Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.8
CVE-2026-74012

Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73397

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73380

Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73376

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73366

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73341

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 7.2
CVE-2026-66620

Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-32465

Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.0
CVE-2026-16138

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with wr…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2024-13784

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 6.6
CVE-2026-10035

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deseria…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 8.8
CVE-2026-16099

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_li…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.1
CVE-2025-7639

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, p…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19826

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/Hes…

No fix yet
Fix from $4,900 2026-08-14
Websphere Application Server MEDIUM 5.3
CVE-2026-10571

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-pri…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.2
CVE-2026-66256

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-28176

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-28149

Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.2
CVE-2026-27380

Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.

No fix yet
Fix from $4,900 2026-08-13
Ash Framework HIGH 7.4
CVE-2026-67579

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.8
CVE-2026-73325

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by s…

No fix yet
Fix from $4,900 2026-08-12
Airflow HIGH 8.8
CVE-2026-67587

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store…

No fix yet
Fix from $4,900 2026-08-12
Airflow HIGH 7.3
CVE-2026-67260

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria…

No fix yet
Fix from $4,900 2026-08-12
Airflow MEDIUM 5.4
CVE-2026-59242

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow HIGH 8.8
CVE-2026-58076

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in…

Fix: 3.3.1+
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.6
CVE-2026-68756

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.4
CVE-2026-18634

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v…

No fix yet
Fix from $4,900 2026-08-11
Lightroom HIGH 8.6
CVE-2026-48397

Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of th…

Fix: 15.5+
Fix from $4,900 2026-08-11