Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.1
CVE-2026-39539

Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39545

Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39443

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39446

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-39529

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-27429

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified MEDIUM 6.5
CVE-2026-27410

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

Mitigation only
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.6
CVE-2026-12115

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions u…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 8.8
CVE-2026-12256

Contributor PHP Object Injection in Avada <= 3.15.3 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.4
CVE-2026-11857

Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-69122

Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-69108

Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-60205

Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Weblogic Server CRITICAL 9.8
CVE-2026-35300

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.…

Mitigation only
Fix from $2,300 2026-06-17
Langgraph Checkpoint MEDIUM 6.8
CVE-2026-48775

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4…

Fix: 4.1.1+
Fix from $1,600 2026-06-16
Unclassified HIGH 8.6
CVE-2026-10748

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system comman…

Mitigation only
Fix from $1,950 2026-06-16
Nemo HIGH 7.8
CVE-2026-24228

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this …

Fix: 2.7.3+
Fix from $1,950 2026-06-16
Unclassified CRITICAL 9.2
CVE-2026-48853

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated …

Patch available
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-9691

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49770

Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49781

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49763

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49765

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49768

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49769

Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49085

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49104

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 ve…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49105

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49106

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-49109

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.

Mitigation only
Fix from $2,300 2026-06-15