Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2025-54723

Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a thro…

Mitigation only
Fix from $2,300 2025-12-18
Isaac Lab CRITICAL 9.0
CVE-2025-33210

NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution.

Fix: 2.3.0+
Fix from $2,300 2025-12-16
Nemo HIGH 7.8
CVE-2025-33212

NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a…

Fix: 2.5.3+
Fix from $1,950 2025-12-16
Nemo HIGH 7.8
CVE-2025-33226

NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful…

Fix: 2.5.3+
Fix from $1,950 2025-12-16
Fickling HIGH 7.8
CVE-2025-67747

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` from the block list of unsafe…

Fix: 0.1.6+
Fix from $1,950 2025-12-16
Fickling HIGH 7.8
CVE-2025-67748

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of uns…

Fix: 0.1.6+
Fix from $1,950 2025-12-16
Unclassified HIGH 8.8
CVE-2025-9121

Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted…

Mitigation only
Fix from $1,950 2025-12-15
Torch Musa CRITICAL 9.8
CVE-2025-65213

MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_singl…

Mitigation only
Fix from $2,300 2025-12-15
Unclassified MEDIUM 5.0
CVE-2025-14606

A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the function pickle.loads of the file …

Mitigation only
Fix from $1,600 2025-12-13
Unclassified HIGH 8.8
CVE-2025-14476

The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1…

Mitigation only
Fix from $1,950 2025-12-13
Hugegraph HIGH 8.8
CVE-2025-26866

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en…

Fix: 1.7.0+
Fix from $1,950 2025-12-12
Unclassified HIGH 8.1
CVE-2025-14044

The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.3 via deserialization of …

Mitigation only
Fix from $1,950 2025-12-12
React HIGH 7.5
CVE-2025-67779EPSS 20%

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a sp…

Fix: 14.2.35 / 15.0.7+
Fix from $1,950 2025-12-12
React HIGH 7.5
CVE-2025-55184EPSS 67%

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.…

Fix: 14.2.35 / 15.0.7+
Fix from $1,950 2025-12-11
Rmm CRITICAL 9.8
CVE-2025-34394

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently p…

Fix: 2025.1.1+
Fix from $2,300 2025-12-10
Unclassified HIGH 8.7
CVE-2025-9571

A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance…

Mitigation only
Fix from $1,950 2025-12-10
Coldfusion HIGH 8.4
CVE-2025-61810EPSS 9%

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit…

Mitigation only
Fix from $1,950 2025-12-10
Ladybug HIGH 8.8
CVE-2025-66214

Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-20251107.114628 contain the AP…

Fix: 3.0-20251107.114628+
Fix from $1,950 2025-12-09
Unclassified CRITICAL 9.3
CVE-2025-34414

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 …

Mitigation only
Fix from $2,300 2025-12-09
Unclassified HIGH 8.8
CVE-2025-33213

NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A succe…

Mitigation only
Fix from $1,950 2025-12-09
Unclassified HIGH 8.8
CVE-2025-33214

NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit…

Mitigation only
Fix from $1,950 2025-12-09
Unclassified MEDIUM 6.6
CVE-2025-67535

Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.…

Mitigation only
Fix from $1,600 2025-12-09
Csla .net CRITICAL 9.8
CVE-2025-66631

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow t…

Fix: 6.0.0+
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.1
CVE-2025-42928EPSS 9%

Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The s…

Mitigation only
Fix from $2,300 2025-12-09
Hummerrisk HIGH 8.8
CVE-2025-63721

HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby…

Fix: after 1.5.0
Fix from $1,950 2025-12-08
Unclassified CRITICAL 9.3
CVE-2025-66571

UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter…

No fix yet
Fix from $2,300 2025-12-04
React CRITICAL 10.0
CVE-2025-55182 KEVEPSS 100%

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the …

Fix: 15.0.5 / 15.1.9+
Fix from $2,300 2025-12-03
Codesys HIGH 7.8
CVE-2025-41700

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CO…

Fix: 3.5.21.40+
Fix from $1,950 2025-12-01
Unclassified MEDIUM 6.3
CVE-2025-9191

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted inp…

Mitigation only
Fix from $1,600 2025-11-26
Fugue HIGH 8.8
CVE-2025-62703

Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewr…

Fix: after 0.9.1
Fix from $1,950 2025-11-25