Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
H2o CRITICAL 9.8
CVE-2026-8751

A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Mod…

Fix: after 7402
Fix from $2,300 2026-05-17
Unclassified MEDIUM 6.3
CVE-2026-8735

A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the …

Mitigation only
Fix from $1,600 2026-05-17
Unclassified CRITICAL 9.8
CVE-2021-47952

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing ma…

Mitigation only
Fix from $2,300 2026-05-16
Www\ MEDIUM 5.3
CVE-2026-8612

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response f…

Fix: 2.00+
Fix from $1,600 2026-05-15
Datahub HIGH 7.1
CVE-2026-44501

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java ob…

Fix: 1.5.0.3+
Fix from $1,950 2026-05-14
GitLab HIGH 7.5
CVE-2026-1184

GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could…

Fix: 18.9.7 / 18.10.6+
Fix from $1,950 2026-05-14
Big Ip Access Policy Manager HIGH 8.8
CVE-2026-41957

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Softw…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Unclassified HIGH 8.1
CVE-2026-7635

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0…

Patch available
Fix from $1,950 2026-05-13
Connect Desktop Application CRITICAL 9.6
CVE-2026-34659

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit…

Fix: after 2025.8.157
Fix from $2,300 2026-05-12
Sharepoint Server HIGH 8.0
CVE-2026-40368

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-12
Sharepoint Server HIGH 8.8
CVE-2026-35439

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-12
Sharepoint Server HIGH 8.8
CVE-2026-40357

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-12
Sharepoint Server HIGH 8.8
CVE-2026-33110

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-12
Sharepoint Server HIGH 8.8
CVE-2026-33112

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31237

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset fil…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31238

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server wit…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31239

The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hu…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31229

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model l…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 8.8
CVE-2026-31232

The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) …

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31234

Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for d…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31235

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The…

Mitigation only
Fix from $2,300 2026-05-12
Pytorch Lightning HIGH 7.8
CVE-2026-31221

PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The Lig…

Fix: after 2.6.0
Fix from $1,950 2026-05-12
Snorkel HIGH 8.8
CVE-2026-31222

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The …

Fix: after 0.10.0
Fix from $1,950 2026-05-12
Snorkel HIGH 8.8
CVE-2026-31223

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLab…

Fix: after 0.10.0
Fix from $1,950 2026-05-12
Snorkel HIGH 8.8
CVE-2026-31224

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the Multita…

Fix: after 0.10.0
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31214

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insec…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 8.8
CVE-2026-31218

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2026-31219

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 5.1
CVE-2026-3048

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be ab…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 7.3
CVE-2026-31253

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnera…

Mitigation only
Fix from $1,950 2026-05-11