Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Fickling HIGH 7.8
CVE-2026-22612

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detection bypass due to "builtins" bl…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2026-22606

Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python’s runpy module as unsaf…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2026-22607

Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python's cProfile module as un…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2026-22608

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren't explicitly blocked. Even o…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Unclassified CRITICAL 9.8
CVE-2025-67911

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newslet…

Mitigation only
Fix from $2,300 2026-01-08
Bio Formats HIGH 7.8
CVE-2026-22187

Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during im…

Fix: after 8.3.0
Fix from $1,950 2026-01-07
Unclassified CRITICAL 9.8
CVE-2025-47552

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified HIGH 8.8
CVE-2025-47553

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery…

Mitigation only
Fix from $1,950 2026-01-06
Unclassified HIGH 8.8
CVE-2025-31047

Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Themify Edmin: from n/a through 2…

Mitigation only
Fix from $1,950 2026-01-05
Unclassified MEDIUM 6.3
CVE-2025-15453

A security vulnerability has been detected in milvus up to 2.6.7. This vulnerability affects the function expr.Exec of the file pkg/util/expr/expr.go…

Mitigation only
Fix from $1,600 2026-01-05
Pluxml HIGH 7.2
CVE-2025-15438

A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the co…

Fix: after 5.8.22
Fix from $1,950 2026-01-02
Unclassified HIGH 7.8
CVE-2025-11157

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located…

Patch available
Fix from $1,950 2026-01-01
Fontforge HIGH 7.8
CVE-2025-15276

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Mitigation only
Fix from $1,950 2025-12-31
Eyoucms HIGH 8.8
CVE-2025-15375

A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the…

Fix: 1.7.8+
Fix from $1,950 2025-12-31
Unclassified MEDIUM 6.3
CVE-2025-15246

A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of…

Mitigation only
Fix from $1,600 2025-12-30
Unclassified MEDIUM 5.0
CVE-2025-15222

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerialize…

Mitigation only
Fix from $1,600 2025-12-30
Lmdeploy HIGH 8.8
CVE-2025-67729

LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmde…

Fix: 0.11.1+
Fix from $1,950 2025-12-26
Unclassified HIGH 7.2
CVE-2025-68038

Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects I…

Mitigation only
Fix from $1,950 2025-12-24
Langchain.js CRITICAL 9.1
CVE-2025-68665

LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0…

Fix: 0.3.37 / 0.3.80+
Fix from $2,300 2025-12-23
Langchain Core HIGH 8.2
CVE-2025-68664EPSS 42%

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerabilit…

Fix: 0.3.81 / 1.2.5+
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13713

Tencent Hunyuan3D-1 load_pretrained Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

Patch available
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13714

Tencent MedicalNet generate_model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…

Patch available
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13715

Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…

Patch available
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13716

Tencent MimicMotion create_pipeline Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

Patch available
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13706

Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacker…

Patch available
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13707

Tencent HunyuanDiT model_resume Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to …

Patch available
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13708

Tencent NeuralNLP-NeuralClassifier _load_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows …

Patch available
Fix from $1,950 2025-12-23
Tface HIGH 7.8
CVE-2025-13709

Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to…

Fix: 2025-09-29+
Fix from $1,950 2025-12-23
Unclassified HIGH 7.8
CVE-2025-13710

Tencent HunyuanVideo load_vae Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

Patch available
Fix from $1,950 2025-12-23
Tface HIGH 7.8
CVE-2025-13711

Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Fix: 2025-09-29+
Fix from $1,950 2025-12-23