| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. |
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. |
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. |
| Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. |
| The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution. |
| Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. |
| Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. |
| Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. |
| Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.
This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. |
| Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. |
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. |
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. |
| Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. |
| Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. |
| Unauthenticated PHP Object Injection in Agora <= 1.9 versions. |
| kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges. |
| Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root. |
| Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. |