Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Gpt Academic HIGH 8.1
CVE-2026-0762

GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

Mitigation only
Fix from $1,950 2026-01-23
Shockline HIGH 7.8
CVE-2025-15348

Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers …

Mitigation only
Fix from $1,950 2026-01-23
Vectorstar HIGH 7.8
CVE-2025-15350

Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

Mitigation only
Fix from $1,950 2026-01-23
Vectorstar HIGH 7.8
CVE-2025-15351

Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified CRITICAL 9.8
CVE-2025-69079

Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue af…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified HIGH 8.8
CVE-2025-69099

Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects North: from n/a through <= 5.…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-69035

Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental …

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-69036

Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life C…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-69002

Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through …

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-68903

Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0.

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-68899

Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= …

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-68047

Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a t…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-67619

Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified CRITICAL 9.8
CVE-2025-67617

Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a t…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified HIGH 8.8
CVE-2025-50004

Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from…

Mitigation only
Fix from $1,950 2026-01-22
Docling Core CRITICAL 9.8
CVE-2026-24009

Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML…

Fix: 2.48.4+
Fix from $2,300 2026-01-22
Tendenci MEDIUM 6.8
CVE-2026-23946

Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a …

Fix: 15.3.12+
Fix from $1,600 2026-01-22
Seroval HIGH 7.5
CVE-2026-23737

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper …

Fix: 1.4.1+
Fix from $1,950 2026-01-21
Reverb CRITICAL 9.8
CVE-2026-23524

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from th…

Fix: 1.7.0+
Fix from $2,300 2026-01-21
Ply CRITICAL 9.8
CVE-2025-56005EPSS 17%

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the…

No fix yet
Fix from $2,300 2026-01-20
Unclassified HIGH 8.1
CVE-2026-0726

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4…

Mitigation only
Fix from $1,950 2026-01-20
Unclassified MEDIUM 5.2
CVE-2026-0895

The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org…

Patch available
Fix from $1,600 2026-01-20
T\+ CRITICAL 9.8
CVE-2023-7334

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code exe…

Fix: after 16.000.000.0283
Fix from $2,300 2026-01-15
Unclassified CRITICAL 9.3
CVE-2026-23746

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 …

Mitigation only
Fix from $2,300 2026-01-15
Azure Core Shared Client Library HIGH 7.5
CVE-2026-21226

Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

Fix: 1.38.0+
Fix from $1,950 2026-01-13
Sharepoint Server CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19127.20442+
Fix from $2,300 2026-01-13
TYPO3 HIGH 7.8
CVE-2026-0859

TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized du…

Fix: 10.4.55 / 11.5.49+
Fix from $1,950 2026-01-13
Llamaindex HIGH 7.8
CVE-2024-14021

LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk()…

Fix: after 0.11.6
Fix from $1,950 2026-01-12
Dx Netops Spectrum HIGH 8.8
CVE-2025-69276

Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps…

Fix: 25.4.1+
Fix from $1,950 2026-01-12
Fickling HIGH 7.8
CVE-2026-22609

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fickling's static analyzer fails…

Fix: 0.1.7+
Fix from $1,950 2026-01-10