CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
2,435 results Clear all
CVE-2023-7032 7.8 HIGH EPSS 0.00
Schneider-electric Easergy Studio < 9.3.5 - Insecure Deserialization
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
CWE-502 Jan 09, 2024
CVE-2024-21318 8.8 HIGH EPSS 0.03
Microsoft Sharepoint Server - Insecure Deserialization
Microsoft SharePoint Server Remote Code Execution Vulnerability
CWE-502 Jan 09, 2024
CVE-2023-52202 9.1 CRITICAL EPSS 0.01
Svnlabs Html5 Mp3 Player With Folder ... - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.
CWE-502 Jan 08, 2024
CVE-2023-52206 7.7 HIGH EPSS 0.00
Blueastral Page Builder < 1.5.25 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
CWE-502 Jan 08, 2024
CVE-2023-52205 9.1 CRITICAL EPSS 0.01
Svnlabs Html5 Soundcloud Player With ... - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.
CWE-502 Jan 08, 2024
CVE-2023-52200 9.6 CRITICAL EPSS 0.00
Reputeinfosystems Armember < 4.0.22 - Insecure Deserialization
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: n/a.
CWE-502 Jan 08, 2024
CVE-2023-6528 8.8 HIGH EPSS 0.16
Slider Revolution <6.6.19 - RCE
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
CWE-502 Jan 08, 2024
CVE-2023-5235 8.8 HIGH EPSS 0.01
Kutethemes Ovic Responsive Wpbakery < 1.2.9 - Insecure Deserialization
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.
CWE-502 Jan 08, 2024
CVE-2023-52207 9.1 CRITICAL EPSS 0.00
Svnlabs Html5 Mp3 Player With Playlist Free - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.
CWE-502 Jan 08, 2024
CVE-2023-52225 10.0 CRITICAL EPSS 0.01
Taggbox < 3.1 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1.
CWE-502 Jan 08, 2024
CVE-2023-52219 9.9 CRITICAL EPSS 0.01
Gecka Terms Thumbnails < 1.1 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.
CWE-502 Jan 08, 2024
CVE-2023-52218 10.0 CRITICAL EPSS 0.01
Antonbond Woocommerce Tranzila Paymen... - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.
CWE-502 Jan 08, 2024
CVE-2024-0302 6.3 MEDIUM EPSS 0.00
Fhs-opensource Iparking - Insecure Deserialization
A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249869 was assigned to this vulnerability.
CWE-502 Jan 08, 2024
CVE-2023-49442 9.8 CRITICAL EPSS 0.56
Jeecg < 4.0 - Insecure Deserialization
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
CWE-502 Jan 03, 2024
CVE-2023-51785 7.5 HIGH EPSS 0.00
Apache InLong <1.10.0 - Deserialization
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/9331
CWE-502 Jan 03, 2024
CVE-2023-49777 9.1 CRITICAL EPSS 0.00
Yithemes Yith Woocommerce Product Add-ons - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.
CWE-502 Dec 31, 2023
CVE-2023-52182 9.9 CRITICAL EPSS 0.00
Ari-soft Ari Stream Quiz < 1.3.0 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.
CWE-502 Dec 31, 2023
CVE-2023-52181 10.0 CRITICAL EPSS 0.00
Presslabs Theme Per User < 1.0.1 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.
CWE-502 Dec 31, 2023
CVE-2023-51545 9.6 CRITICAL EPSS 0.00
ThemeHigh Job Manager & Career - CSRF
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and recruitments.This issue affects Job Manager & Career – Manage job board listings, and recruitments: from n/a through 1.4.4.
CWE-502 Dec 29, 2023
CVE-2023-51505 10.0 CRITICAL EPSS 0.01
Pluginus Woot < 1.0.6 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6.
CWE-502 Dec 29, 2023