Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 7.1
CVE-2026-45134

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith S…

Mitigation only
Fix from $1,950 2026-05-27
Ldap MEDIUM 6.6
CVE-2026-48917

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

Fix: after 793.v754d6b_41b_ea_4
Fix from $1,600 2026-05-27
Active Directory MEDIUM 6.6
CVE-2026-48919

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

Fix: after 2.41
Fix from $1,600 2026-05-27
Langchain HIGH 8.2
CVE-2026-44843

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths tha…

Fix: 0.3.85 / 1.3.3+
Fix from $1,950 2026-05-26
Transformers4rec HIGH 7.8
CVE-2026-24162

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exp…

Fix: 2026-03-11+
Fix from $1,950 2026-05-26
Full Page Cache Warmer CRITICAL 9.8
CVE-2026-45247 KEVEPSS 28%

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attack…

Fix: 1.11.12+
Fix from $2,300 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9497

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson Aut…

Mitigation only
Fix from $1,600 2026-05-25
Transformers HIGH 7.8
CVE-2026-4372

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerabili…

Fix: 5.3.0+
Fix from $1,950 2026-05-24
Sharepoint Server HIGH 8.8
CVE-2026-45659 KEVEPSS 10%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-22
Planetary Computer HIGH 7.5
CVE-2026-41104

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-05-22
Unclassified HIGH 7.1
CVE-2026-9291

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 …

Mitigation only
Fix from $1,950 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destinatio…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Concrete Cms HIGH 7.2
CVE-2026-8135

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controll…

Fix: after 9.5.0
Fix from $1,950 2026-05-21
Fory CRITICAL 9.8
CVE-2026-48207

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…

Fix: 1.0.0+
Fix from $2,300 2026-05-21
Bionemo Framework HIGH 7.8
CVE-2026-24216

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerab…

Fix: 2026-04-03+
Fix from $1,950 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-7637

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input i…

Mitigation only
Fix from $2,300 2026-05-20
Tensorrt Llm CRITICAL 9.8
CVE-2026-24163

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful explo…

Fix: 1.2+
Fix from $2,300 2026-05-20
Tensorrt Llm CRITICAL 9.8
CVE-2026-24142

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability m…

Fix: 1.2+
Fix from $2,300 2026-05-20
Tensorrt Llm CRITICAL 9.8
CVE-2025-33255

NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit…

Fix: 1.2+
Fix from $2,300 2026-05-20
Unclassified HIGH 8.7
CVE-2026-6009

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the aff…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified CRITICAL 9.8
CVE-2026-31072

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via In…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified HIGH 7.3
CVE-2025-51427

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mi…

Patch available
Fix from $1,950 2026-05-19
Unclassified CRITICAL 10.0
CVE-2026-43633

HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch betwe…

Patch available
Fix from $2,300 2026-05-19
Unclassified CRITICAL 9.2
CVE-2026-46725

The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated att…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified HIGH 7.1
CVE-2026-8727

The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawle…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 7.6
CVE-2026-33233

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 8.6
CVE-2026-26978

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, …

Patch available
Fix from $1,950 2026-05-18
Unclassified CRITICAL 10.0
CVE-2026-45829EPSS 12%

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run…

Mitigation only
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.8
CVE-2026-7301

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming…

Mitigation only
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.8
CVE-2026-7304

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl…

Mitigation only
Fix from $2,300 2026-05-18