Due to the insecure BinaryFormatter deserialization vulnerability in Sitecore XM/XP, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.
Successful attacks of this vulnerability can result in takeover of Sitecore.
Upgrade to the latest version of Sitecore

You can search and find all vulnerabilities
