Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.1
CVE-2026-42687

Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 8.8
CVE-2026-39532

Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.2
CVE-2026-39498

Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.2
CVE-2026-39499

Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 8.8
CVE-2026-39474

Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 8.8
CVE-2026-39478

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.2
CVE-2026-39481

Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.2
CVE-2026-39471

Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.2
CVE-2026-39472

Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.2
CVE-2026-39434

Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-27053

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 8.1
CVE-2026-27333

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-39006

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 7.5
CVE-2026-11860

Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper …

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.8
CVE-2026-12191

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py…

Mitigation only
Fix from $1,950 2026-06-14
Cxf HIGH 8.1
CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf HIGH 8.1
CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Spring For Graphql CRITICAL 9.8
CVE-2026-41699

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious…

Fix: 1.3.9 / 1.4.5.1+
Fix from $2,300 2026-06-11
Splunk HIGH 8.8
CVE-2026-20251EPSS 19%

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22…

Fix: 3.8.67 / 3.9.20+
Fix from $1,950 2026-06-10
Jenkins HIGH 8.8
CVE-2026-53435EPSS 19%

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins co…

Fix: 2.555.3 / 2.568+
Fix from $1,950 2026-06-10
Ghidra HIGH 8.8
CVE-2026-52751

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated rem…

Fix: 12.1+
Fix from $1,950 2026-06-10
Unclassified HIGH 8.4
CVE-2026-10721

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauth…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified MEDIUM 5.3
CVE-2026-11815

An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary…

Mitigation only
Fix from $1,600 2026-06-10
Spring For Apache Kafka HIGH 8.1
CVE-2026-41731

JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that tr…

Fix: 2.8.12 / 2.9.14+
Fix from $1,950 2026-06-10
Spring For Apache Pulsar HIGH 8.1
CVE-2026-41732

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all o…

Fix: 1.1.18 / 1.2.17.1+
Fix from $1,950 2026-06-10
Spring Security HIGH 7.2
CVE-2026-40993

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able…

Fix: 7.0.5.1+
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.4
CVE-2026-44963

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Mitigation only
Fix from $2,300 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-48560

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server HIGH 8.8
CVE-2026-45484EPSS 35%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20384+
Fix from $1,950 2026-06-09
Nuance Powerscribe 360 CRITICAL 9.8
CVE-2026-26142

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-06-09