Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Labone Q HIGH 7.8
CVE-2026-7584

The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserial…

Fix: 26.1.2+
Fix from $1,950 2026-05-01
Matrix Authorization Strategy MEDIUM 6.5
CVE-2026-42521

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in con…

Fix: 3.2.10+
Fix from $1,600 2026-04-29
Unclassified MEDIUM 5.0
CVE-2026-7317

A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system…

Patch available
Fix from $1,600 2026-04-28
Nvflare HIGH 8.8
CVE-2026-24186

NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encode…

Fix: 2.7.2+
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.3
CVE-2025-60887

An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/h…

Mitigation only
Fix from $1,600 2026-04-28
Hpx CRITICAL 9.8
CVE-2025-60889

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or othe…

Fix: after 1.11.0
Fix from $2,300 2026-04-28
Camel HIGH 8.8
CVE-2026-27172

The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserializ…

Fix: 4.14.6 / 4.18.1+
Fix from $1,950 2026-04-27
Camel HIGH 8.8
CVE-2026-40858

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.…

Fix: 4.14.7 / 4.18.2+
Fix from $1,950 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41409

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.4
CVE-2026-33454

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt…

Fix: 4.14.6 / 4.18.1+
Fix from $2,300 2026-04-27
Camel HIGH 7.8
CVE-2026-40048

The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.Objec…

Fix: 4.18.2+
Fix from $1,950 2026-04-27
Camel HIGH 8.8
CVE-2026-40473

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any…

Fix: 4.14.6 / 4.18.2+
Fix from $1,950 2026-04-27
Camel CRITICAL 9.8
CVE-2026-40860

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa…

Fix: 4.14.7 / 4.18.2+
Fix from $2,300 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41635

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Dolphinscheduler MEDIUM 6.3
CVE-2025-62233

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.…

Fix: 3.3.1+
Fix from $1,600 2026-04-24
Unclassified HIGH 8.1
CVE-2026-41316

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `E…

Mitigation only
Fix from $1,950 2026-04-24
Bing CRITICAL 9.8
CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-04-23
Ktransformers CRITICAL 9.8
CVE-2026-26210

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a…

Fix: after 0.5.3
Fix from $2,300 2026-04-23
Lerobot CRITICAL 9.8
CVE-2026-25874EPSS 16%

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize da…

Fix: after 0.5.1
Fix from $2,300 2026-04-23
Pipecat CRITICAL 9.8
CVE-2025-62373

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a v…

Fix: 0.0.94+
Fix from $2,300 2026-04-23
Unclassified HIGH 7.5
CVE-2026-6857

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote a…

Mitigation only
Fix from $1,950 2026-04-22
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2026-6023

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto…

Fix: 2026.1.421+
Fix from $2,300 2026-04-22
Jre HIGH 7.5
CVE-2026-22016

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supporte…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified HIGH 7.2
CVE-2026-39467

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive S…

Mitigation only
Fix from $1,950 2026-04-21
Magento HIGH 8.1
CVE-2026-25524

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Fix: 20.17.0+
Fix from $1,950 2026-04-20
Airflow HIGH 7.2
CVE-2026-25917

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Firebird HIGH 7.5
CVE-2026-33337

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, th…

Fix: 3.0.14 / 4.0.7+
Fix from $1,950 2026-04-17
Dataease HIGH 8.8
CVE-2026-40901

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in com…

Fix: 2.10.21+
Fix from $1,950 2026-04-16
Unclassified CRITICAL 9.1
CVE-2026-5426

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent…

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.3
CVE-2025-15610

The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed…

Mitigation only
Fix from $2,300 2026-04-15