Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Rebar3 HIGH 7.5
CVE-2026-21619

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api module…

Fix: 0.12.1 / 2.3.2+
Fix from $1,950 2026-02-27
Accel Platform HIGH 8.8
CVE-2026-27776

IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is dep…

Mitigation only
Fix from $1,950 2026-02-27
Unclassified HIGH 8.4
CVE-2026-3071

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when l…

Mitigation only
Fix from $1,950 2026-02-26
Unclassified HIGH 7.2
CVE-2026-28138

Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <…

Mitigation only
Fix from $1,950 2026-02-26
Unclassified HIGH 8.0
CVE-2026-27830

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instanc…

Patch available
Fix from $1,950 2026-02-26
Unclassified MEDIUM 6.6
CVE-2026-27794

LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in …

Patch available
Fix from $1,600 2026-02-25
Mchange Commons Java CRITICAL 9.8
CVE-2026-27727

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including suppo…

Fix: 0.4.0+
Fix from $2,300 2026-02-25
Altec Doclink CRITICAL 9.8
CVE-2026-26222

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCH…

Mitigation only
Fix from $2,300 2026-02-24
Unclassified HIGH 7.7
CVE-2026-21665

The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) in unsupported version 2021.2.4 (build 4.7.3155.0011) …

Mitigation only
Fix from $1,950 2026-02-23
Camel HIGH 8.8
CVE-2026-25747

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes dat…

Fix: 4.10.9 / 4.14.5+
Fix from $1,950 2026-02-23
Datapizza Ai HIGH 7.5
CVE-2026-2970

A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-…

No fix yet
Fix from $1,950 2026-02-23
Funadmin MEDIUM 6.5
CVE-2026-2898

A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.p…

Fix: 7.1.0+
Fix from $1,600 2026-02-22
Unclassified HIGH 8.1
CVE-2026-27206

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP …

Patch available
Fix from $1,950 2026-02-21
Archiver HIGH 8.8
CVE-2026-2036

GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …

Mitigation only
Fix from $1,950 2026-02-20
Archiver HIGH 8.8
CVE-2026-2037

GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2026-02-20
Openitcockpit HIGH 8.8
CVE-2026-24892

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Ed…

Fix: 5.4.0+
Fix from $1,950 2026-02-20
Openitcockpit HIGH 7.5
CVE-2026-24891

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below c…

Fix: 5.4.0+
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.8
CVE-2026-22384

Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay …

Mitigation only
Fix from $2,300 2026-02-20
Unclassified HIGH 8.8
CVE-2026-22354

Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object In…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.8
CVE-2026-22345

Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-ga…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.8
CVE-2026-22346

Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow slider-responsive-slidesho…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69404

Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69405

Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.T…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69382

Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Th…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69370

Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <=…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69371

Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69372

Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified HIGH 8.8
CVE-2025-69328

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69329

Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < …

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69301

Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <=…

Mitigation only
Fix from $2,300 2026-02-20