Vulnerability index

Browse CVEs

3,032 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Unclassified CRITICAL 9.8
CVE-2026-65571

Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65572

Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65573

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65574

Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65552

Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65556

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 7.2
CVE-2026-65549

Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

No fix yet
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.0
CVE-2026-70426

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-2…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.6
CVE-2026-71294

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controlle…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-71281

Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py l…

No fix yet
Fix from $1,950 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61484

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-70554

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-control…

No fix yet
Fix from $2,300 2026-08-04
Dynamo HIGH 8.2
CVE-2026-47623

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulner…

Fix: after 1.1.0
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-69098

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to …

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.8
CVE-2026-18642

Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. Thi…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.1
CVE-2025-15672

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unaut…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-3245

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.6
CVE-2026-16062

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its…

No fix yet
Fix from $1,600 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-68771

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to exec…

No fix yet
Fix from $2,300 2026-07-31
Unclassified HIGH 7.5
CVE-2026-12720

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users ca…

No fix yet
Fix from $1,950 2026-07-31
Websphere Application Server HIGH 8.5
CVE-2026-11536

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

Fix: 8.5.5.29 / 9.0.5.28+
Fix from $1,950 2026-07-30
Sglang CRITICAL 9.8
CVE-2026-15969

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Sglang CRITICAL 9.8
CVE-2026-15976

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Webmethods Integration CRITICAL 9.8
CVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 7.5
CVE-2026-57859

e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band d…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-1360

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th…

No fix yet
Fix from $1,950 2026-07-30
Aimy Captcha Less Form Guard CRITICAL 9.8
CVE-2026-65883

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o…

Fix: after 20.0
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.1
CVE-2026-58163

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: …

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29