. |
| Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. |
| Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. |
| Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. |
| Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. |
| Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. |
| Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. |
| Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. |
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |