Vulnerabilities (CVE)

Filtered by CWE-502
Total 3251 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-31903 1 Ibm 1 Sterling B2b Integrator 2026-06-17 N/A 8.8 HIGH
IBM Sterling B2B Integrator Standard EditionĀ 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
CVE-2024-31879 1 Ibm 1 I 2026-06-17 N/A 7.5 HIGH
IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.
CVE-2024-31317 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-31308 1 Vjinfotech 1 Wp Import Export Lite 2026-06-17 N/A 4.4 MEDIUM
Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.
CVE-2024-31277 2026-06-17 N/A 8.7 HIGH
Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.
CVE-2024-31224 1 Binary-husky 1 Gpt Academic 2026-06-17 N/A 9.8 CRITICAL
GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution. Any device that exposes the GPT Academic service to the Internet is vulnerable. Version 3.74 contains a patch for the issue. There are no known workarounds aside from upgrading to a patched version.
CVE-2024-31211 1 Wordpress 1 Wordpress 2026-06-17 N/A 5.5 MEDIUM
WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
CVE-2024-31094 2026-06-17 N/A 8.5 HIGH
Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
CVE-2024-30230 1 Acowebs 1 Pdf Invoices And Packing Slips For Woocommerce 2026-06-17 N/A 8.2 HIGH
Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.
CVE-2024-30229 1 Givewp 1 Givewp 2026-06-17 N/A 8.0 HIGH
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2.
CVE-2024-30228 2026-06-17 N/A 9.9 CRITICAL
Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.
CVE-2024-30227 2026-06-17 N/A 9.0 CRITICAL
Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.
CVE-2024-30226 1 Wpdeveloper 1 Betterdocs 2026-06-17 N/A 9.0 CRITICAL
Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.
CVE-2024-30225 2026-06-17 N/A 10.0 CRITICAL
Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.
CVE-2024-30224 1 Wpxpo 1 Wholesalex 2026-06-17 N/A 10.0 CRITICAL
Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.
CVE-2024-30223 1 Reputeinfosystems 1 Armember 2026-06-17 N/A 9.0 CRITICAL
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.
CVE-2024-30222 1 Reputeinfosystems 1 Armember 2026-06-17 N/A 8.5 HIGH
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.
CVE-2024-30221 1 Sunshinephotocart 1 Sunshine Photo Cart 2026-06-17 N/A 5.4 MEDIUM
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.
CVE-2024-30044 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 7.2 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-30042 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-06-17 N/A 7.8 HIGH
Microsoft Excel Remote Code Execution Vulnerability