CVE-2021-23758

HIGH8.1Published on December 3, 2021

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Early warning: exploitation observed

  • Exploitation observed since Aug 20, 2026
  • Not yet in the official CISA catalogue
  • First attack observed 1720 days after disclosure

Source: VulnCheck KEV · Aug 20, 2026

CVSS score8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-502
Vendorsajaxpro.2 project

Affected products

VendorsProdottoVersioni
ajaxpro.2 projectajaxpro.2< 21.10.30.1

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database