Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Connect CRITICAL 9.3
CVE-2026-34615

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Azure Monitor Agent HIGH 7.8
CVE-2026-32192

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.41.0+
Fix from $1,950 2026-04-14
Hpc Pack HIGH 7.8
CVE-2026-32184

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.

Fix: 6.3.8355+
Fix from $1,950 2026-04-14
Connect CRITICAL 9.6
CVE-2026-27303

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Unclassified HIGH 7.2
CVE-2026-3017

The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all ve…

Mitigation only
Fix from $1,950 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-40044

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serializ…

Mitigation only
Fix from $2,300 2026-04-13
Airflow HIGH 8.8
CVE-2026-33858

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…

Fix: 3.2.0+
Fix from $1,950 2026-04-13
Openshift Ai HIGH 7.8
CVE-2026-1462

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin…

Fix: 2.25.7+
Fix from $1,950 2026-04-13
Storm HIGH 8.8
CVE-2026-35337

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credential…

Fix: 2.8.6+
Fix from $1,950 2026-04-13
Escargot HIGH 7.5
CVE-2026-25204

Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. Th…

Fix: 2026-03-28+
Fix from $1,950 2026-04-13
Unclassified CRITICAL 9.4
CVE-2026-3199

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with ta…

Mitigation only
Fix from $2,300 2026-04-08
Praisonai CRITICAL 9.8
CVE-2026-39890

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files wit…

Fix: after 4.5.114
Fix from $2,300 2026-04-08
Unclassified HIGH 7.5
CVE-2026-23869

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turb…

Mitigation only
Fix from $1,950 2026-04-08
Mirror Registry For Red Hat Openshift HIGH 8.8
CVE-2026-32590

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified CRITICAL 9.8
CVE-2026-3296

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untru…

Mitigation only
Fix from $2,300 2026-04-08
Langflow HIGH 8.8
CVE-2026-3357

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure de…

Fix: 1.8.3+
Fix from $1,950 2026-04-08
Openam CRITICAL 9.8
CVE-2026-33439EPSS 10%

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Re…

Fix: 16.0.6+
Fix from $2,300 2026-04-07
Rack Session CRITICAL 9.8
CVE-2026-39324

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu…

Fix: 2.1.2+
Fix from $2,300 2026-04-07
Data Loading Library HIGH 7.3
CVE-2026-24156

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability mi…

Fix: 2.0.0+
Fix from $1,950 2026-04-07
Pyload HIGH 7.5
CVE-2026-35464

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin us…

Fix: 2026-04-02+
Fix from $1,950 2026-04-07
Transformers HIGH 7.8
CVE-2026-1839

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_sta…

Fix: 5.0.0+
Fix from $1,950 2026-04-07
Kedro CRITICAL 9.8
CVE-2026-35171

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN…

Fix: 1.3.0+
Fix from $2,300 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5659

A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/d…

Mitigation only
Fix from $1,600 2026-04-06
Fedml HIGH 7.3
CVE-2026-5536

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC s…

Fix: after 0.8.9
Fix from $1,950 2026-04-05
Core Flight System HIGH 7.0
CVE-2026-5473

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipul…

Fix: after 7.0.0
Fix from $1,950 2026-04-03
Webmail HIGH 7.5
CVE-2026-35537

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbit…

Fix: 1.5.14 / 1.6.14+
Fix from $1,950 2026-04-03
Group Office CRITICAL 9.9
CVE-2026-34838

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability i…

Fix: 6.8.156 / 25.0.90+
Fix from $2,300 2026-04-02
Mbed Tls CRITICAL 9.8
CVE-2026-34877

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session st…

Fix: 3.6.6+
Fix from $2,300 2026-04-02
Openstamanager HIGH 7.2
CVE-2026-29782

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAM…

Fix: 2.10.2+
Fix from $1,950 2026-04-02
Bionemo Framework HIGH 8.8
CVE-2026-24165

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability migh…

Fix: 2026-01-21+
Fix from $1,950 2026-03-31