Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Nios HIGH 8.8
CVE-2025-61880

In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.

Fix: after 8.6.5
Fix from $1,950 2026-02-12
Unclassified CRITICAL 9.3
CVE-2026-26215

manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticate…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-69872

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified HIGH 8.8
CVE-2026-0910

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untru…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified MEDIUM 6.5
CVE-2026-1235

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Obj…

Mitigation only
Fix from $1,600 2026-02-11
Azure Conversation Authoring Client Library CRITICAL 9.8
CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-02-10
365 Apps HIGH 7.5
CVE-2026-21511

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.19127.20518+
Fix from $1,950 2026-02-10
My Little Forum CRITICAL 9.1
CVE-2026-25923

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application f…

Fix: 20260208.1+
Fix from $2,300 2026-02-09
Powerdocu HIGH 7.8
CVE-2026-25925

PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability…

Fix: 2.4.0+
Fix from $1,950 2026-02-09
Tpadmin CRITICAL 9.8
CVE-2026-2113

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/web…

Fix: after 1.3.12
Fix from $2,300 2026-02-07
Epyt Flow CRITICAL 10.0
CVE-2026-25632

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to …

Fix: 0.16.1+
Fix from $2,300 2026-02-06
Unclassified CRITICAL 9.8
CVE-2020-37071

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a …

Mitigation only
Fix from $2,300 2026-02-03
Blesta HIGH 7.2
CVE-2026-25615

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.

Fix: 5.13.3+
Fix from $1,950 2026-02-03
Blesta HIGH 7.5
CVE-2026-25614

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.

Fix: 5.13.2+
Fix from $1,950 2026-02-03
Unclassified MEDIUM 6.5
CVE-2025-70559

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to dese…

Mitigation only
Fix from $1,600 2026-02-03
Boltz HIGH 8.4
CVE-2025-70560

Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deseriali…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified HIGH 8.8
CVE-2026-24954

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro…

Mitigation only
Fix from $1,950 2026-02-03
Bolo Solo HIGH 8.8
CVE-2026-1691

A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/…

Fix: after 2.6.4
Fix from $1,950 2026-01-30
Jsonpath CRITICAL 9.8
CVE-2025-61140

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Mitigation only
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40551 KEVEPSS 84%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40553EPSS 60%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Pytorch HIGH 8.8
CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows a…

Fix: 2.10.0+
Fix from $1,950 2026-01-27
Debian Linux HIGH 7.8
CVE-2026-24765

PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involvi…

Fix: 8.5.52 / 9.6.33+
Fix from $1,950 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24815

Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangt…

Patch available
Fix from $2,300 2026-01-27
React HIGH 7.5
CVE-2026-23864

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-…

Fix: 19.0.4 / 19.1.5+
Fix from $1,950 2026-01-26
Langflow HIGH 7.5
CVE-2026-0772

Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0773

Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-01-23
Gpt Academic CRITICAL 9.8
CVE-2026-0763

GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a…

Mitigation only
Fix from $2,300 2026-01-23
Gpt Academic CRITICAL 9.8
CVE-2026-0764

GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-01-23
Metagpt CRITICAL 9.8
CVE-2026-0760

Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote…

Mitigation only
Fix from $2,300 2026-01-23