Vulnerability index

Browse CVEs

3,042 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Jsherp CRITICAL 9.8
CVE-2025-51744

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51745

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51746

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51743

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization att…

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51742

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter direc…

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Pmb CRITICAL 9.8
CVE-2025-61168

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

Mitigation only
Fix from $2,300 2025-11-25
Unclassified MEDIUM 5.5
CVE-2025-13467

A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserializa…

Patch available
Fix from $1,600 2025-11-25
Unclassified HIGH 7.2
CVE-2025-66073

Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/…

Mitigation only
Fix from $1,950 2025-11-21
Unclassified HIGH 7.2
CVE-2025-66055

Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affec…

Mitigation only
Fix from $1,950 2025-11-21
Vllm HIGH 8.8
CVE-2025-62164

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability co…

Fix: 0.11.1+
Fix from $1,950 2025-11-21
Sharepoint Online CRITICAL 9.8
CVE-2025-59245

Microsoft SharePoint Online Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Webmethods Integration HIGH 8.8
CVE-2025-36072

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration…

Mitigation only
Fix from $1,950 2025-11-20
Causeway MEDIUM 6.3
CVE-2025-64408EPSS 11%

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul…

Fix: 3.5.0+
Fix from $1,600 2025-11-19
Unclassified HIGH 7.2
CVE-2025-13145

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…

Mitigation only
Fix from $1,950 2025-11-19
Max HIGH 8.4
CVE-2025-60455

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used al…

Fix: 25.6.0+
Fix from $1,950 2025-11-18
Drupal MEDIUM 5.9
CVE-2025-13081

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue…

Fix: 10.4.9 / 10.5.6+
Fix from $1,600 2025-11-18
Unclassified HIGH 7.1
CVE-2025-12844

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via des…

Mitigation only
Fix from $1,950 2025-11-13
N Central CRITICAL 9.8
CVE-2025-11367

The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization

Fix: 2025.4+
Fix from $2,300 2025-11-12
Sharepoint Server HIGH 8.0
CVE-2025-62204

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19127.20338+
Fix from $1,950 2025-11-11
Debian Linux HIGH 7.8
CVE-2025-64512

Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107…

Fix: 2025-11-07+
Fix from $1,950 2025-11-10
Ktg Mes MEDIUM 6.5
CVE-2025-63617

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and…

Fix: 2025-10-08+
Fix from $1,600 2025-11-10
Unclassified HIGH 7.2
CVE-2025-12099

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Mitigation only
Fix from $1,950 2025-11-08
Unclassified HIGH 7.4
CVE-2025-64439

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 2…

Patch available
Fix from $1,950 2025-11-07
Unclassified HIGH 8.8
CVE-2025-62035

Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

Mitigation only
Fix from $1,950 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-60245

Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-58998

Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a t…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified HIGH 8.1
CVE-2025-58592

Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects T…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.8
CVE-2025-58619

Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection.This issue affects Falang multilanguage…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-58636

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue af…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified HIGH 8.8
CVE-2025-53586

Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through …

Mitigation only
Fix from $1,950 2025-11-06