Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Footprints HIGH 8.8
CVE-2025-71260EPSS 34%

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTA…

Fix: after 20.24.01.001
Fix from $1,950 2026-03-19
Unclassified HIGH 8.8
CVE-2026-25445

Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-60233

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-60237

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

Mitigation only
Fix from $2,300 2026-03-19
Unclassified HIGH 8.1
CVE-2026-27096

Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue af…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified CRITICAL 9.8
CVE-2026-25873

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute ar…

Patch available
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.8
CVE-2026-25449

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through…

Mitigation only
Fix from $2,300 2026-03-18
Wazuh CRITICAL 9.1
CVE-2026-25769EPSS 9%

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execut…

Fix: 4.14.3+
Fix from $2,300 2026-03-17
Mailqueue HIGH 8.8
CVE-2026-1323

The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute un…

Fix: 0.4.5 / 0.5.2+
Fix from $1,950 2026-03-17
Spark HIGH 8.8
CVE-2025-54920EPSS 5%

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.…

Fix: 3.5.7+
Fix from $1,950 2026-03-16
Unclassified HIGH 8.8
CVE-2026-32355

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a thr…

Mitigation only
Fix from $1,950 2026-03-13
Ignition MEDIUM 6.8
CVE-2025-13913

A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious …

Fix: 8.3.0+
Fix from $1,600 2026-03-12
Sglang CRITICAL 9.8
CVE-2026-3059

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat…

Fix: after 0.5.9
Fix from $2,300 2026-03-12
Sglang CRITICAL 9.8
CVE-2026-3060

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri…

Fix: after 0.5.9
Fix from $2,300 2026-03-12
Sglang HIGH 7.8
CVE-2026-3989

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of …

Fix: 0.5.10+
Fix from $1,950 2026-03-12
Unclassified MEDIUM 6.3
CVE-2026-3967

A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file a…

Mitigation only
Fix from $1,600 2026-03-12
Glpi HIGH 8.8
CVE-2026-22248

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. Fr…

Fix: 11.0.5+
Fix from $1,950 2026-03-11
Unclassified HIGH 8.1
CVE-2026-2626

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated us…

Mitigation only
Fix from $1,950 2026-03-11
Sharepoint Server HIGH 8.8
CVE-2026-26114

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-25166

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Ecostruxure Foxboro Dcs Control Software MEDIUM 6.5
CVE-2026-1286

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execu…

Fix: 8.1+
Fix from $1,600 2026-03-10
Limesurvey CRITICAL 9.8
CVE-2025-56422

A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

Fix: after 6.14.3
Fix from $2,300 2026-03-10
Ecostruxure Power Monitoring Expert HIGH 7.8
CVE-2025-11739

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a local…

Mitigation only
Fix from $1,950 2026-03-10
Unclassified CRITICAL 9.1
CVE-2026-27685

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, …

Mitigation only
Fix from $2,300 2026-03-10
Unclassified HIGH 7.5
CVE-2026-2020

The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortco…

Mitigation only
Fix from $1,950 2026-03-07
Langgraph HIGH 7.2
CVE-2026-28277

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.…

Fix: after 1.0.9
Fix from $1,950 2026-03-05
Internet Security HIGH 7.8
CVE-2026-27749

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeO…

Fix: 1.1.114.3113+
Fix from $1,950 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-2599

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-28105

Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a t…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-28074

Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a t…

Mitigation only
Fix from $2,300 2026-03-05