Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2026-31235

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The…

Mitigation only
Fix from $2,300 2026-05-12
Pytorch Lightning HIGH 7.8
CVE-2026-31221

PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The Lig…

Fix: after 2.6.0
Fix from $1,950 2026-05-12
Snorkel HIGH 8.8
CVE-2026-31222

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The …

Fix: after 0.10.0
Fix from $1,950 2026-05-12
Snorkel HIGH 8.8
CVE-2026-31223

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLab…

Fix: after 0.10.0
Fix from $1,950 2026-05-12
Snorkel HIGH 8.8
CVE-2026-31224

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the Multita…

Fix: after 0.10.0
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31214

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insec…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 8.8
CVE-2026-31218

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2026-31219

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 5.1
CVE-2026-3048

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be ab…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 7.3
CVE-2026-31253

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnera…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2026-31249

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2026-31250

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its avera…

Mitigation only
Fix from $1,950 2026-05-11
Pgadmin 4 HIGH 7.8
CVE-2026-7818

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-f…

Fix: 9.15+
Fix from $1,950 2026-05-11
Ray HIGH 8.8
CVE-2026-41486

Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ra…

Patch available
Fix from $1,950 2026-05-08
Unclassified CRITICAL 9.2
CVE-2026-44126

SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow u…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified HIGH 8.8
CVE-2026-5127

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deseria…

Mitigation only
Fix from $1,950 2026-05-08
Pfsense CRITICAL 9.1
CVE-2025-69690

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo…

No fix yet
Fix from $2,300 2026-05-08
Unclassified HIGH 7.3
CVE-2024-53326

LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.

Mitigation only
Fix from $1,950 2026-05-08
Unclassified CRITICAL 9.3
CVE-2026-41586

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to…

Mitigation only
Fix from $2,300 2026-05-07
Phpspreadsheet CRITICAL 9.8
CVE-2026-34084

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3…

Fix: 1.30.3 / 2.1.15+
Fix from $2,300 2026-05-05
Opennlp CRITICAL 9.8
CVE-2026-42027

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7712

A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipul…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 8.1
CVE-2026-7647

The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7597

A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Per…

Patch available
Fix from $1,600 2026-05-01
Unclassified HIGH 8.1
CVE-2026-42471

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize() on data rece…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-42472

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the …

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-42473

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesyste…

Mitigation only
Fix from $2,300 2026-05-01
Mix Php HIGH 8.4
CVE-2026-37552

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket,…

Fix: after 2.2.17
Fix from $1,950 2026-05-01
Mina CRITICAL 9.8
CVE-2026-42778

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Mina CRITICAL 9.8
CVE-2026-42779

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01