CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
2,435 results Clear all
CVE-2024-5871 9.8 CRITICAL EPSS 0.05
Wpwebelite Woocommerce Social Login < 2.6.3 - Insecure Deserialization
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CWE-502 Jun 15, 2024
CVE-2024-5671 9.8 CRITICAL EPSS 0.06
Trellix IPS Manager - RCE
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.
CWE-502 Jun 14, 2024
CVE-2024-4371 9.0 CRITICAL EPSS 0.05
Codexpert Codesigner < 4.5 - Insecure Deserialization
The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CWE-502 Jun 13, 2024
CVE-2024-3468 EPSS 0.01
AVEVA PI Web API - Code Injection
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
CWE-502 Jun 12, 2024
CVE-2024-3467 7.8 HIGH EPSS 0.00
Aveva PI Asset Framework Client - Insecure Deserialization
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.
CWE-502 Jun 12, 2024
CVE-2024-28964 7.8 HIGH EPSS 0.00
Dell Common Event Enabler < 8.9.10.0 - Insecure Deserialization
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.
CWE-502 Jun 12, 2024
CVE-2024-35249 8.8 HIGH EPSS 0.20
Microsoft Dynamics 365 Business Central - Insecure Deserialization
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
CWE-502 Jun 11, 2024
CVE-2024-36528 8.8 HIGH EPSS 0.00
nukeviet <4.5 - Code Injection
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.
CWE-502 Jun 10, 2024
CVE-2024-5675 10.0 CRITICAL EPSS 0.00
Mentor - Employee Portal <3.83.35 - Code Injection
Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.
CWE-502 Jun 06, 2024
CVE-2024-33568 8.5 HIGH EPSS 0.01
Bdthemes Element Pack < 7.7.4 - Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from n/a before 7.19.3.
CWE-22 Jun 04, 2024
CVE-2024-37065 7.8 HIGH EPSS 0.00
Pypi Skops - Insecure Deserialization
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
CWE-502 Jun 04, 2024
CVE-2024-37064 7.8 HIGH EPSS 0.00
Pypi Ydata-profiling - Insecure Deserialization
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.
CWE-502 Jun 04, 2024
CVE-2024-37062 7.8 HIGH EPSS 0.00
Pypi Ydata-profiling - Insecure Deserialization
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded.
CWE-502 Jun 04, 2024
CVE-2024-37060 8.8 HIGH EPSS 0.00
Lfprojects Mlflow - Insecure Deserialization
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.
CWE-502 Jun 04, 2024
CVE-2024-37059 8.8 HIGH EPSS 0.00
Lfprojects Mlflow - Insecure Deserialization
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.
CWE-502 Jun 04, 2024
CVE-2024-37058 8.8 HIGH EPSS 0.00
Lfprojects Mlflow - Insecure Deserialization
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.
CWE-502 Jun 04, 2024
CVE-2024-37057 8.8 HIGH EPSS 0.01
Lfprojects Mlflow - Insecure Deserialization
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.
CWE-502 Jun 04, 2024
CVE-2024-37056 8.8 HIGH EPSS 0.00
Lfprojects Mlflow - Insecure Deserialization
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.
CWE-502 Jun 04, 2024
CVE-2024-37055 8.8 HIGH EPSS 0.01
Lfprojects Mlflow - Insecure Deserialization
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.
CWE-502 Jun 04, 2024
CVE-2024-37054 8.8 HIGH 1 PoC Analysis EPSS 0.00
Lfprojects Mlflow - Insecure Deserialization
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.
CWE-502 Jun 04, 2024