CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
2,435 results Clear all
CVE-2023-51470 9.9 CRITICAL EPSS 0.01
Rencontre - Dating Site <3.11.1 - Deserialization
Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.
CWE-502 Dec 29, 2023
CVE-2023-51422 9.9 CRITICAL EPSS 0.01
Saleswonder Team Webinar Plugin <3.05.0 - Deserialization
Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.
CWE-502 Dec 29, 2023
CVE-2023-51414 9.6 CRITICAL EPSS 0.01
EnvialoSimple <2.1 - Deserialization
Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.
CWE-502 Dec 29, 2023
CVE-2023-36381 6.6 MEDIUM EPSS 0.00
Zippy <1.6.5 - Use After Free
Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.
CWE-502 Dec 28, 2023
CVE-2023-32795 8.2 HIGH EPSS 0.00
Woocommerce Product Addons < 6.1.3 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.
CWE-502 Dec 28, 2023
CVE-2023-32513 7.5 HIGH EPSS 0.00
Givewp < 2.25.3 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.
CWE-502 Dec 28, 2023
CVE-2023-51700 6.4 MEDIUM 1 Writeup EPSS 0.01
Jamieblomerus Unofficial Mobile Bankid Integration < 1.0.1 - Insecure Deserialization
Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability, specifically impacting scenarios where an attacker can manipulate the database. If unauthorized actors gain access to the database, they could exploit this vulnerability to execute object injection attacks. This could lead to unauthorized code execution, data manipulation, or data exfiltration within the WordPress environment. Users of the plugin should upgrade to version 1.0.1 (or later), where the serialization and deserialization of OrderResponse objects have been switched out to an array stored as JSON. A possible workaround for users unable to upgrade immediately is to enforce stricter access controls on the database, ensuring that only trusted and authorized entities can modify data. Additionally, implementing monitoring tools to detect unusual database activities could help identify and mitigate potential exploitation attempts.
CWE-502 Dec 27, 2023
CVE-2022-34268 9.8 CRITICAL EPSS 0.00
RWS Worldserver < 11.7.3 - Insecure Deserialization
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.
CWE-502 Dec 25, 2023
CVE-2023-49826 8.1 HIGH EPSS 0.01
Pencidesign Soledad < 8.4.2 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.
CWE-502 Dec 21, 2023
CVE-2023-49778 10.0 CRITICAL EPSS 0.01
Dmry Sayfa Sayac < 2.6 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.
CWE-502 Dec 21, 2023
CVE-2023-32242 9.8 CRITICAL EXPLOITED EPSS 0.01
Xtemos Woodmart < 1.0.37 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.
CWE-502 Dec 21, 2023
CVE-2023-51656 9.8 CRITICAL EPSS 0.01
Apache IoTDB <1.2.2 - Deserialization
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
CWE-502 Dec 21, 2023
CVE-2022-47599 5.5 MEDIUM EPSS 0.00
Bitapps File Manager < 6.0.0 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7.
CWE-502 Dec 20, 2023
CVE-2023-7018 7.8 HIGH 1 Writeup EPSS 0.00
Huggingface Transformers < 4.36.0 - Insecure Deserialization
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
CWE-502 Dec 20, 2023
CVE-2023-49773 10.0 CRITICAL EPSS 0.00
Bcorp Shortcodes < 0.23 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Tim Brattberg BCorp Shortcodes.This issue affects BCorp Shortcodes: from n/a through 0.23.
CWE-502 Dec 20, 2023
CVE-2023-49772 10.0 CRITICAL EPSS 0.00
Phpbits Genesis Simple Love < 2.0 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Phpbits Creative Studio Genesis Simple Love.This issue affects Genesis Simple Love: from n/a through 2.0.
CWE-502 Dec 20, 2023
CVE-2023-28782 8.3 HIGH EPSS 0.00
Rocketgenius Inc. Gravity Forms <2.7.3 - Deserialization
Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.
CWE-502 Dec 20, 2023
CVE-2023-47507 7.1 HIGH EPSS 0.00
Averta Master Slider Pro < 3.6.5 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.
CWE-502 Dec 20, 2023
CVE-2023-46147 7.4 HIGH EPSS 0.00
Themify Themify Ultra - Use After Free
Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
CWE-502 Dec 20, 2023
CVE-2023-40555 8.3 HIGH EPSS 0.00
UX-themes Flatsome <3.17.5 - Deserialization
Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.
CWE-502 Dec 20, 2023