Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified HIGH 8.8
CVE-2025-69294

Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a thro…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.8
CVE-2025-68853

Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: …

Mitigation only
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-68541

Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified HIGH 8.8
CVE-2025-68526

Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup B…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.8
CVE-2025-68531

Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Obje…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-67997

Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-67995

Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a throu…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-67996

Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2…

Mitigation only
Fix from $2,300 2026-02-20
Spip HIGH 8.1
CVE-2026-27475

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized d…

Fix: 4.4.9+
Fix from $1,950 2026-02-19
Unclassified HIGH 7.2
CVE-2026-25316

Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-23542

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Resta…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified HIGH 8.8
CVE-2026-23544

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-23549

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified HIGH 7.2
CVE-2026-22333

Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affe…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.5
CVE-2025-15579

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote cod…

Mitigation only
Fix from $2,300 2026-02-18
Unclassified HIGH 8.8
CVE-2026-1426

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deseri…

Mitigation only
Fix from $1,950 2026-02-18
Nemo HIGH 7.8
CVE-2025-33252

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might …

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Nemo HIGH 7.3
CVE-2025-33253

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted…

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Rexroth Indraworks HIGH 8.8
CVE-2025-60035

A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected.…

Fix: 15v24+
Fix from $1,950 2026-02-18
Rexroth Indraworks HIGH 8.8
CVE-2025-60036

A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. …

Fix: 2.9.0 / 15v24+
Fix from $1,950 2026-02-18
Rexroth Indraworks HIGH 8.8
CVE-2025-60037

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a m…

Fix: after 15v24
Fix from $1,950 2026-02-18
Rexroth Indraworks HIGH 8.8
CVE-2025-60038

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a m…

Fix: after 15v24
Fix from $1,950 2026-02-18
Nemo HIGH 7.8
CVE-2025-33243

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit …

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Nemo HIGH 8.8
CVE-2025-33245

NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability mig…

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Nemo HIGH 7.8
CVE-2025-33241

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successfu…

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Unclassified CRITICAL 9.3
CVE-2026-26220

LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD ma…

Mitigation only
Fix from $2,300 2026-02-17
Jeecg Boot HIGH 7.5
CVE-2026-2555

A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/…

No fix yet
Fix from $1,950 2026-02-16
Verasmart CRITICAL 9.8
CVE-2026-26333

Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default Objec…

Fix: 2022.0+
Fix from $2,300 2026-02-13
Unclassified HIGH 7.8
CVE-2026-26208

ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Cod…

Patch available
Fix from $1,950 2026-02-13
Unclassified CRITICAL 9.8
CVE-2026-26221

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attack…

Mitigation only
Fix from $2,300 2026-02-13