Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified MEDIUM 6.3
CVE-2026-49740

TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class r…

Patch available
Fix from $1,600 2026-06-09
Unclassified HIGH 8.8
CVE-2026-8365

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the …

Mitigation only
Fix from $1,950 2026-06-09
Spring Framework CRITICAL 9.8
CVE-2026-41855

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.conver…

Fix: 5.3.49 / 6.1.28+
Fix from $2,300 2026-06-09
Unclassified MEDIUM 6.6
CVE-2026-7566

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via d…

Mitigation only
Fix from $1,600 2026-06-06
Unclassified HIGH 8.8
CVE-2026-7654

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18.…

Mitigation only
Fix from $1,950 2026-06-05
Ironic HIGH 7.5
CVE-2026-50589

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…

Fix: 37.0.0+
Fix from $1,950 2026-06-05
Unclassified CRITICAL 9.8
CVE-2026-25550

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed o…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified HIGH 7.8
CVE-2026-25551

Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escala…

Mitigation only
Fix from $1,950 2026-06-04
Fory CRITICAL 9.1
CVE-2026-50076

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo…

Fix: 1.1.0+
Fix from $2,300 2026-06-04
Unclassified HIGH 8.4
CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack…

Mitigation only
Fix from $1,950 2026-06-03
Mina CRITICAL 9.8
CVE-2026-47065

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri…

Mitigation only
Fix from $2,300 2026-06-03
React Router HIGH 8.1
CVE-2026-42211

React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unaut…

Fix: 7.14.2+
Fix from $1,950 2026-06-02
Aiohttp HIGH 7.3
CVE-2026-34993

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted in…

Fix: 3.14.0+
Fix from $1,950 2026-06-02
Nvtabular HIGH 7.8
CVE-2026-24221

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vuln…

Fix: 2026-03-12+
Fix from $1,950 2026-06-02
Nvtabular HIGH 7.8
CVE-2026-24237

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vuln…

Fix: 2026-03-12+
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2026-39555

Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2026-39550

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2026-39551

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 5.3
CVE-2026-10566

A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/…

Mitigation only
Fix from $1,600 2026-06-02
Websphere Application Server CRITICAL 9.0
CVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server HIGH 8.5
CVE-2026-9330

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web S…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-01
Aiter CRITICAL 9.8
CVE-2026-49121

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function …

Fix: after 0.1.14
Fix from $2,300 2026-06-01
Unclassified HIGH 7.8
CVE-2026-38950

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load …

Patch available
Fix from $1,950 2026-06-01
Unclassified CRITICAL 9.8
CVE-2026-7858

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Colla…

Mitigation only
Fix from $2,300 2026-06-01
Airflow HIGH 7.3
CVE-2026-45360

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary clas…

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Airflow HIGH 8.8
CVE-2026-42359

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a …

Fix: 3.2.2+
Fix from $1,950 2026-06-01
Unclassified CRITICAL 9.8
CVE-2026-10042

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle…

Patch available
Fix from $2,300 2026-05-29
Unclassified HIGH 8.8
CVE-2025-11993

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Mitigation only
Fix from $1,950 2026-05-29
Unclassified HIGH 7.3
CVE-2026-37579

An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.7
CVE-2026-47161

RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accep…

Patch available
Fix from $1,950 2026-05-27