Tag
Graphite graph database engine Insecure Deserialization Vulnerability
1 rule 1 TTPGraphite versions before 0.2 are vulnerable to insecure deserialization due to the use of Python's `pickle` module for database storage, allowing attackers to craft malicious database files that execute arbitrary code when loaded.
Perfex CRM Unauthenticated Remote Code Execution via Insecure Deserialization
2 rules 1 TTP 2 IOCsPerfex CRM is vulnerable to unauthenticated remote code execution (RCE) due to an autologin cookie being fed into unserialize().
Grav File Cache Insecure Deserialization Vulnerability
2 rules 2 TTPsGrav versions 1.7.44 through 1.7.49.5 are vulnerable to insecure deserialization in the File Cache component, where the `unserialize` function with `allowed_classes => true` can lead to arbitrary code execution if an attacker tampers with cache files.
MONAI Library Vulnerable to Arbitrary Code Execution via Pickle Deserialization
2 rules 1 TTPThe MONAI library is vulnerable to arbitrary code execution due to insecure deserialization of pickle files via the `algo_from_pickle` function, allowing attackers to execute arbitrary code by providing a malicious pickle file.
Gigabyte Control Center Insecure Deserialization Privilege Escalation (CVE-2026-4416)
2 rules 1 TTPA local, authenticated attacker can exploit an insecure deserialization vulnerability in the Gigabyte Control Center's Performance Library component by sending a malicious serialized payload to the EasyTune Engine service, leading to privilege escalation.