| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with world-readable permissions when developers run the CLI. |
| picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load(). |
| picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. |
| picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks. |
| A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. |
| Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions. |
| Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. |
| Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions. |
| Unauthenticated PHP Object Injection in Behold <= 1.5 versions. |
| Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. |
| The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Deserialization is triggered automatically upon the post-import redirect that renders the list table, and again when any item is opened for editing, requiring no additional navigation beyond the import action itself. |
| Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. |
| Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions. |
| Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions. |
| Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. |
| Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions. |
| Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. |
| Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. |