Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Bionemo Framework CRITICAL 9.8
CVE-2026-24164

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability migh…

Fix: 2026-01-21+
Fix from $2,300 2026-03-31
Zebra HIGH 7.5
CVE-2026-34202

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction p…

Fix: 4.3.0 / 6.0.1+
Fix from $1,950 2026-03-31
Fireware MEDIUM 6.7
CVE-2026-4266

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through…

Fix: 12.12 / 2026.2+
Fix from $1,600 2026-03-30
Performance Library HIGH 7.8
CVE-2026-4416

The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a …

Fix: 25.12.31.01+
Fix from $1,950 2026-03-30
Grid\ CRITICAL 9.8
CVE-2026-4851

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Ca…

Fix: after 0.127
Fix from $2,300 2026-03-29
Dd Trace Java CRITICAL 9.8
CVE-2026-33728

dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a cus…

Fix: 1.60.3+
Fix from $2,300 2026-03-27
Opentelemetry Instrumentation For Java CRITICAL 9.8
CVE-2026-33701

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, t…

Fix: 2.26.1+
Fix from $2,300 2026-03-27
Metabase HIGH 7.2
CVE-2026-33725

Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.5…

Fix: 1.54.22 / 1.55.22+
Fix from $1,950 2026-03-27
Unclassified HIGH 7.3
CVE-2026-4860

A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file sr…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified HIGH 7.2
CVE-2026-3328

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form p…

Mitigation only
Fix from $1,950 2026-03-26
Saloon CRITICAL 9.8
CVE-2026-33942

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAut…

Fix: 4.0.0+
Fix from $2,300 2026-03-26
Unclassified MEDIUM 5.4
CVE-2026-32508

Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a thro…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 5.4
CVE-2026-32509

Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 5.4
CVE-2026-32510

Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a throug…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 5.4
CVE-2026-32511

Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7.

Mitigation only
Fix from $1,600 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-32512

Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue …

Mitigation only
Fix from $2,300 2026-03-25
Unclassified HIGH 8.8
CVE-2026-32513

Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affect…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-32502

Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects …

Mitigation only
Fix from $2,300 2026-03-25
Unclassified MEDIUM 5.4
CVE-2026-32506

Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a throug…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified MEDIUM 5.4
CVE-2026-32507

Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < …

Mitigation only
Fix from $1,600 2026-03-25
Unclassified HIGH 8.8
CVE-2026-32484

Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-27084

Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-27095

Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation a…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-27082

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a thro…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-27083

Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified HIGH 8.8
CVE-2026-27045

Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This i…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-25429

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a th…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified HIGH 8.8
CVE-2026-25400

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <=…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 8.8
CVE-2026-25359

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < …

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 8.8
CVE-2026-25360

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.

Mitigation only
Fix from $1,950 2026-03-25